Skip to main content
PolicySpeak
← All files

EU consultation

Technical description of important and critical products with digital elements

67 submissions from 67 organizations told the European Commission what they think about this file. Here is what each of them said, in their own words.

The Commission lists 122 submissions on this file. Shown here: the 67 from organizations. Not shown, by design: submissions from private individuals, which we never publish, and anything filed since our last weekly refresh.

Who showed up

46 submissions from industry — companies and their trade associations — against 8 from civil society: NGOs, consumer organizations, environmental groups and trade unions. That is 5.8 industry submissions for every one from civil society.

Industry 46Civil society 8Public authorities, academia, other 13

Groupings use the respondent type each organization selected when filing. Counting submissions, not organizations — a body that filed twice is counted twice.

What the room declares

36 of 67
in the EU Register
178
full-time lobbying staff
€27.7M+
declared costs a year
133
EP accreditations declared

Self-declared to the EU Transparency Register (snapshot 30 Aug 2026). The cost figure sums band floors, so the true total is higher.

The file, right now

The consultation closed on 18 Apr 2025 — it ran from 13 Mar 2025.

Policy area
Digital & tech (DG CNECT)
Where it stands
Awaiting adoption
Adoption expected
30 Sept 2025

How it got here

  1. Draft implementing regulation18 Apr 2025

Also on the Commission’s pipeline for this file, with no date recorded: Initiative planned, Implementing regulation.

67 positions · showing 25

AN

Adyen NV

· · filed 18 Apr 2025 · source

PDF

Attached are our detailed comments. The keys aspects to address are the descriptions of the critical products, ensuring that open-source solutions are not biassed against, and that certified and non-certified products are treated equally with respect to the CRA annex I part II requirements.

LinkedInX
BD

Black Duck Software

· · filed 18 Apr 2025 · source

PDF

From the perspective of a supplier of products with digital elements, one core assumption is that any product with digital elements is brought into scope under Regulation 2024/2847 due to its inclusion in at least one class under Annex III or Annex IV. Where a product with digital elements might require a conformity assessment based on multiple classes, only the first class need apply.

LinkedInX
EF

Eclipse Foundation AISBL

· · filed 18 Apr 2025 · source

PDF

The Open Regulatory Compliance (ORC) Working Group of the Eclipse Foundation thanks the European Commission for the opportunity to provide input to this draft implementing regulation. We take the opportunity to thank the Commission for the clarifications provided by the recitals which shine a light on areas that were a source of concern and confusion for the open source community.

LinkedInX
E

Eurosmart

· · filed 18 Apr 2025 · source

PDF

The attached document compiles the feedback provided by Eurosmart on the draft Implementing Regulation concerning the technical description of the categories of important and critical products with digital elements.

LinkedInX
L

LightingEurope

· · filed 18 Apr 2025 · source

PDF

We thank the European Commission for this opportunity to provide our feedback to an essential Implementing Regulation of the CRA. LightingEurope would like to request clarification regarding the classification of 10. Physical and virtual network interfaces under Class I (Important Products) in Annex I of the draft Implementing Regulation on product categories for the Cyber Resilience Act (CRA).

LinkedInX
TB

TrustCB B.V.

· · filed 18 Apr 2025 · source

We value the CRA and the impulse it will give to bringing state of the art security to a vast spread of devices. The assignment of various devices in categories still requires more clarification and consensus building with the stakeholders, with priority on the biggest impact devices already having an existing industrywide aligned and operational schemes.

LinkedInX
NC

NMi Certin B.V.

· · filed 18 Apr 2025 · source

Implications of the Cyber Resilience Act on Manufacturers and Integrators The Cyber Resilience Act (CRA) aims to enhance the cybersecurity of products with digital elements within the EU. This paper discusses how manufacturers can comply with the CRA, focusing on the implications for different types of products and the responsibilities of integrators. Manufacturers' Compliance with the CRA 1.

LinkedInX
W

WindEuope

· · filed 18 Apr 2025 · source

PDF

WindEurope Feedback Summary on the Draft Implementing Regulation (Cyber Resilience Act) WindEurope welcomes the European Commissions initiative to develop a harmonized framework for identifying important and critical products with digital elements under the Cyber Resilience Act (CRA). We support the effort to enhance cybersecurity across sectors and appreciate the opportunity to provide input.

LinkedInX
OE

Orgalim, Europe's Technology Industries

· · filed 18 Apr 2025 · source

PDF

Orgalim represents Europes technology industries, comprised of 770 000 innovative companies spanning the mechanical engineering, electrical engineering, electronics, ICT and metal technology branches. Together they represent the EUs largest manufacturing sector.

LinkedInX
E

EURALARM

· · filed 18 Apr 2025 · source

PDF

Euralarm is pleased to provide their feedback on the proposal from the European Commission for the technical description of 2 categories of products with digital elements: - Annex I, Class I, 17. Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems - Annex II, 1. Hardware Devices with Security Boxes. See the feedback attached.

LinkedInX
PE

Panasonic Europe B.V.

· · filed 18 Apr 2025 · source

PDF

Panasonic welcomes the opportunity to provide feedback to the European Commission's public consultation on the Cyber Resilience Act Implementing Act. We acknowledge the significance of this act in providing clarity and practical guidance for the CRA's effective implementation. Stakeholder input is crucial for robust and technically sound legislation that fosters a secure digital ecosystem.

LinkedInX
D

DIGITALEUROPE

· · filed 18 Apr 2025 · source

PDF

Thank you very much for the opportunity to react to this draft implementing act. Whilst we are appreciative of the substantial work already done, we see a need for further improvements to the both the recitals and technical descriptions, predominantly to provide greater legal certainty.

LinkedInX
TD

T&D Europe

· · filed 18 Apr 2025 · source

PDF

Despite the very good effort to technically clarify the family of products under Class I, II and III, some uncertainties and unclear elements are still present. Special attention should be given to class III equipment where the description is still very vague and , in some cases , not bringing the needed clarification of scope.

LinkedInX
GC

GIE Cartes Bancaires CB

· · filed 18 Apr 2025 · source

PDF

GIE Cartes Bancaires CB (CB for short) is an economic interest grouping (GIE) which has, in France, sovereign authority over all CB-branded payments. Among the many tasks entrusted to it, it grants CB the approval of products that operate in the CB system, including card products, payment terminals and payment HSMs. Please find attached our comments.

LinkedInX
EE

European Electronic Component Manufacturers' Association

· · filed 18 Apr 2025 · source

PDF

Executive Summary Semiconductors are key components of everyday electronic devices that make life easier, safer, more secure, and greener. From ground and air transportation to pass-ports, payment cards, terminals, servers in data centres, desktop computers, sensors, etc., semiconductors are ubiquitous, fulfilling a crucial role in the whole domain of the Cyber Resilience Act (CRA).

LinkedInX
SA

Siemens AG

· · filed 18 Apr 2025 · source

PDF

From a Siemens AG perspective, it is essential that companies are being given sufficient time to prepare the implementation of the CRA. We feel that the current deadlines are very challenging and force companies to allocate significant resources to it. This is also valid for the European standardisation activities which will rely on those technical descriptions. Simplification of the framework is therefore critical.

LinkedInX
NS

NXP Semiconductors B.V.

· · filed 18 Apr 2025 · source

PDF

NXP thank you for the opportunity to provide comments to the Draft Implementing Regulation. Please find our contribution in the attached document, addressing the semiconductors listed as Products with Digital Elements in Class I, Class II, and Critical products within the Cyber Resilience Act, and the proposed Implementing Regulation.

LinkedInX
ES

Enel SpA

· · filed 18 Apr 2025 · source

PDF

Dear Members of the European Commission, The Enel Group, a multinational company and a leading operator in the power and renewables markets of Europe, welcome the public consultation on the possibilities to build up a holistic European Cyber Resilience Act. Please find attached the complete response to the consultation. Best regards, [name removed]

LinkedInX
U

UNIFE

· · filed 18 Apr 2025 · source

PDF

As representative of the rail supply industry, UNIFE is very active in making the implementation of the CRA in the railway sector streamlined and efficient. Collaborating to the production of implementing acts and guidelines for the CRA is a key part of this process. The CRA encompasses a very broad ensemble of products in very different sectors, all with their own specificities.

LinkedInX
AI

Associazione Italiana Internet Provider

· · filed 18 Apr 2025 · source

PDF

Associazione Italiana Internet Provider (AIIP) welcomes the opportunity to provide feedback on the draft implementing regulation of the Cyber Resilience Act (CRA) and wishes to highlight critical aspects that may significantly impact small and medium-sized enterprises (SMEs), especially those that develop software internally for self-consumption or contribute to the open-source ecosystem.

LinkedInX
CS

Cyber Security Platform (CSP) - Austria

· · filed 18 Apr 2025 · source

PDF

The Cyber Security Platform (CSP) is an Austrian public-private partnership that was founded in 2015 as part of the Austrian Strategy for Cybersecurity (ÖSCS) and counts 500+ security experts as members. The CSP supports the Cyber Security Steering Group (CSS) in improving cybersecurity in Austria below the political and above the technical level.

LinkedInX
F

Fujitsu

· · filed 18 Apr 2025 · source

We appreciate the opportunity to contribute to the consultation on the draft implementing regulation under Article 24(9) of the Cyber Resilience Act (CRA). Fujitsu, as a global Japanese company with a significant presence in Europe and deep expertise in B2B services, cloud and on-premise infrastructure, IoT, and cutting-edge fields such as quantum computing and artificial intelligence, we fully support the…

LinkedInX
RI

Research Institute for Visual Computing

· · filed 18 Apr 2025 · source

PDF

Dear madams or sirs, please find attached our comments on the available draft Commission Implementing Regulation on the technical description of the categories of important and critical products with digital elements pursuant to Regulation (EU) 2024/2847 of the European Parliament and of the Council. Please do not hesitate to come back to our research institute for further dialogue on this topic.

LinkedInX
IT

Information Technology Industry Council

· · filed 18 Apr 2025 · source

PDF

Thank you for the opportunity to provide comments on the draft Implementing Act concerning the technical descriptions of the categories of important and critical products with digital elements pursuant to the Cyber Resilience Act. Please find attached the response of the Information Technology Industry Council (ITI).

LinkedInX
KB

Knorr-Bremse Systeme für Schienenfahrzeuge GmbH

· · filed 18 Apr 2025 · source

PDF

Knorr-Bremse supports the objectives of the Cyber Resilience Act (CRA) and acknowledges the European Commissions efforts to clarify the technical descriptions of the categories of important and critical products with digital elements listed in Annexes III and IV of the Regulation, through its review of stakeholder feedback.

LinkedInX
Take the dataCSV — all 67 submissionsJSONFull text, not the excerpt. Free to cite.Search every submission →

Follow this file

Get an email when a new organization files a position here: one email on Tuesdays, only when there is something new. Free.

We use your email for updates on this file, and PolicySpeak may contact you about the product. Unsubscribe in one click. Privacy policy.

Method. Every quote is verbatim from the organization’s own submission to the European Commission, trimmed to its opening passage and never summarized by a model. Where a submission was filed in another EU language we show the English text the European Commission publishes alongside it, labeled on the quote; the original is one click away at the source. Groupings use the respondent type the organization itself selected when filing. We deliberately do not label anyone “supportive” or “opposed” — you read what they wrote and draw your own conclusion. Organizations only, never individuals. Reused under Commission Decision 2011/833/EU; the European Commission is not liable for this reuse.