Emtract Ingest
API
EN
EN
DE
Dashboard
Regulations
Crawlers
Attributes
Topics
Home
/
Regulations
/
CRA
/
Edit obligation
Edit obligation
Title (English)
Title (German)
Kind
Approval
Due Diligence
Governance
Other
Record Keeping
Reporting
Stakeholder Engagement
Frequency
Annual
Biennial
Continuous
Event-triggered
Monthly
One-time
Other
Quarterly
Weekly
Check frequency
Annual
Biennial
Continuous
Event-triggered
Monthly
One-time
Other
Quarterly
Weekly
Rule set
Regulation-wide (no rule set)
Manufacturers of products with digital elements
Manufacturers of products with digital elements, including products already on the market
Authorised representatives of a manufacturer
Importers of products with digital elements
Distributors of products with digital elements
Economic operators — manufacturers, authorised representatives, importers and distributors
Importers and distributors
Manufacturers of critical products with digital elements
Open-source software stewards
Manufacturers, authorised representatives and importers of products with digital elements
Manufacturers of important products with digital elements, class I
Manufacturers of important products with digital elements, class II
Complexity (0–5)
Business functions
Communications
Compliance
Executive
Finance
Human Resources
Legal
Operations
Other
Procurement
Product
Sales
Sustainability
Description (English)
Unless the information has already been provided, the manufacturer submits a final report to the coordinator CSIRT and ENISA no later than 14 days after a corrective or mitigating measure is available, describing the vulnerability with its severity and impact, any malicious actor that exploited it where available, and the security update or other corrective measures made available to remedy it.
Description (German)
Soweit die Angaben nicht bereits vorliegen, legt der Hersteller spätestens 14 Tage, nachdem eine Korrektur- oder Risikominderungsmaßnahme zur Verfügung steht, dem als Koordinator benannten CSIRT und der ENISA einen Abschlussbericht vor. Er enthält mindestens eine Beschreibung der Schwachstelle einschließlich ihres Schweregrads und ihrer Auswirkungen, falls verfügbar Informationen über jeden böswilligen Akteur, der die Schwachstelle ausgenutzt hat oder ausnutzt, und Informationen über die Sicherheitsaktualisierung oder andere Korrekturmaßnahmen, die zur Behebung der Schwachstelle zur Verfügung gestellt wurden.
Affected products/services (English)
All products with digital elements the company makes available on the Union market.
Affected products/services (German)
Alle Produkte mit digitalen Elementen, die das Unternehmen auf dem Unionsmarkt bereitstellt.
Checking responsibility (English)
Product security incident response team or an equivalent function with out-of-hours availability.
Checking responsibility (German)
Product Security Incident Response Team oder eine gleichwertige Stelle mit Rufbereitschaft außerhalb der Geschäftszeiten.
Check method (English)
Notification through the single reporting platform under Article 16 to the electronic endpoint of the competent CSIRT, with a documented timestamp of becoming aware.
Check method (German)
Meldung über die einheitliche Meldeplattform nach Artikel 16 an den elektronischen Meldeendpunkt des zuständigen CSIRT, mit dokumentiertem Zeitstempel der Kenntniserlangung.
Withdrawn at
Cancel
Delete this obligation