Emtract Ingest
API
EN
EN
DE
Dashboard
Regulations
Crawlers
Attributes
Topics
Home
/
Regulations
/
CRA
/
Edit obligation
Edit obligation
Title (English)
Title (German)
Kind
Approval
Due Diligence
Governance
Other
Record Keeping
Reporting
Stakeholder Engagement
Frequency
Annual
Biennial
Continuous
Event-triggered
Monthly
One-time
Other
Quarterly
Weekly
Check frequency
Annual
Biennial
Continuous
Event-triggered
Monthly
One-time
Other
Quarterly
Weekly
Rule set
Regulation-wide (no rule set)
Manufacturers of products with digital elements
Manufacturers of products with digital elements, including products already on the market
Authorised representatives of a manufacturer
Importers of products with digital elements
Distributors of products with digital elements
Economic operators — manufacturers, authorised representatives, importers and distributors
Importers and distributors
Manufacturers of critical products with digital elements
Open-source software stewards
Manufacturers, authorised representatives and importers of products with digital elements
Manufacturers of important products with digital elements, class I
Manufacturers of important products with digital elements, class II
Complexity (0–5)
Business functions
Communications
Compliance
Executive
Finance
Human Resources
Legal
Operations
Other
Procurement
Product
Sales
Sustainability
Description (English)
Manufacturers integrating third-party components must exercise due diligence so that those components do not compromise the cybersecurity of the product, including free and open-source software. Vulnerabilities found in a component must be reported to the person or entity maintaining it, and any fix shared with them.
Description (German)
Wer von Dritten bezogene Komponenten in ein Produkt mit digitalen Elementen integriert, muss die gebotene Sorgfalt walten lassen, damit diese Komponenten die Cybersicherheit des Produkts nicht beeinträchtigen; das gilt ausdrücklich auch für freie und quelloffene Software, die nicht im Rahmen einer Geschäftstätigkeit bereitgestellt wurde. Stellt der Hersteller eine Schwachstelle in einer integrierten Komponente fest, meldet er sie der Person oder Einrichtung, die die Komponente herstellt oder wartet, und behebt sie nach Anhang I Teil II. Hat er einen Fix entwickelt, teilt er Code oder Unterlagen dieser Stelle mit, gegebenenfalls maschinenlesbar. Für Zulieferer mit hoher Fremdsoftwarequote ist das die Pflicht mit der größten Breitenwirkung.
Affected products/services (English)
All products with digital elements containing third-party software or hardware components, including open-source parts.
Affected products/services (German)
Alle Produkte mit digitalen Elementen, die fremdbezogene Software- oder Hardwarekomponenten enthalten, einschließlich quelloffener Bestandteile.
Checking responsibility (English)
Procurement together with product development; component assessment belongs in supplier qualification.
Checking responsibility (German)
Einkauf und Produktentwicklung gemeinsam; die Bewertung der Komponenten gehört in die Lieferantenqualifikation.
Check method (English)
Software bill of materials per product, matching against vulnerability databases, and contractual commitments from component suppliers.
Check method (German)
Software-Stückliste je Produkt, Abgleich gegen Schwachstellendatenbanken und vertragliche Zusagen der Komponentenlieferanten.
Withdrawn at
Cancel
Delete this obligation