Emtract Ingest
API
EN
EN
DE
Dashboard
Regulations
Crawlers
Attributes
Topics
Home
/
Regulations
/
CRA
/
Edit obligation
Edit obligation
Title (English)
Title (German)
Kind
Approval
Due Diligence
Governance
Other
Record Keeping
Reporting
Stakeholder Engagement
Frequency
Annual
Biennial
Continuous
Event-triggered
Monthly
One-time
Other
Quarterly
Weekly
Check frequency
Annual
Biennial
Continuous
Event-triggered
Monthly
One-time
Other
Quarterly
Weekly
Rule set
Regulation-wide (no rule set)
Manufacturers of products with digital elements
Manufacturers of products with digital elements, including products already on the market
Authorised representatives of a manufacturer
Importers of products with digital elements
Distributors of products with digital elements
Economic operators — manufacturers, authorised representatives, importers and distributors
Importers and distributors
Manufacturers of critical products with digital elements
Open-source software stewards
Manufacturers, authorised representatives and importers of products with digital elements
Manufacturers of important products with digital elements, class I
Manufacturers of important products with digital elements, class II
Complexity (0–5)
Business functions
Communications
Compliance
Executive
Finance
Human Resources
Legal
Operations
Other
Procurement
Product
Sales
Sustainability
Description (English)
For an important product of class I under Annex III, internal control (module A) is available only where the manufacturer fully applies harmonised standards, common specifications or a European cybersecurity certification scheme at assurance level at least "medium" under Article 27. Where these have not been applied, or only in part, or do not exist, the manufacturer must carry out EU type-examination (module B) followed by conformity to type based on internal production control (module C), or a full quality assurance assessment (module H), in both cases involving a notified body. Class I covers, among others, network management systems, network interfaces, operating systems, routers, modems and switches, and microprocessors and microcontrollers with security-related functionalities.
Description (German)
Bei einem wichtigen Produkt der Klasse I nach Anhang III genügt die interne Kontrolle nach Modul A nur, solange der Hersteller harmonisierte Normen, gemeinsame Spezifikationen oder ein europäisches Schema für die Cybersicherheitszertifizierung mindestens der Vertrauenswürdigkeitsstufe "mittel" nach Artikel 27 vollständig anwendet. Hat er sie nicht oder nur zum Teil angewandt oder gibt es sie nicht, muss er die EU-Baumusterprüfung nach Modul B mit anschließender Fertigungskontrolle nach Modul C oder die umfassende Qualitätssicherung nach Modul H durchführen — in beiden Fällen unter Einschaltung einer notifizierten Stelle. Klasse I umfasst nach Anhang III unter anderem Netzmanagementsysteme (Nummer 6), physische und virtuelle Netzschnittstellen (Nummer 10), Betriebssysteme (Nummer 11), Router, Modems für die Internetanbindung und Switches (Nummer 12) sowie Mikroprozessoren und Mikrocontroller mit sicherheitsrelevanten Funktionen (Nummern 13 und 14). Für die Industrie-Netzwerktechnik ist das die entscheidende Weichenstellung — ein Switch oder Router fällt damit nicht unter die reine Selbsterklärung, sobald die Normenlage lückenhaft ist.
Affected products/services (English)
Products in class I of Annex III, in industrial networking above all switches, routers and modems, network management systems, network interfaces, operating systems and microcontrollers with security-related functionalities.
Affected products/services (German)
Produkte der Anhang-III-Klasse I, in der Industrie-Netzwerktechnik vor allem Switches, Router und Modems (Nummer 12), Netzmanagementsysteme (Nummer 6), Netzschnittstellen (Nummer 10), Betriebssysteme (Nummer 11) und Mikrocontroller mit sicherheitsrelevanten Funktionen (Nummer 14).
Checking responsibility (English)
Product development and compliance determine per product whether the relevant harmonised standards are fully applied; if not, compliance manages the engagement of the notified body.
Checking responsibility (German)
Produktentwicklung und Compliance bestimmen je Produkt, ob die einschlägigen harmonisierten Normen vollständig angewandt sind; ist das nicht der Fall, steuert die Compliance-Funktion die Beauftragung der notifizierten Stelle.
Check method (English)
A mapping per product of the harmonised standards and common specifications applied, with evidence of gaps, documented in the technical documentation under Annex VII; where gaps exist, evidence of the module B/C or module H procedure.
Check method (German)
Je Produkt eine Zuordnungsliste der angewandten harmonisierten Normen und gemeinsamen Spezifikationen mit Lückennachweis, dokumentiert in der technischen Dokumentation nach Anhang VII; bei Lücken der Nachweis des Modul-B/C- oder Modul-H-Verfahrens.
Withdrawn at
Cancel
Delete this obligation