BRUSSELS – Today, global tech trade association 91¿ì»îÁÖ, the 91¿ì»îÁÖ, led industry partners Developers Alliance, BSA|The Software Alliance, and the Computer & Communications Industry Associations (CCIA) on to advance the goals of the EU’s Cyber Resiliency Act (CRA) while addressing concerns in the current proposal. In the recommendations, the groups encourage policymakers to clarify and narrow the scope of the CRA, avoid duplication with other applicable legislation, and ensure the CRA is compatible with international standards and existing industry best practices, as well as different business models.

“As the EU co-legislators are making progress in setting out their positions on the Cyber Resilience Act, our associations wish to put forward concrete recommendations to support the EU’s efforts to improve cybersecurity and resilience while addressing remaining criticalities in the current proposal,” the groups wrote. “While both the European Parliament and the Council have made some significant improvements, many problematic aspects still need to be addressed. We therefore urge the co-legislators not to prioritise speed over quality in finalising their positions to avoid unintended outcomes.”

The groups encourage the EU lawmakers to provide proportionate and workable approaches for the following:

  • The scope of the CRA should be clearer and narrower.  In particular, any reference to “remote data processing solutions” should be excluded from the scope.

  • There needs to be a more proportionate, risk-based approach to determining the risk level of a product with digital elements in Article 6, and greater certainty for manufacturers to ascertain if a product is a critical one.

  • Only patched vulnerabilities that have been actively exploited and pose a significant cybersecurity risk should be reported under the CRA.

  • In general, it is crucial that the reporting obligations, including the reporting timeline and the competent authority, in both Article 11(1) and (2) are in line with the NIS 2 Directive. In addition, only “significant” incidents should be reported.

  • Further work is needed to avoid disproportionate or impossible obligations, and obligations that would in practice increase cybersecurity risks, such as the obligation to “deliver a product without known exploitable vulnerabilities” in Annex I, Section I, the possibility for the Commission to mandate the format and elements of Software Bill of Materials (SBOM), and the extension of the GDPR principle of data minimisation to non-personal data in Annex I.

Read the full recommendations .

Cybersecurity]" tabindex="0">Related [Cybersecurity]