Cyber Resilience Act

13 march 2024

The regulation, already agreed with Council in December 2023, aims to ensure that products with digital features are secure to use, resilient against cyber threats and provide enough information about their security properties.

Important and critical products will be put into different lists based on their criticality and the level of cybersecurity risk they pose. The two lists will be proposed and updated by the European Commission. Products deemed to pose a higher cybersecurity risk will be examined more stringently by a notified body, while others may go through a lighter conformity assessment process, often managed internally by the manufacturers.

During the negotiations, MEPs made sure that products such as identity management systems software, password managers, biometric readers, smart home assistants and private security cameras are covered by the new rules. Products should also have security updates installed automatically and separately from functionality updates.

MEPs also pushed for the European Union Agency for Cybersecurity (ENISA) to be more closely involved when vulnerabilities are found and incidents occur. The agency will be notified by the member state concerned and receive information so it can assess the situation and, if it identifies a systemic risk, will inform other member states so they are able to take the necessary steps.

To emphasise the importance of professional skills in the cybersecurity field, MEPs also introduced education and training programmes, collaborative initiatives, and strategies to enhance workforce mobility in the regulation.

News archive

 

Firm news

mag7

07/05/2024

Modifica al codice deontologico in materia di equo compenso

Il 3 maggio 2024, e’ stato pubblicata nella Gazzetta Ufficiale il  seguente Comunicato del CNF:  Il Consiglio nazionale forense, nella seduta  amministrativa  del 23

mag3

03/05/2024

Lotta contro le contraffazioni commesse online

Lotta contro i reati e ingerenza nei diritti fondamentali: un'autorita` pubblica nazionale incaricata della lotta contro le contraffazioni commesse online puo` accedere ai dati identificativi

mag3

03/05/2024

Tabulati telefonici

Secondo la legge italiana, il delitto di furto aggravato fa parte dei reati che giustificano l’acquisizione di tabulati telefonici presso il fornitore di servizi di comunicazione elettronica,

Lawyer News

mag10

10/05/2024

Codice della crisi e società con perdite rilevanti: lo studio CNN

<p>Il Codice della Crisi d'Impresa

mag10

10/05/2024

Correttivo Codice crisi d’impresa: arriva l’ok del Governo? Cybersicurezza: concluso l’esame del ddl

<p>Pubblicati in G.U. il <a href="https://onelegale.wolterskluwer.it/document/10LX0000962555SOMM"

mag10

10/05/2024

Raccolta dati dei minori: il Minnesota si muove per la limitazione

Proposte misure volte a garantire una maggiore