Skip to main content
PolicySpeak
← All files

2022/0272(COD) · In Force

Cyber Resilience Act

165 submissions from 143 organizations told the European Commission what they think about this file. Here is what each of them said, in their own words.

The Commission lists 406 submissions on this file. Shown here: the 165 from organizations. Not shown, by design: submissions from private individuals, which we never publish, and anything filed since our last weekly refresh.

Committee ITRERapporteur Nicola Danti (Renew)
  1. Published in the Official Journal · 20 Nov 2024
  2. Signed · 23 Oct 2024
  3. Approval of the EP's first reading position by the Council (adoption of the legislative act) · 10 Oct 2024
  4. Discussions within the Council or its preparatory bodies · 18 Jun 2024
  5. Plenary Vote · 12 Mar 2024

Who showed up

123 submissions from industry — companies and their trade associations — against 21 from civil society: NGOs, consumer organizations, environmental groups and trade unions. That is 5.9 industry submissions for every one from civil society.

Industry 123Civil society 21Public authorities, academia, other 21

Groupings use the respondent type each organization selected when filing. Counting submissions, not organizations — a body that filed twice is counted twice.

What the room declares

88 of 143
in the EU Register
514
full-time lobbying staff
€73.1M+
declared costs a year
344
EP accreditations declared

Self-declared to the EU Transparency Register (snapshot 2 Sept 2026). The cost figure sums band floors, so the true total is higher.

The file, right now

The consultation closed on 23 Jan 2023 — it ran from 19 Sept 2022.

Policy area
Digital & tech (DG CNECT)
Where it stands
Awaiting adoption
Legislative stage
In Force
Lead committee
ITRE
Commission reference
COM(2022)454

How it got here

  1. Call for evidence · impact assessment25 May 2022
  2. Public consultation25 May 2022
  3. Proposal for a regulation23 Jan 2023

Also on the Commission’s pipeline for this file, with no date recorded: Initiative planned.

Showing 25 of 165 submissions.

MP

Max Planck Institute

· · filed 23 Jan 2023 · source

PDF

I am pleased to provide a feedback on behalf of the Max-Planck Institute for Security and Privacy. We support the general objectives in the Cyber Resilience Act in order to improve the cybersecurity of products.

Filed in Irish · English published by the European Commission

LinkedInX
OE

OpenForum Europe

· · filed 23 Jan 2023 · source

PDF

Dear Sir/Madam, Attached is a statement from OpenForum Europe (OFE) aisbl, co-signed by Eclipse Foundation, Open Source Initiative (OSI), APELL, CNLL, and The OSB Alliance. We have very serious concerns regarding some parts of the proposed text in its current form and we look forward to working with the EU institutions on this proposal to strengthen cybersecurity in the EU.

LinkedInX
TO

The Open Source Security Foundation

· · filed 23 Jan 2023 · source

PDF

The OpenSSF is a cross-industry organization that brings together the most important open source security initiatives and the individuals and companies that support them. The OpenSSF is committed to collaboration and working with the entire open source ecosystem to advance open source security for all.

LinkedInX
II

IARU (International Amateur Radio Union)

· · filed 23 Jan 2023 · source

The International Amateur Radio Union (IARU) is a Non-Governmental Organisation representing the interests of Radio Amateurs in the European Union and worldwide. The amateur and amateur satellite radio services are one of the oldest radio services recognised and regulated by the International Telecommunication Union (ITU) and pre-dates the regulation of radio communications.

LinkedInX
TD

The Document Foundation

· · filed 23 Jan 2023 · source

PDF

Please find attached a comment about the Cyber Resilience Act from The Document Foundation, the home of the free open source office suite LibreOffice. For the sake of brevity, we publish only the last section of the document: Recommendations and Solutions. We propose that all open source development and distribution activities should be excluded from the scope of the Cyber Resilience Act, without exception.

LinkedInX

Clusit strongly supports the adoption of a horizontal Regulation on cybersecurity, covering the many connected products not covered by vertical regulations and setting a baseline of security measures. The range of connected products that could pose a specific threat to the citizens, such as baby monitors, connected toys, home security webcams, but also components for the connected production in different markets…

LinkedInX
DA

Developers Alliance

· · filed 23 Jan 2023 · source

PDF

Developers Alliance welcomes the opportunity to provide comments on the proposal for a regulation on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act). The Cyber Resilience Act (CRA) imposes baseline cybersecurity requirements that can improve the level of security of digital products.

LinkedInX
VO

Vrijschrift.org

· · filed 23 Jan 2023 · source

PDF

Vrijschrift.org welcomes the Commission's draft proposal in the sense that product liability for security flaws is a missing piece of the puzzle. However, the proposal raises concerns regarding open source software. More details in the attached document.

LinkedInX
OX

Open-Xchange AG

· · filed 23 Jan 2023 · source

PDF

Open-Xchange would like to thank for the opportunity to provide comments on the Commissions proposal for a Cyber Resilience Act, specifically from the viewpoint of the European open-source software industry. While we support the objective of increased security in digital products, we think that the proposal suffers from a misunderstanding of the nature of software.

LinkedInX
AH

APPLiA (Home Appliance Europe)

· · filed 23 Jan 2023 · source

PDF

APPLiA representing household appliance industry in Europe - acknowledges the draft proposal for the Cyber Resilience Act. It is based on the New Legislative Framework Principles and as such should serve as one stop shop, central reference point for all cybersecurity requirements. Some detailed comments and recommendations from household appliance industry can be found in the attached file.

LinkedInX
G

GitHub

· · filed 23 Jan 2023 · source

PDF

GitHub is the largest code repository and platform for collaborative software development. Home to over 94 million developers, and nearly 14 million in the EU, we are where the world builds software. GitHub welcomes the European Commissions efforts to improve cybersecurity in the single market and, in particular, the Cyber Resilience Act (CRA) proposal.

LinkedInX
N

Netnod

· · filed 23 Jan 2023 · source

PDF

A summary of Netnod comments on the content of the suggested regulation can be found below. For the full response, see attached document. 1. There is no recognition that a product can consist of many components.

LinkedInX
GC

German Chamber of Commerce and Industry

· · filed 23 Jan 2023 · source

PDF

DIHK welcomes the opportunity to respond to the Cyber resilience act. Please find our comments in the attached document and a detailed position paper under the following Link soon: https://www.dihk.de/de/stellungnahmen-zur-europaeischen-gesetzgebung-8112

LinkedInX
E

Eurosmart

· · filed 23 Jan 2023 · source

PDF

Over the last decade, the European Union has been developing a solid cybersecurity regulatory approach. The overall approach is to make the European market more resilient while ensuring the digital sovereignty of the whole continent. This trend has prioritized sensitive domains that deserve strong resilience to more and more skilled attackers.

LinkedInX
SE

SEMI Europe

· · filed 23 Jan 2023 · source

PDF

SEMI Europe is the European affiliate of SEMI, the industry association representing more than 2,500 semiconductor and electronics manufacturing companies worldwide. SEMI Europe appreciates the opportunity to provide feedback to the European Commission on the Cyber Resilience Act (CRA). Please find our position in the attached document.

LinkedInX
OS

Open Source Initiative

· · filed 23 Jan 2023 · source

PDF

OSI recognise that the European Commission has framed an exception in recital 10 attempting to ensure the provisions of this proposed Act do not accidentally impact Open Source software. However, drawing on more than two decades of experience, we at the Open Source Initiative can clearly see that the current text will cause extensive problems for Open Source software.

LinkedInX
HH

Hangzhou Hikvision Digital Technology Co., Ltd.

· · filed 23 Jan 2023 · source

PDF

Hikvision appreciates the opportunity to participate to the consultation process on the proposed Cyber Resilience Act. Hikvision applauds the EU for its continued global leadership in developing a cybersecurity regulatory framework, and we welcome the proposal to create and apply strong requirements to protect end-users, end-user data, computing systems and the Internet at large.

LinkedInX
S

SNCF

· · filed 23 Jan 2023 · source

SNCF welcomes the introduction of the CRA and is convinced that it will be a valuable instrument for increasing cyber security. The sector makes use of both sector specific products and services and general-purpose solutions and services. The interplay between vertical and horizontal legislation should be further developed and sector specific legislation adapted accordingly. 1.

LinkedInX
A

AMETIC

· · filed 23 Jan 2023 · source

PDF

AMETIC, a multisectoral association representing the digital industry in Spain, considers that the development of the Cyber Resilience Act (CRA) demonstrates the European Union’s interest in tackling one of the main causes of successful cyber-attacks, through the malicious use of vulnerabilities in any software component.

Filed in Spanish · English published by the European Commission

LinkedInX
C

CEMA

· · filed 23 Jan 2023 · source

PDF

CEMA welcomes the CRA as an overarching horizontal legislation on Cybersecurity for products with digital elements. However, in case the scope of the essential requirements is not clarified and, linked to that, a more realistic timeline for non IT products is provided, it is impossible to become compliant with the whole fleet overall, and quality of implementation will suffer.

LinkedInX
BT

BEUC - The European Consumer Organisation

· · filed 23 Jan 2023 · source

PDF

BEUC welcomes the European Commission proposal on the Cyber Resilience Act (CRA). This proposal answers a longstanding need that BEUC and its members have identified and warned about repeatedly. Over the past years, BEUC members have demonstrated that too many connected products sold on the European market lack even the most basic security features. Too many products are putting consumers at risk on a daily basis.

LinkedInX
TI

TomTom International BV

· · filed 23 Jan 2023 · source

PDF

TomTom wishes to provide feedback regarding the public consultation for the proposal for a regulation on horizontal cybersecurity requirements for products with digital elements (amending Regulation (EU) 2019/1020) published on the 15th of September 2022, the Cyber Resilience Act.

LinkedInX
RN

RIPE NCC

· · filed 23 Jan 2023 · source

PDF

As the Regional Internet Registry for Europe, the Middle East and parts of Central Asia, the RIPE NCC welcomes the opportunity to give feedback on the European Commission's proposed Cyber Resilience Act. In the attached document, we explain how we foresee the Cyber Resilience Act impacting the RIPE NCC's own operations and services, and areas in which we believe further clarity is needed.

LinkedInX
II

ITI - Information Technology Industry Council

· · filed 23 Jan 2023 · source

PDF

ITI the Information Technology Industry Council appreciates the opportunity to submit comments to the Cyber Resilience Act (CRA) proposal. ITI represents 80 of the worlds leading information and communication technology (ICT) companies from all corners of the technology sector.

LinkedInX
AP

Alliance pour la Confiance Numérique

· · filed 23 Jan 2023 · source

PDF

The Alliance for Digital Trust (ACN), with more than 100 members, represents French companies (global leaders, SMEs and mid-caps) in the digital trust sector, in particular cybersecurity, digital confidentiality and trustworthy Artificial Intelligence. The NCA has for many years been calling for public authorities to rely on the importance of digital trust in an increasingly connected world.

Filed in French · English published by the European Commission

LinkedInX
Take the dataCSV — all 165 submissionsJSONFull text, not the excerpt. Free to cite.Search every submission →

Follow this file

Get an email when a new organization files a position here: one email on Tuesdays, only when there is something new. Free.

We use your email for updates on this file, and PolicySpeak may contact you about the product. Unsubscribe in one click. Privacy policy.

Method. Every quote is verbatim from the organization’s own submission to the European Commission, trimmed to its opening passage and never summarized by a model. Where a submission was filed in another EU language we show the English text the European Commission publishes alongside it, labeled on the quote; the original is one click away at the source. Groupings use the respondent type the organization itself selected when filing. We deliberately do not label anyone “supportive” or “opposed” — you read what they wrote and draw your own conclusion. Organizations only, never individuals. Reused under Commission Decision 2011/833/EU; the European Commission is not liable for this reuse.