Mensch Hände Smartphone
Article

Cyber Resilience Act: EU enhances cyber resilience of hardware and software

Smart home, smart mobility and Industry 4.0: from everyday life to transport and factory production, more and more areas of our daily lives are becoming ‘smarter’ – that is, more digital and therefore more connected. According to recent studies, the average number of connected devices (IoT devices) per household in Europe is 17.4 – higher than the international average. The ongoing spread of digital technologies is creating a multitude of new opportunities for both private and commercial users. However, digitalisation also brings with it numerous challenges in terms of security and data protection.

In businesses, the use of sensors and actuators in machinery and plant enables real-time monitoring as well as predictive maintenance based on this data. Companies are increasingly offering not only hardware solutions such as production machinery, but also digital platform- and app-based services.

However, connected products are constantly exposed to threats from cybercriminals. These risks can be addressed through targeted technical, regulatory and behavioural measures (e.g. security by design). German industry is already investing in the cyber security of products, processes, people and services. Nevertheless, 100 per cent cyber security cannot be achieved, let alone guaranteed.

Cyber Resilience Act: Introduction of mandatory minimum requirements

Against the backdrop of the increasing digital transformation in households and industry, as well as the persistently high level of cyber threats, the European Commission proposed the Cyber Resilience Act in 2021. The European Council and the European Parliament reached agreement on a joint legislative text at the end of 2023. The Cyber Resilience Act introduces mandatory cybersecurity requirements for all products containing digital elements. In addition, the Cyber Resilience Act establishes a vulnerability management framework for the manufacturers of these products. By combining cybersecurity requirements with vulnerability management, the cyber resilience of products is strengthened throughout the entire value chain – from design, through production and placing on the market, to operation. The industry must implement the requirements by the end of 2027.

BDI backs regulatory proposals – companies must now implement the requirements

For businesses, coherent legal frameworks are crucial to enabling the development and marketing of products that comply with legal requirements. The BDI has therefore – in collaboration with the German Institute for Standardisation DIN and the German Commission for Electrical, Electronic and Information Technologies DKE, as well as the German Engineering Federation (VDMA), the German Electrical and Digital Industry Association (ZVEI) and Bitkom – to advocate, between 2019 and 2022, for the introduction of horizontal cybersecurity requirements based on the principles of the New Legislative Framework, the regulatory framework for European product regulation. The German business community therefore supports the European Union (EU) in its efforts to holistically strengthen Europe’s cyber resilience by introducing cybersecurity requirements for all products containing digital elements. The Cyber Resilience Act will assist operators of critical infrastructure, as well as very important and important facilities, in implementing their risk management measures in accordance with the NIS 2 Directive.

The legislation that has now been adopted places significant demands on manufacturing companies, as they must implement the far-reaching requirements of the Cyber Resilience Acts within three years. At the same time, cyber-resilient products will be of particular help to those companies that need to comply with the cybersecurity requirements of the NIS 2 Directive. If only cyber-resilient products (hardware and software) are available on the European market, this will make it considerably easier to implement risk management measures.

Coherent national implementation

German industry supports the objective of the Cyber Resilience Act (CRA) A) to introduce horizontally binding requirements for the cybersecurity of products containing digital elements. For the effective implementation of the CRA, it is essential that each Member State designates at least one market surveillance authority and one notifying authority. German industry therefore generally welcomes the Federal Government’s current draft bill, as it consistently drives forward the implementation of the CRA.

Companies already implements a high level of security for products with digital elements through risk-based cyber resilience measures. To ensure the practical implementation of the CRA, we recommend:

  • Market supervision with sufficient capacity: Strong and competent market supervision is a fundamental component of the effective implementation of the CRA and is therefore expressly supported by the BDI.
  • Support measures for the businesses: We also view the support measures for affected companies set out in the draft act – such as awareness-raising and training programmes or the introduction of a real-world laboratory for cyber resilience – as very positive. Such measures can significantly facilitate the implementation of the CRA requirements, particularly during the early implementation phase.
  • Practical further development of the CRA at EU level: In addition to the planned support measures, however, German industry considers targeted amendments to the Cyber Resilience Act at European level to be a necessary step that goes beyond these measures.
Related Publications
Contact

Steven Heckler

Senior Expert Innovation, Security and Technology