165 submissions from 143 organizations told the European Commission what they think about this file. Here is what each of them said, in their own words.
The Commission lists 406 submissions on this file. Shown here: the 165 from organizations. Not shown, by design: submissions from private individuals, which we never publish, and anything filed since our last weekly refresh.
CommitteeITRERapporteurNicola Danti (Renew)
Published in the Official Journal · 20 Nov 2024
Signed · 23 Oct 2024
Approval of the EP's first reading position by the Council (adoption of the legislative act) · 10 Oct 2024
Discussions within the Council or its preparatory bodies · 18 Jun 2024
Plenary Vote · 12 Mar 2024
Who showed up
123 submissions from industry — companies and their trade associations — against 21 from civil society: NGOs, consumer organizations, environmental groups and trade unions. That is 5.9 industry submissions for every one from civil society.
Industry 123Civil society 21Public authorities, academia, other 21
Groupings use the respondent type each organization selected when filing. Counting submissions, not organizations — a body that filed twice is counted twice.
What the room declares
88 of 143
in the EU Register
514
full-time lobbying staff
€73.1M+
declared costs a year
344
EP accreditations declared
Self-declared to the EU Transparency Register (snapshot 2 Sept 2026). The cost figure sums band floors, so the true total is higher.
The file, right now
The consultation closed on 23 Jan 2023 — it ran from 19 Sept 2022.
I am pleased to provide a feedback on behalf of the Max-Planck Institute for Security and Privacy. We support the general objectives in the Cyber Resilience Act in order to improve the cybersecurity of products.
Filed in Irish · English published by the European Commission
Dear Sir/Madam, Attached is a statement from OpenForum Europe (OFE) aisbl, co-signed by Eclipse Foundation, Open Source Initiative (OSI), APELL, CNLL, and The OSB Alliance. We have very serious concerns regarding some parts of the proposed text in its current form and we look forward to working with the EU institutions on this proposal to strengthen cybersecurity in the EU.
The OpenSSF is a cross-industry organization that brings together the most important open source security initiatives and the individuals and companies that support them. The OpenSSF is committed to collaboration and working with the entire open source ecosystem to advance open source security for all.
The International Amateur Radio Union (IARU) is a Non-Governmental Organisation representing the interests of Radio Amateurs in the European Union and worldwide. The amateur and amateur satellite radio services are one of the oldest radio services recognised and regulated by the International Telecommunication Union (ITU) and pre-dates the regulation of radio communications.
Please find attached a comment about the Cyber Resilience Act from The Document Foundation, the home of the free open source office suite LibreOffice. For the sake of brevity, we publish only the last section of the document: Recommendations and Solutions. We propose that all open source development and distribution activities should be excluded from the scope of the Cyber Resilience Act, without exception.
Clusit strongly supports the adoption of a horizontal Regulation on cybersecurity, covering the many connected products not covered by vertical regulations and setting a baseline of security measures. The range of connected products that could pose a specific threat to the citizens, such as baby monitors, connected toys, home security webcams, but also components for the connected production in different markets…
Developers Alliance welcomes the opportunity to provide comments on the proposal for a regulation on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act). The Cyber Resilience Act (CRA) imposes baseline cybersecurity requirements that can improve the level of security of digital products.
Vrijschrift.org welcomes the Commission's draft proposal in the sense that product liability for security flaws is a missing piece of the puzzle. However, the proposal raises concerns regarding open source software. More details in the attached document.
Open-Xchange would like to thank for the opportunity to provide comments on the Commissions proposal for a Cyber Resilience Act, specifically from the viewpoint of the European open-source software industry. While we support the objective of increased security in digital products, we think that the proposal suffers from a misunderstanding of the nature of software.
APPLiA representing household appliance industry in Europe - acknowledges the draft proposal for the Cyber Resilience Act. It is based on the New Legislative Framework Principles and as such should serve as one stop shop, central reference point for all cybersecurity requirements. Some detailed comments and recommendations from household appliance industry can be found in the attached file.
GitHub is the largest code repository and platform for collaborative software development. Home to over 94 million developers, and nearly 14 million in the EU, we are where the world builds software. GitHub welcomes the European Commissions efforts to improve cybersecurity in the single market and, in particular, the Cyber Resilience Act (CRA) proposal.
A summary of Netnod comments on the content of the suggested regulation can be found below. For the full response, see attached document. 1. There is no recognition that a product can consist of many components.
DIHK welcomes the opportunity to respond to the Cyber resilience act. Please find our comments in the attached document and a detailed position paper under the following Link soon: https://www.dihk.de/de/stellungnahmen-zur-europaeischen-gesetzgebung-8112
Over the last decade, the European Union has been developing a solid cybersecurity regulatory approach. The overall approach is to make the European market more resilient while ensuring the digital sovereignty of the whole continent. This trend has prioritized sensitive domains that deserve strong resilience to more and more skilled attackers.
SEMI Europe is the European affiliate of SEMI, the industry association representing more than 2,500 semiconductor and electronics manufacturing companies worldwide. SEMI Europe appreciates the opportunity to provide feedback to the European Commission on the Cyber Resilience Act (CRA). Please find our position in the attached document.
OSI recognise that the European Commission has framed an exception in recital 10 attempting to ensure the provisions of this proposed Act do not accidentally impact Open Source software. However, drawing on more than two decades of experience, we at the Open Source Initiative can clearly see that the current text will cause extensive problems for Open Source software.
Hikvision appreciates the opportunity to participate to the consultation process on the proposed Cyber Resilience Act. Hikvision applauds the EU for its continued global leadership in developing a cybersecurity regulatory framework, and we welcome the proposal to create and apply strong requirements to protect end-users, end-user data, computing systems and the Internet at large.
SNCF welcomes the introduction of the CRA and is convinced that it will be a valuable instrument for increasing cyber security. The sector makes use of both sector specific products and services and general-purpose solutions and services. The interplay between vertical and horizontal legislation should be further developed and sector specific legislation adapted accordingly. 1.
AMETIC, a multisectoral association representing the digital industry in Spain, considers that the development of the Cyber Resilience Act (CRA) demonstrates the European Union’s interest in tackling one of the main causes of successful cyber-attacks, through the malicious use of vulnerabilities in any software component.
Filed in Spanish · English published by the European Commission
CEMA welcomes the CRA as an overarching horizontal legislation on Cybersecurity for products with digital elements. However, in case the scope of the essential requirements is not clarified and, linked to that, a more realistic timeline for non IT products is provided, it is impossible to become compliant with the whole fleet overall, and quality of implementation will suffer.
BEUC welcomes the European Commission proposal on the Cyber Resilience Act (CRA). This proposal answers a longstanding need that BEUC and its members have identified and warned about repeatedly. Over the past years, BEUC members have demonstrated that too many connected products sold on the European market lack even the most basic security features. Too many products are putting consumers at risk on a daily basis.
TomTom wishes to provide feedback regarding the public consultation for the proposal for a regulation on horizontal cybersecurity requirements for products with digital elements (amending Regulation (EU) 2019/1020) published on the 15th of September 2022, the Cyber Resilience Act.
As the Regional Internet Registry for Europe, the Middle East and parts of Central Asia, the RIPE NCC welcomes the opportunity to give feedback on the European Commission's proposed Cyber Resilience Act. In the attached document, we explain how we foresee the Cyber Resilience Act impacting the RIPE NCC's own operations and services, and areas in which we believe further clarity is needed.
ITI the Information Technology Industry Council appreciates the opportunity to submit comments to the Cyber Resilience Act (CRA) proposal. ITI represents 80 of the worlds leading information and communication technology (ICT) companies from all corners of the technology sector.
The Alliance for Digital Trust (ACN), with more than 100 members, represents French companies (global leaders, SMEs and mid-caps) in the digital trust sector, in particular cybersecurity, digital confidentiality and trustworthy Artificial Intelligence. The NCA has for many years been calling for public authorities to rely on the importance of digital trust in an increasingly connected world.
Filed in French · English published by the European Commission
FERMA is pleased to provide feedback to the European Commission on the proposed Cyber Resilience Act on behalf of the risk management community. While FERMA is, on the whole, supportive of the intention behind the CRA, namely to raise the level of cybersecurity of digital products in the EU (and beyond), we have some practical concerns, which we hope will be addressed by the time the text is finalised.
Alstom - the leading European supplier of railway equipment (trains, signaling, infrastructure and their maintenance- acknowledges the European Commission's proposal on horizontal cybersecurity requirements for products with digital elements, the Cyber Resilience Act (CRA).
The Association for Computing Machinery (ACM) is the worlds largest and longest established professional society of individuals involved in all aspects of computing. It annually bestows the ACM A.M. Turing Award, often popularly referred to as the Nobel Prize of computing.
Cybersecurity has become indispensable to our economy and society, and can no longer be an add-on to Europes regulatory landscape for products. DIGITALEUROPE strongly welcomes and supports the objectives of the proposed Cyber Resilience Act (CRA), which will for the first time introduce mandatory cybersecurity requirements for products with digital elements.
Japanese Business Council in Europe (JBCE) welcomes the opportunity to contribute to the European Commissions consultation on the Cyber Resilience Act proposal. Attached you will find the feedback of the Japanese Business Council in Europe (JBCE) on the Cyber Resilience Act. The views in the document also reflect those of many domestic industries in Japan.
Please see attached comments from Local Government Denmark (Transparency Reg. # 43783176689-06) concerning the Commission proposal for a Regulation on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020.
Filed in Danish · English published by the European Commission
The Medef is in favour of a general increase in the level of cybersecurity in Europe and therefore the objective pursued by the proposed Regulation. With the development of connected objects and the Internet of Things (IoT), which are central to our daily lives (from watches connected to industrial sensors), it is important to give users access to hardware and software products with fewer vulnerabilities.
Filed in French · English published by the European Commission
Global and European organisations, regardless of whether they are part of the governmental sector, critical infrastructure or private businesses, are subjected to an increased number of cybersecurity risks. As stated in the proposal for a Cyber Resilience Act (CRA), global annual cost of cybercrime is estimated at EUR 5.5 trillion in 2021.
COCIR welcomes the European Commissions proposal on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020 (referred to as Cyber Resilience Act) and its aim to increase the overall level of cybersecurity of all products with digital elements. Please find attached our detailed comments.
Dear European Commission, BlackBerry is a global leader in cybersecurity. For close to 40 years, BlackBerry has invented and built trusted security solutions to give people, governments, and businesses the ability to stay secure, mobile and productive. We have reviewed the draft cyber-resilience act and provide comments in the attached.
CSC considers cybersecurity as one of the key issues of the digital decade and welcomes the Commissions intention to complement the related European regulatory framework with a Cyber Resilience Act. In our view, the proposal recognises cybersecurity risks of digital products and solutions adequately based on well-established international best security practices, and proposes a justified and comprehensive governance…
Insurance Europe welcomes the European Commissions (EC) ambition to raise the level of cybersecurity in the European Union through the introduction of common cybersecurity standards for digital products. The insurance industrys use of digital products will be governed by the forthcoming Digital Operational Resilience Act (DORA).
The German Social Accident Insurance(Deutsche Gesetzliche Unfallversicherung, DGUV), is the umbrella association of the social accident insurance institutions for industry, trade and the public sectors. It looks after the joint interests of its members and promotes the work they do for the benefit of insured persons and enterprises.
Filed in German · English published by the European Commission
DI agrees there is a need to strengthen the cyber security of products in Europe and we support the proposed CRA regulation. We support a horizontal approach to cybersecurity and appreciate that the proposal aims at applying the NLF principles which will ease compliance for our member companies. Never-the-less, adaptations will be needed to clarify the obligations and make them more proportionate.
Alliance Française des Industries du Numérique (Alliance Française des Industries du Numérique) is a professional organisation that brings together almost 60 digital industrialists that manufacture and market the hardware components essential to the digital economy as a whole, from components to connected networks and terminals.
Filed in French · English published by the European Commission
AIOTI welcomes the move to regulate for greater cyber security. Our members are committed to providing security in our products, we welcome steps to create maximum trust among users and consumers of the safety, security, and resilience of their digital products. We want to point out that the value chain of manufacturing electronic devices is more complex than portrayed in the proposed regulation.
In the light of the proliferation of a fragmented regulatory landscape regarding cybersecurity, the ZVEI is a strong long-time proponent for a horizontal cybersecurity regulation for products within the proven new legislative framework (NLF).
We "Europeans for Safe Connections" welcome this initiative and we would like to add some important improvements. Article 10 is about obligations of manufacturers. Among the obligations there is also to publish INFORMATION AND INSTRUCTIONS TO THE USER further defined in Annex II - that is the list of information that the product with digital elements shall be accompanied by.
Arthur Legal, Strategies & Systems welcomes, supports and endorses the Commission' legislative proposal to establish common, horizontal cybersecurity rules and requirements for a wide range of digital products and associated, ancillary services that are placed on the market across the European Union.
Microsoft applauds the European Commissions focus on enhancing the cybersecurity of hardware and software, and we are committed to partnering with the Commission and governments globally to reduce cybersecurity risk. We appreciate the opportunity to provide feedback on the September 2022 proposed European Union (EU) Cyber Resilience Act (CRA) and to contribute to the development of this important legislation.
UP KRITIS welcomes and supports the security by design approach proposed by the Cyber Resilience Act. Only through this approach, and in the context of the increasing importance of attacks in the supply chain and the growing geopolitical implications in the procurement of IT components, can security be guaranteed in the future.
Introducing cybersecurity by design and by default principles into digital products, the proposed EU Cyber Resilience Act (CRA) marks a clear commitment from the European Union to protect millions of businesses and consumers in an increasingly connected world. The draft legislation covers any product with digital elements and applies to manufacturers of hardware and software components and devices.
Siemens AG welcomes a horizontal EU-wide cybersecurity regulation that ensures the functioning of free movement of goods in the EU internal market for covered products. We ask to consider the specifics of products intended to be used by professionals solely in industrial and critical infrastructure domains (e.g.
Tyre manufacturers on the top of manufacturing tyres have been heavily working on a variety of technologies to connect tyres to the internet and digital services accompanying the lifetime of the tyre, known as Tyre-as-a-Service . To this end, our position on Cyber Resilience Act is attached.
As a Qualified Trust Service Provider, InfoCert firmly believes that actions such as the proposed initiative can positively assist the development on the topic of cyber security on a European level. In the attached feedback file InfoCert proposes several focus points for a fruitful development of the topic.
SPECTARIS - the German Industry Association for Optics, Photonics, Analytical and Medical Technologies - welcomes the European Commissions proposal for a Cyber Resilience Act (CRA). In times of constantly changing and increasing cyber threats and risks, regulatory actions to improve the general cybersecurity level of digital products, companies and infrastructures on a European level are of the highest importance.
We, ALE International, a French company operating under the brand name of Alcatel-Lucent Enterprise, delivers Network infrastructure, communication solutions and cloud based communication solutions for business entities and public institutions worldwide. ALE welcomes European Union initiative about cyber security by means of the Cyber Resilience Act.
EUDCA public consultation on the Cyber Resilience Act The European Data Centre Association (EUDCA) represents the European data centre operators and vendors of data centre equipment. The EUDCA is happy to submit feedback on the initiative of the Cyber Resilience Act.
Euralarm, the European trade association representing the electronic fire safety and security industry, has for more than 2 years asked for a horizontal legislation on cybersecurity for products instead of adding pieces of cybersecurity provisions in vertical legislations.
As a Business-to-Business (B2B) provider of cloud communication services, Twilio welcomes the laudable intent of the Cyber Resilience Act (CRA). Protecting critical telecommunications and information infrastructure is a key priority to Twilio.
Bitkom appreciates the opportunity to provide feedback on the Commissions proposal for a Cyber Resilience Act. Please find our position paper attached. We welcome the proposal to create a more efficient legal framework to improve cybersecurity in Europe. Nevertheless, some important aspects should be optimized and clarified during the legislative process.
As an independent Testing, Inspection and Certification (TIC) company, safety, security, and sustainability are our vision and mission. For this reason, we welcome the European Commissions proposal for a Regulation on cybersecurity requirements for products with digital elements to ensure the safety and security of European citizens.
Kaspersky values and supports the continuous efforts of the European Commission to strengthen cybersecurity in the European Union (EU) and, particularly, to introduce horizontal legislation to improve the security of products with digital elements and thus to enable businesses and consumers to use such products securely.
Eurocadres, the representative of Europes Professionals and Managers, is one of three recognised European cross-sectoral social partners, and represents over six million employees. We welcome the Cyber Resilience Act, which can help to bring technical certainty to Professionals and Managers, while addressing important security aspects that impact workplaces in general.
Siemens Healthineers welcomes the European Commissions initiative to introduce horizontal cybersecurity requirements for products with digital elements. We believe that cybersecurity by design is crucial for the security of EU citizens, in particular for patients in Europe, as well as for safe and responsible innovation in healthcare.
(ISC)² is an international nonprofit membership association focused on building a safe and secure cyber world. Our membership, more than 300,000 strong globally, with more than 40,000 throughout Europe, consists of certified cybersecurity professionals responsible for securing governments, economies, critical infrastructure, and personal information.
Effective cybersecurity regulation is crucial to enabling digital transformation of European companies. Beltug, Cigref, CIO Platform Nederland and Voice-e.v. welcome the Commissions ambition to improve the cybersecurity of products with digital elements to enable businesses to use products with digital elements securely in its Cyber Resilience Act (CRA).
Knorr-Bremse Systeme für Schienenfahrzeuge GmbH welcomes the European Commissions work for a comprehensive ruleset enhancing cyber resilience in concept. The view on products with digital elements is an essential step in recognizing the connected and digital characteristics of future industrialization.
Orgalim welcomes the Commissions initiative and is convinced that a coherent regulatory framework is of the highest importance, especially in the context of the smooth functioning of Europes Single Market. We think that the proposal is off to a good start but leaves some room for improvement. With this consultation response, Orgalim would like to share its views on how this proposal could be improved.
Schneider Electric welcomes the opportunity participate to the consultation process of the European Commission on the proposed Cyber Resilience Act. Overall, Schneider Electric supports the European Commissions objective to create a uniform legal framework of essential cybersecurity requirements for products with digital elements.
Deutsche Bahn welcomes the introduction of the CRA and is convinced that it will be a valuable instrument for increasing cyber security. The sector makes use of both sector specific products and services and general-purpose solutions and services. The interplay between vertical and horizontal legislation should be further developed and sector specific legislation adapted accordingly. 1.
UNIFE - the European Rail Supply Industry Association - acknowledges the European Commissions proposal on horizontal cybersecurity requirements for products with digital elements, the Cyber Resilience Act (CRA).
CER (repr. European RUs & IMs) welcomes the introduction of the CRA and is convinced that it will be a valuable instrument for increasing cyber security. The sector makes use of both sector specific products and services and general purpose solutions and services. The interplay between vertical and horizontal legislation should be further developed and sector specific legislation adapted accordingly. 1.
Through its tasks and activities, La Poste Groupe must ensure a high level of detection and response to cybersecurity incidents. In this context, the principles for managing and dealing with cyber risks are one of the challenges facing La Poste Groupe.
Filed in French · English published by the European Commission
Independent Retail Europe welcomes the Cyber Resilience Act, as it will help to achieve a higher level of cyber security for products with digital elements made available in the EU. In this context, retailers have important obligations to fulfil to ensure that they sell to consumers only products with are in conformity with these new cyber security requirements.
MedTech Europe is the European trade association for the medical technology industry including diagnostics, medical devices and digital health. Our members are national, European and multinational companies as well as a network of national medical technology associations who research, develop, manufacture, distribute and supply health-related technologies, services and solutions.
TIC Council, the global trade association representing independent third-party Testing, Inspection, and Certification (TIC) organisations globally, welcomes the objectives of the Commission's proposal for a Cyber Resilience Act. TIC companies provide independent conformity assessment services, ensuring that certified products comply with regulatory requirements and are secure.
First of all, CECAPI would like to thank the European Commission for the draft text given for the CRA to become a leading document aiming to improve the security on the European market and to be a legal reference framework for other legislations.
Please see attached comments of ACT | The App Association (Transparency Reg. # 7202951387754) on the European Commissions proposal for a Regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020.
The European Organisation for Security (EOS), as the representative of the European Industrial and Research Security Community, welcomes the opportunity to provide feedback to the European Commissions proposal for a Cyber Resilience Act.
We understand that the proposed Cyber Resilience Act (CRA) Regulation has a horizontal reach and therefore it could be pertinent to various digital networks, IT systems, and Internet of Things (IoT) solutions commonly deployed in hospitals and healthcare environments not covered by other EU legislation.
Cybersecurity is important, but this Directive severely hampers digital development. Depending on the software, updates may often be made. If a test or a conformity procedure were to be drawn up for each update, this would lead to massive financial burdens and, in particular, to delays in the publication of the updates. Especially in the case of security-related updates, this can have massive negative consequences.
Filed in German · English published by the European Commission
As the European Commission aims to strengthen the EUs cybersecurity policy through the Cyber Resilience Act (CRA), it must ensure that all industry concerns are taken into consideration, as these will be key for the successful adoption and implementation of the CRA.
Dear Members of the EU Commission, The Enel Group, a multinational company and a leading operator in the power and renewables markets of Europe and worldwide, welcomes the Act as a positive step towards a Europe fit for the digital age, and see some possibilities to improve the holistic, practical, executive side of the Data Act, summarised below: 1. Enhanced interplay with EU legislation.
Please find enclosed Opinion No 73/2022 of the German Bar Association (DAV) by its Information Right Committee on the European Commission’s proposal for a Regulation on a Cyber Resilience Act. In its opinion, the DAV concludes that the envisaged parallel application of the Cyber Resilience Act provides multilevel protection alongside the GDPR, albeit from different directions.
Filed in German · English published by the European Commission
On September 15th, 2022, the EU Commission presented a proposal on a Cyber Resilience Act (CRA). DATEV fully shares the Commissions objective to increase the level of cybersecurity of both hardware and software products in the European Union. In order to unfold their full potential, the foreseen legal requirement should be feasible in practice and serve the intended purpose.
With more than 1,000 member companies, eco is the largest Internet industry association in Europe. Since 1995 eco has been instrumental in shaping the Internet, fostering new technologies, forming framework conditions, and representing the interests of members in politics and international committees.
Okta (Transparency Register number 985910748406-44), the leading global identity and access management company, welcomes the opportunity to provide feedback on the proposed regulation for an EU Cyber Resilience Act. Please find our comments in the attached paper.
The exponential growth in the use of connected products makes the security of such devices obvious. As equipment manufacturer we believe that an horizontal regulation covering wireless and wired products connected to internet is needed.
CECE, the Committee for European Construction Equipment, welcomes the European Commissions proposal for a Cyber Resilience Act (CRA). Although the risk of cybersecurity incidents has increased over recent years given the multiplication of connected products on the market and technological changes, CECE wishes to stress that, even today, the construction equipment sector is already committed to assessing the level of…
Enedis, one of the main electricity DSO in Europe and an operator of essential services according to NIS Directive, would like to provide feedback on the proposed Cyber Resilience Act as the company uses and operates products that are directly targeted in the Annex of this Act such as Smart meters, SCADA, IACS The electricity system is a highly critical one, with systemic risks directly concerning DSOs.
This statement provides the Federation of German Consumer Organisations (Verbraucherzentrale Bundesverband - vzbv) feedback for the European Commissions proposal of the Cyber Resilience Act (CRA). vzbv welcomes the European Commis-sions proposal introducing binding and harmonised rules on the cybersecurity of digital products.
Dear ladies and gentlemen, we consider the draft CRA as a milestone in the goal of bringing more cybersecurity to today's digital products in the European Union. Software products are increasingly subject to successful cyberattacks, leading to massive financial cost, to loss of know-how and to risk to people and environment.
The Center for Data Innovation (Transparency Register #: 367682319221-26) is pleased to submit this feedback on the European Commissions consultation and call for evidence regarding the Cyber Resilience Act. The Center previously submitted feedback on the roadmap for the Cyber Resilience Act and has been closely following its development.
We do not agree with your regulation for the following reasons: - we do not want a conformity of the product in question to be presumed and not proven; - you do not specify what a safe product means (or is this also presumed?); - you do not specify what the sanctions are for the manufacturer of a product that harms the interests of a consumer (use of malware software programs by the manufacturer, including backdoor…
It is clear that the CRA is intended to close a gap in previous European digital legislation and does credit to this objective - and in this respect this was the only logical conclusion, because up to now the EU has placed its considerable legislative efforts in digitization in recent years primarily sector-specific and vertical.
FIDO2 authentication devices are not listed among Class II devices in Annex III. Of course, theyre strictly related to Secure elements, Secure cryptoprocessors and Smartcards, smartcard readers and tokens; however, since theres an ad-hoc entry for Hardware Security Modules (HSMs), it may be useful to provide a specific entry for those devices too.
We welcome the proposal on horizontal cybersecurity requirements as it includes several of SMEuniteds preliminary requests. Indeed, a patchwork of rules would hamper the ability of manufacturers of digital products, especially of small and medium size, to operate and scale up across European markets. To ensure legal certainty, we insist that the requirements must be defined precisely.
German industry advocates for the implementation of risk-adequate cybersecurity measures across all products with digital elements during the design, development and production phases as well as when and while a product is placed on the market. We therefore support the European Commissions proposal for the Cyber Resilience Act (CRA) in principle.
BSA welcomes the EU Commissions overall objective in its proposal on horizontal cybersecurity requirements for products with digital elements and amending Regulation (EU) 2019/1020 (EU Cyber-Resilience Act, hereafter CRA) to improve the cybersecurity of products with digital elements to enable businesses and consumers to use products with digital elements securely by mitigating the risk of incidents or attacks that…
The TÜV Association welcomes the European Commissions intention of establishing binding cybersecurity requirements for a broad range of connected products with digital elements. Given the ever-increasing number of cybersecurity incidents across the Union, it is of paramount importance to provide consumers and businesses with secure products both at the time of purchase and over their entire lifecycle.
Atlantic Wireless Telecommunications provide mission critical communications systems to Governments, Semi-State bodies and SME's in the EMEA region. We believe the act should cover Industrial Internet of Things (IIoT) Solutions. A solution should be tested end to end and in situ before awarding a CE mark. This should cover wireline, wireless or hybrid communication systems.
Over 72% of the security requirements (8/11) defined within Annex 1 of the proposed language for the Cyber Resilience Act explicitly calls out the need to protect, identify, remediate, or report vulnerabilities within software.
The European Savings and Retail Banking Group (ESBG) welcomes the European Commissions proposal for a Cyber Resilience Act and supports the goal of only having secure software on the internal market. Banks, as users of the products that fall under the scope of application of this Regulation, support the initiative to guarantee the cyber-resilience of hardware and software products that can be and are acquired by the…
The European Lift Association is representing more than 85% of European companies installing lifts or manufacturing lift components. Having the opportunity to comment on the Cyber resilience act new cybersecurity rules for digital products and ancillary services, we want to point out the following key messages.
CECIMO, as the European Association of Machine Tool Industries and related manufacturing technologies, strongly believes that a Cyber Resilience Act is necessary and that we are pleased that the EC put is working in order to define a structured and harmonized framework for adapting the European economy to the current challenges of the digital transition. However, we have strong concerns about the current proposal.
The Federation of Finnish Enterprises welcomes the Commission’s proposal for a Cyber Resiliency Act and subscribes to its main objectives. In our assessment, the Regulation would, if implemented effectively, improve SMEs’ internal cybersecurity by enabling them to acquire and operate safer digital products.
Please see attached comments of ACT | The App Association (Transparency Reg. # 7202951387754) on the European Commission’s call for evidence for an impact assessment for a Cyber Resilience Act (Regulation on horizontal cybersecurity requirements for digital products and ancillary services).
Confartigianato Imprese welcomes the European Commission’s initiative to establish a law on cyber resilience in order to avoid fragmentation of the single market by creating a clear and well-defined regulatory framework by prescribing specific cybersecurity requirements, such as the whole life cycle of a product.
Filed in Italian · English published by the European Commission
The Occitanie cybersecurity industry has engaged with the Region to respond to this consultation. It identifies several areas where problems are concentrated: emails, product design: software, IoT, updating management, lack of public information, etc. 96 % of the security gaps are linked to the user.
Filed in French · English published by the European Commission
Canada appreciates the opportunity offered by the European Commission to provide feedback on the Commission’s new European Cyber Resilience Act (CRA). Canada strongly supports the legitimate objective of strengthening the cybersecurity of digital products, and recognizes the increased threat to security and privacy caused by the rising number of these products.
EFESME is the European Federation for Elevator Small and Medium-sized Enterprises, and it is active at European and international level to support lift SMEs in their daily work and activities. EFESME represents fifteen members in fourteen member states.
The Institute for Research in Law and Technology of Recife — IP.rec is an independent Brazilian research and policy focus centre focusing on analysing public and technological policies affecting the internet rights ecosystem. IP.rec acts as a reference in the areas of privacy, security and surveillance technologies, with emphasis on cryptography policies.
Filed in Portuguese · English published by the European Commission
Developers Alliance welcomes the opportunity to respond to the call for evidence for an impact assessment on a legislative initiative for common cyber security rules for manufacturers and vendors of tangible and intangible digital products and ancillary services. Please find our comments in the attached document.
As a cyber hub of the Tinexta Group, an Italian company with the participation of the Chambers of Commerce, and through the experience of the companies forming the cluster — Corvallis, Yoroi and Swascan — we believe that actions such as the proposed initiative can work in the right direction to create a fruitful EU exchange on the subject.
Filed in Italian · English published by the European Commission
The Cybersecurity Coalition submits the attached comments in response to the open consultation launched by the European Commission Directorate‑General for Communications Networks, Content and Technology on the Cyber Resilience Act: Regulation on horizontal cybersecurity requirements for digital products and ancillary services.
Response to European Commission Public Consultation on the Cyber Resilience Act Naarden, 25-05-2022 We appreciate the opportunity to respond on behalf of Cyberveilig Nederland, the association of the cybersecurity sector in the Netherlands, to the European Commission Public Consultation on the Cyber Resilience Act.
SMEunited welcomes the initiative for harmonised rules regarding cyber resilience. Manufacturers and developers must be liable to ensure cybersecurity, not sellers. The Cyber Resilience Act must be precise regarding when cybersecurity must be ensured: assessments during the whole lifetime of a product would be costly. We recommend a mixed approach, combining both soft and hard rules.
The European DIGITAL SME Alliance will provide further details in a position paper, when more information about the Act is know. At present, we are able share some general thoughts on the Act: • DIGITAL SME recognises the need for increased cybersecurity and welcomes efforts to ensure that European products are more secure and that customers can be confident in the security of their purchase.
>>Challenges: GISAD welcomes the EU Commission's intention for a cyber resilience law. However, it is doubted that even option 5 will achieve the desired purpose. Politicians always want to regulate something after the fact, when a wrong development has been identified.
The European Automobile Manufacturers' Association (ACEA) supports the Commission’s objective of enhancing and ensuring a high level of cybersecurity for digital products and related services and of setting up a level playing field for vendors. This will help increase resilience against a continuously evolving and more complex cyber threat landscape.
Ref. Ares(2022)1955751 - 17/03/2022 Dear recipient, Technology Industries of Finland (later TIF) wishes to thank European Commission for the possibility to be heard on the matter of European Commission’s call for evidence for an impact assessment on Cyber Resilience Act. Please find our position paper attached.
Arthur's Legal, Strategies & Systems welcomes, supports and endorses the Cyber Resilience Act initiative. In this Digital Age, digital is not a nice to have anymore but a need to have. People, organisations (public, private and other) and society at large are depending on those, while (a) not in meaningful control and (b) more and more becoming vulnerable to detrimental cyber threats, all this throughout the various…
Liberty Global welcomes the opportunity to comment on the European Commission’s call for evidence for an impact assessment of the likely initiative ‘Regulation on horizontal cybersecurity requirements for digital products and ancillary services’ (Cyber Resilience Act).
Opinion of Stockholm Region Digitalisation and rapid technological developments provide new value creation opportunities and benefits for society, but also new challenges. Today, there are large amounts of digital products and related services on the market with a lack of protection.
Filed in Swedish · English published by the European Commission
Eurosmart fully supports the CRA general objective but would recommend a scalable approach for both hardware and software products. The CRA should clearly define the type of products falling under its scope since the market access and market surveillance rules are closely bound with liability.
The Austrian Chamber of Commerce recognises the European Commission’s objectives to strengthen cyber resilience, as a cybersecurity incident can undoubtedly lead to enormous financial burdens due to business disruption (e.g. due to a ransomware attack), reputational damage to businesses and a threat to the security of our economy and society.
Filed in German · English published by the European Commission
We appreciate and welcome the initiative of the Commission to put forward its upcoming Cyber Resilience Act. Orgalim is convinced that a coherent regulatory framework is of the highest importance, especially in the context of the smooth functioning of Europe’s Single Market.
ITI - The Information Technology Industry Council appreciates the opportunity to submit comments to the European Commission on the Cyber Resilience Act consultation. ITI is the premier global advocate for technology, representing the world’s most innovative companies. Founded in 1916, ITI is an international trade association with a team of professionals on four continents.
APPLiA represents Home Appliance Industry in Europe. We provide more details in the attached file. The brief summary can be outlined here: Whilst the NIS and NIS2 Directives properly address organisations with a set of consistent requirements, there is a risk that our products are regulated by different, disconnected pieces of legislation.
IBM welcomes the opportunity to contribute to the European Commission’s consultation on the Cyber Resilience Act (CRA) and to offer our views on how we believe the EU can build a strong cybersecurity environment and increase its resilience against a continuously evolving and more complex cyber threat landscape.
Beltug, the Belgian association of CIOs and digital technology leaders represents business users of digital technologies in Belgium. We have 500 members from all secotors of the economy, including government agencies, universities, hospitals as well as companies from all sectors of the economie.
ANEC supports the broad scope of the initiative and agrees that a robust and coherent EU legislative intervention on cybersecurity will provide a more effective, less-fragmented protection for consumers. ANEC agrees that the CRA will complement and close gaps in the existing EU legislative framework. We submit the attached position.
The German Electro and Digital Industry Association (ZVEI) welcomes the opportunity to provide feedback to the Impact Assessment of the European Commission. Cybersecurity, as a cross-cutting task is a top priority at ZVEI in all its lead markets: Industry 4.0, energy, mobility, components, building, health and consumer electronics.
CIGREF welcomes the European Commission’s approach to introducing regulation on cyber resilience. We support the need to impose cybersecurity requirements on all digital products and services throughout the European Union as envisaged by the Cyber Resilience Act.
Filed in French · English published by the European Commission
Digital health and care technologies can innovate and improve access to care and quality of care and make healthcare delivery more efficient. Providing secure devices and services and keeping users and patients safe and protected is a core goal of the medical technology industry.
Enedis, one of the main electricity DSO in Europe and an operator of essential services according to NIS Directive, would like to provide recommendations on the upcoming Cyber Resilience Act. The electricity sector is highly critical: electric systems must be balanced every second in terms of loads and generation.The vocation of any electrical entity, especially a DSO, is to guarantee the delivery of electricity to…
— Improving the cybersecurity of digital devices and their ancillary services is a necessary element to address overall cybersecurity improvement, prevent incidents, and enable more trustworthy use of products by society at large.
Filed in Spanish · English published by the European Commission
ESB Networks Ltd. (ESBN), a regulated subsidiary within ESB Group, is the licensed operator of the electricity distribution system in the Republic of Ireland. ESBN is responsible for building, operating, maintaining and developing the electricity network and serving all electricity customers in the Republic of Ireland.
ETSI welcomes the call for evidence for an impact assessment related to a potential Cyber Resilience Act. Developing standards that enable a sustainable and securely connected society has been at the heart of ETSI work for more than 30 years both as a broadly inclusive global international standards body, and in its European Standardization Organization role.
Over the years BusinessEurope consistently called for encouragement of all players in the value chain to ensure products, processes and systems are cybersecure from the earliest stage of the engineering process in a dynamic way, thereby also promoting responsible innovation through security-by-design.
The Center for Data Innovation (Transparency Register #: 367682319221-26) is pleased to submit this feedback on the European Commission’s consultation and call for evidence regarding the Cyber Resilience Act initiative.
Please find attached the contribution of the European Cyber Security Organisation (ECSO). The European Cyber Security Organisation (ECSO) is a non-for-profit organisation, established in 2016 to support the Public – Private Partnership on cybersecurity with the European Commission.
The current approach towards cyber security has been focusing mainly on processes and technology. Cuccibu would like to bring attention on the importance of a resilient approach in setting ISMS as a governance structure allowing organizations to overcome cyber attacks as well as a way to set up procedures to recover as fast as possible from different types of disasters.
As the European Union’s economy and society continue to embrace digital solutions, there is an urgent need to ensure that the EU’s networks and information systems are resilient against evolving cyberattacks. The American Chamber of Commerce to the European Union (AmCham EU) supports a strong cybersecurity environment in Europe, which is the responsibility of government and industry alike.
Software, connected hardware, and network-connected services are integral to society, creating a wide spectrum of benefits and risks. Increasing connectivity, more critical use scenarios, and escalating cyber threats underline a significant and growing need to develop multi-faceted and coordinated strategies to address substantial risks.
The National Council of Commercial Court Registrars (CNGTC) welcomes the European Commission’s initiative on the Cyber Resilience Act, which aims, on the one hand, to enhance and ensure a high level of cybersecurity for digital products and, on the other hand, to allow users to choose the level of security according to their need.
Filed in French · English published by the European Commission
[See our full feedback in the attachment.] The Federation of Finnish Enterprises agrees with the general objectives of the Commission’s initiative concerning the Cyber Resilience Act. The level of cybersecurity of digital products and ancillary services offered in Member States for SMEs needs to be raised and the fragmentation of the internal market with respect to cybersecurity rules prevented.
The TÜV Association welcomes the Commission’s intention of establishing binding cybersecurity requirements for a broad range of products and services. To date, the EU is lacking an all-encompassing approach to cybersecurity. Cybersecurity provisions in current legislation are either limited to specific product groups or are only applicable on a voluntary basis.
The TIC Council, representing the independent Testing, Inspection, and Certification (TIC) companies, welcomes the Commission’s intention of proposing a Cyber Resilience Act. Indeed, the TIC Council views with great interest the introduction of harmonised minimum requirements to ensure baseline principles for the cybersecurity for digital products and their associated services in the EU.
Kaspersky very much welcomes the fact that the European Commission, in the spirit of a good legislative process, is offering the various stakeholders the opportunity to share their ideas to the upcoming Cyber Resilience Act. Kaspersky hopes that this paper could be of value in the further legislative process.
The Enel Group, a multinational company and a leading operator in the power and renewables markets of Europe, welcome the public consultation on the possibilities to build up a holistic European Cyber Resilience Act. Please find attached the complete response to the consultation, while below you may find a brief overview of their recommendations on how to improve cyber resilience in Europe: I.
DI supports the ambition to strengthen cyberresilience in Europe. We are in favor of policy option 4 with the modification that we do not believe ancillary services should be included. From Option 5 we would support the inclusion of embedded software and also non-embedded (standalone software) with an intended use to be integrated into specific products, preferably only for critical software.
In response to the request for contributions to this consultation, the Cybersecurity Coordination Office (OCC) of the State Secretariat for Security of the Ministry of the Interior submits the following. The OCC takes into account the EU regulatory framework governing cybersecurity, the advantages (speed of development) and disadvantages (lack of validity for all EU Member States) of cybersecurity certifications…
Filed in Spanish · English published by the European Commission
CLEPA supports the Commission’s objective of enhancing and ensuring a high level of cybersecurity for digital products and related services. We also welcome the objective of setting up a level playing field for vendors.
About eco: With more than 1,000 member companies, eco is the largest Internet industry association in Europe. Since 1995, eco has been instrumental in shaping the Internet, fostering new technologies, forming framework conditions, and representing the interests of members in politics and international committees.
ESMIG members would like to share their feedback on the call for evidence on the Cyber Resilience Act. In the past few years, cyber and information security topics, network protection, security risk management, security governance, security certification and data protection have been addressed with several legislative and regulatory directives, acts and frameworks, like the Network and Information Security (NIS)…
IDW very much welcomes the Call for Evidence “Cyber Resilience Act” and thanks you for the opportunity to comment on the Commission's legislative plans. We share Madam President’s view that Europe should strive to become a leader in cybersecurity (CS).
None of the current EU-instruments specifically addresses the cyber security of the EV-recharging infrastructure at this moment in time. The EU-policy regarding the cyber security of recharging infrastructure seems scattered and there is no comprehensive approach. In this context, the proposed Cyber Resilience Act may act as a safety net to fill in the legislative gaps which are not covered by specific instruments.
Hello, Finally, a bombing against abusive AI in the cyber space also: In order for regulatory intervention at EU level to establish a high level of trust among users, thus increasing the attractiveness of EU digital products and ancillary services, I think there is a need for a kind of common validation and certification: inspired by the civil aviation industry in theory and practice of monitoring... Good for you
Filed in French · English published by the European Commission
As the Commission has opened consultations on the Cyber Resilience Act, the aim of this new initiative seems to be to improve the internal market’s functioning by streamlining and supplementing existing rules applicable to digital products and preventing further fragmentation of cybersecurity requirements for digital products and ancillary services in the market.
BD is one of the largest global medical technology companies in the world and is advancing the world of health by improving medical discovery, diagnostics, and the delivery of care. BD helps customers enhance outcomes, lower costs, increase efficiencies, improve safety, and expand access to healthcare.
Fecc acknowledges the consultation on the Cyber Resilience Act and welcomes the opportunity to provide input. In this context, we would like to raise the following points in this consultation: 1. The synergy between the Cyber Resilience Act and current national initiatives should be put into perspective.
CPME welcomes the initiative of the European Commission to consult on a possible legislation on cyber-resilience. Cybersecurity is a major issue for the sustainability of our companies and its importance will increase in the coming years. A European response is therefore essential.
Madam/Sir, In response to the consultation and call for evidence of the Commission’s proposal for EU Cybersecurity Resilience Act, we would like to submit the following. We understand that the Commission is not shy to commit the initiative to place obligations on economic operators, and introduce provisions regarding the conformity assessment and the notification of conformity assessment bodies.
1) Cyber resilient product as reasonable expectation of the customer It would be nice to see cyber resilience/security of a product or service being provided to customers (B2B ro B2C) as part of normal functioning of a product.
EUTC Input to the Public Consultation on an EU Cyber Resilience Act. The European Utilities Telecom Council (EUTC) is pleased to provide an input to the above legislation. EUTC represents European electricity generation, transmission and distribution companies and associated vendors plus equivalent operations in public gas and water utilities.
Cybersecurity requires technologies and procedures. It involves trusted authorities and users (at least). Resilience against cyber attacks thus depends on technologies and procedures. Technologies shall not be specified such that specific equipment is needed (e.g. smart phones). Technologies shall be specified such that these are future-proof (e.g. replace security algorithms by new ones).
This project is a step in the right direction. In terms of cybersecurity, the two key concepts are Risks and Trust. The aim of the scheme should be to create an ecosystem to build trust and reduce risks related to the security of digital products/services.
Filed in French · English published by the European Commission
Security and privacy in digital products delivered in the EU must be CE certified (as any other product) as secure and respecting data privacy. Also the last point (privacy) must be addressed by means of new disruptive technologies that by default must guarantee user data protection as GDPR alone, being only normative rules, is not sufficient even now and more in the future digital systems (6G, AI, IoT, etc.).
Method. Every quote is verbatim from the organization’s own submission to the European Commission, trimmed to its opening passage and never summarized by a model. Where a submission was filed in another EU language we show the English text the European Commission publishes alongside it, labeled on the quote; the original is one click away at the source. Groupings use the respondent type the organization itself selected when filing. We deliberately do not label anyone “supportive” or “opposed” — you read what they wrote and draw your own conclusion. Organizations only, never individuals. Reused under Commission Decision 2011/833/EU; the European Commission is not liable for this reuse.