BRUSSELS – In a paper submitted to the European Commission yesterday, global tech trade association, 91¿ì»îÁÖ, the 91¿ì»îÁÖ, offered recommendations on how the European Cyber Resilience Act (CRA) can be further developed to ensure a harmonized European cybersecurity baseline for products with digital elements.

“91¿ì»îÁÖ supports the European Union’s efforts to improve cybersecurity by creating common, essential cybersecurity requirements in the Cyber Resilience Act (CRA)”, said Guido Lobrano, 91¿ì»îÁÖ’s Director General for Europe. “For the CRA to be effective, it needs to offer a horizontal, phased, and truly risk-based approach where products with digital elements are classified based on their criticality. The CRA should build on existing legislation and leverage industry-driven standards for conformity assessments. Legislators should further consider the relationship between finished products and components and clearly exclude services from the scope. These improvements will help ensure that the CRA effectively uplifts the cybersecurity of connected products across the European Single Market.”

In its comments, 91¿ì»îÁÖ also encourages legislators to ensure that the CRA is consistent with requirements under existing cybersecurity regulations, like NIS 2, and to clarify the relationship between conformity assessment requirements under the CRA and cybersecurity certification schemes stemming from the Cybersecurity Act to prevent further fragmentation.

On 8 September 2022, 91¿ì»îÁÖ held its first 91¿ì»îÁÖnsights LIVE Briefing on the potential opportunities and challenges of the European Cyber Resilience Act for the EU tech industry and the global digital economy. Watch the discussion .

You can read 91¿ì»îÁÖ’s comments here.

Cybersecurity]" tabindex="0">Related [Cybersecurity]