BRUSSELS – Today, global tech trade association the 91¿ì»îÁÖ (±õ°Õ±õ) submitted comments to the European Commission consultation on the Cyber Resilience Act (CRA).

The CRA offers the EU an opportunity to take a ‘precision’ regulatory approach, in which regulation is risk-based and takes into account the end-use of the product or service. The future proposal should include clear and harmonized rules, be aligned with internationally recognized standards, and avoid overly prescriptive requirements and inconsistencies with other EU legislation, 91¿ì»îÁÖ wrote in its comments.

The submission also highlights that European and international standards should be aligned as international standards provide widely vetted, consensus-based information and guidance for defining and implementing effective security methodologies and facilitate common approaches to common challenges, thus enabling collaboration and interoperability. Relying on international standards is key to avoid regulatory fragmentation globally.

The CRA should prioritize harmonization and conformity with existing and upcoming EU legislation. 91¿ì»îÁÖ’s submission also calls for future proof requirements for higher-risk products and services, and recommends a mixed approach, combining horizontal rules for a wide variety products and ancillary services with soft measures for non-embedded software.

Read 91¿ì»îÁÖ’s full comments here.

Cybersecurity]" tabindex="0">Related [Cybersecurity]