Emtract Ingest
API
EN
EN
DE
Dashboard
Regulations
Crawlers
Attributes
Topics
Home
/
Regulations
/
CRA
/
Edit obligation
Edit obligation
Title (English)
Title (German)
Kind
Approval
Due Diligence
Governance
Other
Record Keeping
Reporting
Stakeholder Engagement
Frequency
Annual
Biennial
Continuous
Event-triggered
Monthly
One-time
Other
Quarterly
Weekly
Check frequency
Annual
Biennial
Continuous
Event-triggered
Monthly
One-time
Other
Quarterly
Weekly
Rule set
Regulation-wide (no rule set)
Manufacturers of products with digital elements
Manufacturers of products with digital elements, including products already on the market
Authorised representatives of a manufacturer
Importers of products with digital elements
Distributors of products with digital elements
Economic operators — manufacturers, authorised representatives, importers and distributors
Importers and distributors
Manufacturers of critical products with digital elements
Open-source software stewards
Manufacturers, authorised representatives and importers of products with digital elements
Manufacturers of important products with digital elements, class I
Manufacturers of important products with digital elements, class II
Complexity (0–5)
Business functions
Communications
Compliance
Executive
Finance
Human Resources
Legal
Operations
Other
Procurement
Product
Sales
Sustainability
Description (English)
Unless the information has already been provided, the manufacturer submits a vulnerability notification to the coordinator CSIRT and ENISA without undue delay and in any event within 72 hours of becoming aware of the actively exploited vulnerability, with general information on the product, the general nature of the exploit and of the vulnerability, and corrective or mitigating measures taken and those users can take. The CSIRT may additionally request an intermediate report on relevant status updates.
Description (German)
Soweit die Angaben nicht bereits vorliegen, übermittelt der Hersteller unverzüglich, in jedem Fall aber innerhalb von 72 Stunden, nachdem er Kenntnis von der aktiv ausgenutzten Schwachstelle erlangt hat, dem als Koordinator benannten CSIRT und der ENISA eine Meldung von Schwachstellen. Sie enthält, soweit verfügbar, allgemeine Informationen über das betroffene Produkt, die allgemeine Art der Ausnutzung und der Schwachstelle, ergriffene Korrektur- oder Risikominderungsmaßnahmen sowie Korrektur- oder Abhilfemaßnahmen, die Nutzer ergreifen können, und gegebenenfalls, als wie sensibel der Hersteller die gemeldeten Informationen ansieht. Das CSIRT kann zusätzlich einen Zwischenbericht über relevante Statusaktualisierungen anfordern.
Affected products/services (English)
All products with digital elements the company makes available on the Union market.
Affected products/services (German)
Alle Produkte mit digitalen Elementen, die das Unternehmen auf dem Unionsmarkt bereitstellt.
Checking responsibility (English)
Product security incident response team or an equivalent function with out-of-hours availability.
Checking responsibility (German)
Product Security Incident Response Team oder eine gleichwertige Stelle mit Rufbereitschaft außerhalb der Geschäftszeiten.
Check method (English)
Notification through the single reporting platform under Article 16 to the electronic endpoint of the competent CSIRT, with a documented timestamp of becoming aware.
Check method (German)
Meldung über die einheitliche Meldeplattform nach Artikel 16 an den elektronischen Meldeendpunkt des zuständigen CSIRT, mit dokumentiertem Zeitstempel der Kenntniserlangung.
Withdrawn at
Cancel
Delete this obligation