Cyber Resilience Act
   HOME

TheInfoList



OR:

The Cyber Resilience Act (CRA) is an
EU regulation A regulation is a legal act of the European Union which becomes immediately enforceable as law in all member states simultaneously. Regulations can be distinguished from directives which, at least in principle, need to be transposed into nation ...
for improving
cybersecurity Computer security (also cybersecurity, digital security, or information technology (IT) security) is a subdiscipline within the field of information security. It consists of the protection of computer software, systems and networks from thr ...
and cyber resilience in the EU through common cybersecurity standards for products with digital elements in the EU, such as required incident reports and automatic security updates. Products with digital elements mainly are hardware and
software Software consists of computer programs that instruct the Execution (computing), execution of a computer. Software also includes design documents and specifications. The history of software is closely tied to the development of digital comput ...
whose "intended and foreseeable use includes direct or indirect data connection to a device or network". After its proposal on 15 September 2022 by the
European Commission The European Commission (EC) is the primary Executive (government), executive arm of the European Union (EU). It operates as a cabinet government, with a number of European Commissioner, members of the Commission (directorial system, informall ...
, multiple
open source Open source is source code that is made freely available for possible modification and redistribution. Products include permission to use and view the source code, design documents, or content of the product. The open source model is a decentrali ...
organizations criticized CRA for creating a "chilling effect on
open source software development Open-source software development (OSSD) is the process by which open-source software, or similar software whose source code is publicly available, is developed by an open-source software project. These are software products available with its sourc ...
". The European Commission reached political agreement on the CRA on 1 December 2023, after a series of amendments. The revised bill introduced the "open source steward", a new economic concept, and received relief from many open source organizations due to its exception for open-source software, while Debian criticized its effect on small businesses and redistributors. The CRA agreement received formal approval by the
European Parliament The European Parliament (EP) is one of the two legislative bodies of the European Union and one of its seven institutions. Together with the Council of the European Union (known as the Council and informally as the Council of Ministers), it ...
in March 2024. It was adopted by the Council on 10 October 2024.


Purposes and motivations

The background, purposes and motivations for the proposed policy include: * Consumers increasingly become victims to security flaws of digital products (e.g.
vulnerabilities Vulnerability refers to "the quality or state of being exposed to the possibility of being attacked or harmed, either physically or emotionally." The understanding of social and environmental vulnerability, as a methodological approach, involves ...
), including of
Internet of Things Internet of things (IoT) describes devices with sensors, processing ability, software and other technologies that connect and exchange data with other devices and systems over the Internet or other communication networks. The IoT encompasse ...
devices or
smart device A smart device is an electronic device, generally connected to other devices or networks via different wireless protocols (such as Bluetooth, Zigbee, near-field communication, Wi-Fi, NearLink, Li-Fi, or 5G) that can operate to some extent inte ...
s. * Ensuring that digital products in the
supply chain A supply chain is a complex logistics system that consists of facilities that convert raw materials into finished products and distribute them to end consumers or end customers, while supply chain management deals with the flow of goods in distri ...
are secure is important for businesses, and cybersecurity often is a "full company risk issue". * Potential impacts of hacking include "severe disruption of economic and social activities across the internal market, undermining security or even becoming life-threatening". * Secure by default principles would impose a duty of care for the lifecycle of products, instead of e.g. relying on consumers and volunteers to establish a basic level of security. The new rules would "rebalance responsibility towards manufacturers". *
Cyberattack A cyberattack (or cyber attack) occurs when there is an unauthorized action against computer infrastructure that compromises the confidentiality, integrity, or availability of its content. The rising dependence on increasingly complex and inte ...
s have led "to an estimated
global Global may refer to: General *Globe, a spherical model of celestial bodies *Earth, the third planet from the Sun Entertainment * ''Global'' (Paul van Dyk album), 2003 * ''Global'' (Bunji Garlin album), 2007 * ''Global'' (Humanoid album), 198 ...
annual cost of
cybercrime Cybercrime encompasses a wide range of criminal activities that are carried out using digital devices and/or Computer network, networks. It has been variously defined as "a crime committed on a computer network, especially the Internet"; Cyberc ...
of €5.5 trillion by 2021". * The rapid spread of digital technologies means rogue states or non-state groups could more easily disrupt
critical infrastructure Critical infrastructure, or critical national infrastructure (CNI) in the UK, describes infrastructure considered essential by governments for the functioning of a society and economy and deserving of special protection for national security. ...
s such as public administration and hospitals. According to
The Washington Post ''The Washington Post'', locally known as ''The'' ''Post'' and, informally, ''WaPo'' or ''WP'', is an American daily newspaper published in Washington, D.C., the national capital. It is the most widely circulated newspaper in the Washington m ...
, the CRA could make the EU a leader on cybersecurity and "change the rules of the game globally".


Implementation and mechanisms

The policy requires software that are "reasonably expected" to have automatic updates should roll out
security update A patch is data that is intended to be used to modify an existing software resource such as a program or a file, often to fix bugs and security vulnerabilities. A patch may be created to improve functionality, usability, or performance. A pa ...
s automatically
by default ''By Default'' is the fourth studio album by British rock band Band of Skulls, released on 27 May 2016 through BMG as the band's first release by a major label. The album was the last album to feature drummer Matt Hayward before his departure i ...
while allowing users to opt out. When feasible, security updates should be separated from feature updates. Companies need to conduct cyber risk assessments before a product is put on the market and retain its data inventory and documentation throughout the 10 years after being put on market or its support period, whichever is longer. Companies would have to notify EU cybersecurity agency ENISA of any incidents within 24 hours of becoming aware of them, and take measures to resolve them. Products carrying the
CE marking The presence of the logo on Product (business), commercial products indicates that the Manufacturing, manufacturer or importer affirms the goods' conformity with European Environment, health and safety, health, safety, and environmental prote ...
would "meet a minimum level of cybersecurity checks". About 90% of products with digital elements fall under a default category, for which manufacturers will self-assess security, write an EU declaration of conformity, and provide technical documentation. The rest are either "important" or "critical". Security-important products are categorized into two classes of risks. Products assessed as 'critical' will need to undergo external audits. Once the law has passed, manufacturers would have two years to adapt to the new requirements and one year to implement vulnerability and incident reporting. Failure to comply could result in fines of up to €15 million or 2.5 percent of the offender's total worldwide annual turnover for the preceding financial year. Fines do not apply to non-commercial open-source developers. Euractiv has reported on novel drafts or draft-changes that includes changes like the "removal of time obligations for products' lifetime and limiting the scope of reporting to significant incidents". The first compromise amendment will be discussed on 22 May 2023 until which groups reportedly could submit written comments. Euractiv has provided a summary overview of the proposed changes. The main political groups in the
European Parliament The European Parliament (EP) is one of the two legislative bodies of the European Union and one of its seven institutions. Together with the Council of the European Union (known as the Council and informally as the Council of Ministers), it ...
are expected to agree on the Cyber Resilience Act at a meeting on 5 July 2023. Lawmakers will discuss open source considerations, support periods, reporting obligations, and the implementation timeline. The committee vote is scheduled for 19 July 2023. The Spanish presidency of the EU Council has released a revised draft that simplifies the regulatory requirements for connected devices. It would reduce the number of product categories that must comply with specific regulations, mandate reporting of cybersecurity incidents to national CSIRTs, and include provisions for determining product lifetime and easing administrative burdens for small companies. The law also clarifies that spare parts with digital elements supplied by the original manufacturer are exempt from the new requirements. The Council text further stipulates that prior to seeking compulsory certification, the European Union executives must undertake an impact assessment to evaluate both the supply and demand aspects of the internal market, as well as the member states' capacity and preparedness for implementing the proposed schemes. On June 25, 2024, the Czech National Office for Cyber and Information Security (NÚKIB) announced steps to implement the Cyber Resilience Act (CRA), including a regulation expected in autumn 2024, with enforcement starting in late 2027 after a three-year transition. This regulation will require manufacturers of digital products to enhance cybersecurity throughout the product lifecycle. NÚKIB will also hold consultations with manufacturers of significant and critical products from June 25 to July 17, 2024, to develop technical specifications and gather feedback.


Reception

Initially, the proposed act was heavily criticized by open-source advocates. * Multiple open source organizations like the
Eclipse Foundation The Eclipse Foundation AISBL is an independent, Europe-based not-for-profit organization that acts as a steward of the Eclipse open source software development community, with legal jurisdiction in the European Union. It is an organization supp ...
, the
Open Source Initiative The Open Source Initiative (OSI) is a California public benefit corporation "actively involved in Open Source community-building, education, and public advocacy to promote awareness and the importance of non-proprietary software". Governance The ...
(OSI), and
The Document Foundation The Document Foundation (TDF) is a non-profit organization that supports the development of LibreOffice, a free and open-source office suite. Established in 2010 by members of the OpenOffice.org community, TDF aims to provide a vendor-neutral p ...
have signed the
open letter An open letter is a Letter (message), letter that is intended to be read by a wide audience, or a letter intended for an individual, but that is nonetheless widely distributed intentionally. Open letters usually take the form of a letter (mess ...
" Open Letter to the European Commission on the Cyber Resilience Act", asking policy-makers to change the under-representation of the open source community. It finds that with the policy " /nowiki>free and open source software,">free_and_open_source_software.html" ;"title="/nowiki>free and open source software">/nowiki>free and open source software,more than 70% of the software in Europe[,] is about to be regulated without an in-depth consultation" and if implemented as written (as of April) would have a "chilling effect on
open source software development Open-source software development (OSSD) is the process by which open-source software, or similar software whose source code is publicly available, is developed by an open-source software project. These are software products available with its sourc ...
as a global endeavour, with the net effect of undermining the EU's own expressed
goal A goal or objective is an idea of the future or desired result that a person or a group of people envision, plan, and commit to achieve. People endeavour to reach goals within a finite time by setting deadlines. A goal is roughly similar to ...
s for
innovation Innovation is the practical implementation of ideas that result in the introduction of new goods or service (economics), services or improvement in offering goods or services. ISO TC 279 in the standard ISO 56000:2020 defines innovation as "a n ...
, digital
sovereignty Sovereignty can generally be defined as supreme authority. Sovereignty entails hierarchy within a state as well as external autonomy for states. In any state, sovereignty is assigned to the person, body or institution that has the ultimate au ...
, and future prosperity".
The Apache Software Foundation The Apache Software Foundation ( ; ASF) is an American nonprofit corporation (classified as a 501(c)(3) organization in the United States) to support a number of open-source software projects. The ASF was formed from a group of developers of the A ...
published a similar statement, and the OSI submitted this information to the European Commission's request for input. * Although
Mozilla Mozilla is a free software community founded in 1998 by members of Netscape. The Mozilla community uses, develops, publishes and supports Mozilla products, thereby promoting free software and open standards. The community is supported institution ...
"welcome and support the overarching goals of the CRA", it also criticised the proposal for unclear references to "commercial activity" that could include many open source projects (a viewpoint Ilkka Turunen of
Computer Weekly ''Computer Weekly'' is a digital magazine and website for IT professionals in the United Kingdom owned by Informa TechTarget. It was formerly published as a weekly print magazine by Reed Business Information for over 50 years. Topics covered wit ...
repeated), misalignment with other EU rules, and requirements for the disclosure of unmitigated vulnerabilities. * Steven J. Vaughan-Nichols of
The Register ''The Register'' (often also called El Reg) is a British Technology journalism, technology news website co-founded in 1994 by Mike Magee (journalist), Mike Magee and John Lettice. The online newspaper's Nameplate_(publishing), masthead Logo, s ...
argued the CRA's "underlying assumption is that you can just add security to software" while " ny open source developers have neither the revenue nor resources to secure their programs to a government standard". * CCIA Europe warned that "the resulting red tape from the approval process could hamper the roll-out of new technologies and services in Europe". Amendments were released on 1 December 2023, as part of political agreement between co-legislators, to the acclaim of many open-source advocates. As Mike Milinkovich, executive director of the Eclipse foundation, wrote: The OSI noted
Debian Debian () is a free and open-source software, free and open source Linux distribution, developed by the Debian Project, which was established by Ian Murdock in August 1993. Debian is one of the oldest operating systems based on the Linux kerne ...
's statement that many small businesses and solo developers would have trouble navigating the act when redistributing open source software remained unaddressed. Apache reviewed the changes positively while worrying about applicability of the CRA on potentially critical open-source components and stressing the importance of collaboration with international standards bodies to ease certification of software.


See also

* NIS 2 Directive * Artificial Intelligence Act * Cyber Security and Resilience Bill—proposed UK legislation *
Consumer protection Consumer protection is the practice of safeguarding buyers of goods and services, and the public, against unfair practices in the marketplace. Consumer protection measures are often established by law. Such laws are intended to prevent business ...
* Cyber self-defense *
List of data breaches This is a list of reports about data breaches, using data compiled from various sources, including press reports, government news releases, and mainstream news articles. The list includes those involving the theft or compromise of 30,000 or more ...
* List of security hacking incidents# *
Sustainable design Environmentally sustainable design (also called environmentally conscious design, eco-design, etc.) is the philosophy of designing physical objects, the built environment, and services to comply with the principles of ecological sustainability ...
*
Standardization Standardization (American English) or standardisation (British English) is the process of implementing and developing technical standards based on the consensus of different parties that include firms, users, interest groups, standards organiza ...


References


External links


Cyber Resilience Act
on
EUR-Lex EUR-Lex is the official online database of European Union law and other public documents of the European Union (EU), published in 24 official Languages of the European Union, languages of the EU. The Official Journal of the European Union, Offici ...

Cyber Resilience Act {{! Shaping Europe's digital future
landing page of the EU Commission ( DG CONNECT)
Procedure 2022/0272/COD
on EUR-Lex
Procedure 2022/0272(COD)
on ŒIL European Union data protection law Computing legislation 2024 in law Computer security Internet of things IT infrastructure 2024 in politics 2024 in computing