The next piece of the puzzle is almost ready to fit into the EU cybersecurity framework. On November 30, the EU Council and Parliament reached an agreement on the EU Cyber Resilience Act (CRA), which will introduce uniform cybersecurity requirements for products with digital elements. Similar to other acts of the EU Data Strategy, the CRA aims to create responsibility for manufacturers and transparency for consumers and businesses. There will also be a vulnerability handling process.
While simplifying the scope of the CRA and adding a three-year grace period, the agreement reached by the EU Council and the EU Parliament amended the EU Commission's proposal by adding that the support period for products must be at least five years, and there will be a reporting obligation for exploited vulnerabilities and incidents.
The final draft is expected in the next weeks, once the details have been finalized.
We will update you here on the developments of the European Cybersecurity Framework.