|
CRA1
Article 13 - Obligations Of Manufacturers
|
Criterion XX, The manufacturer shall ensure that, when placing a product with digital elements on the market, it has been designed, developed and produced in accordance with the essential cybersecurity requirements set out in Part I of Annex I of the Cyber Resilience Act.
Proof of compliance: Declaration/certification
Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidence about the provision covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail:
(i) how products with digital elements are designed, developed, and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks, including reference to the cybersecurity risk assessment referred to in Article 13(2) of the EU Cyber Resilience Act.
(ii) How, on the basis of the cybersecurity risk assessment and where applicable, products with digital elements:
a. are made available on the market without known exploitable vulnerabilities;
b. are made available on the market with a secure by default configuration, unless otherwise agreed between manufacturer and business user in relation to a tailor-made product with digital elements, including the possibility to reset the product to its original state;
c. ensure that vulnerabilities can be addressed through security updates, including, where applicable, through automatic security updates that are installed within an appropriate timeframe enabled as a default setting, with a clear and easy-to-use opt-out mechanism, through the notification of available updates to users, and the option to temporarily postpone them;
d. ensure protection from unauthorized access by appropriate control mechanisms, including but not limited to authentication, identity or access management systems, and report on possible unauthorised access;
e. protect the confidentiality of stored, transmitted or processed data, personal or other, such as by encrypting relevant data at rest or in transit by state of the art mechanisms, and by using other technical means;
f. protect the integrity of stored, transmitted or otherwise processed data, personal or other, commands, programs and configuration against any manipulation or modification not authorised by the user, and report on corruptions;
g. process only data, personal or other, that are adequate, relevant and limited to what is necessary in relation to the intended purpose of the product with digital elements (data minimisation);
h. protect the availability of essential and basic functions, also after an incident, including through resilience and mitigation measures against denial-of-service attacks;
i. minimise the negative impact by the products themselves or connected devices on the availability of services provided by other devices or networks;
j. are designed, developed, and produced to limit attack surfaces, including external interfaces;
k. are designed, developed and produced to reduce the impact of an incident using appropriate exploitation mitigation mechanisms and techniques;
l. provide security related information by recording and monitoring relevant internal activity, including the access to or modification of data, services or functions, with an opt-out mechanism for the user;
m. provide the possibility for users to securely and easily remove on a permanent basis all data and settings and, where such data can be transferred to other products or systems, ensure that this is done in a secure manner.
Permissible Standards: N/A
Note: The evidence may be provided through product and/or technical documentation, security architecture descriptions, conformity assessment reports, or equivalent documentation, provided that the wording and scope of the evidence correspond to the requirements set out in Part I of Annex I of the EU Cyber Resilience Act.
|
|
|
CRA2
Article 13 - Obligations Of Manufacturers
|
Criterion XX. The Manufacturer shall ensure there are specific provisions regarding procedures for assessment of the cybersecurity risks associated with a product with digital elements.
Proof of compliance: Declaration/certification
Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidence about the provision covering the criterion, either (i) copied from the legally binding document, or (ii) by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail:
a. documented process ensuring that the outcome of that assessment into account during the planning, design, development, production, delivery and maintenance phases of the product with digital elements with a view to minimising cybersecurity risks, preventing incidents and minimising their impact, including in relation to the health and safety of users.
b. documented process ensuring that the cybersecurity risk assessment is documented and updated as appropriate during the vulnerability handling support period;
c. documented process ensuring that the cybersecurity risk assessment comprises at least an analysis of cybersecurity risks based on the intended purpose and reasonably foreseeable use, as well as the conditions of use, of the product with digital elements, such as the operational environment or the assets to be protected, taking into account the length of time the product is expected to be in use.
d. Requires further analysis. documented process ensuring that the cybersecurity risk assessment indicates whether and, if so in what manner, the security requirements set out in Part I, point (2), of Annex I are applicable to the relevant product with digital elements and how those requirements are implemented as informed by the cybersecurity risk assessment. It shall also indicate how the manufacturer is to apply Part I, point (1), of Annex I and the vulnerability handling requirements set out in Part II of Annex I.
e. Requires further analysis. documented process indicating that, when placing a product with digital elements on the market, the manufacturer includes the cybersecurity risk assessment referred to in paragraph 3 of this Article in the technical documentation required pursuant to Article 31 and Annex VII. For products with digital elements as referred to in Article 12, which are also subject to other Union legal acts, the cybersecurity risk assessment may be part of the risk assessment required by those Union legal acts. Where certain essential cybersecurity requirements are not applicable to the product with digital elements, the manufacturer shall include a clear justification to that effect in that technical documentation.
Permissible Standards: N/A
|
|
|
CRA3
Article 13 - Obligations Of Manufacturers
|
Criterion XX. The Manufacturer shall exercise due diligence when integrating components sourced from third parties so that those components do not compromise the cybersecurity of the product with digital elements, including when integrating components of free and open-source software that have not been made available on the market in the course of a commercial activity.
Proof of compliance: Declaration / certification
Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidences about the provisions covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail:
(a) documented due diligence processes applied when integrating components sourced from third parties, demonstrating that such components do not compromise the cybersecurity of the product with digital elements;
(b) documented assessment, review, or inventory of third-party components, including components of free and open-source software that have not been made available on the market in the course of a commercial activity, showing how cybersecurity risks associated with those components are identified and addressed;
(c) internal policies, procedures, or attestations demonstrating ongoing governance of third-party component integration with regard to cybersecurity of the product with digital elements.
Permissible Standards: N/A
|
|
|
CRA4
Article 13 - Obligations Of Manufacturers
|
Criterion XX. The manufacturer shall systematically document, in a manner that is proportionate to the nature and the cybersecurity risks, relevant cybersecurity aspects concerning the products with digital elements, including vulnerabilities of which they become aware and any relevant information provided by third parties, and shall, where applicable, update the cybersecurity risk assessment of the products.
Proof of compliance: Declaration / certification
Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidences about the provisions covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail:
(a) documented cybersecurity information relating to the product with digital elements, proportionate to its nature and cybersecurity risks, including records of identified or reported vulnerabilities;
(b) documentation showing how relevant cybersecurity information provided by third parties is collected, assessed, and incorporated into the product’s cybersecurity documentation;
(c) documentation demonstrating that, where applicable, the cybersecurity risk assessment of the product with digital elements is updated to reflect newly documented cybersecurity aspects or vulnerabilities.
Permissible Standards: N/A
|
|
|
CRA5
Article 13 - Obligations Of Manufacturers
|
Criterion XX. The Manufacturer shall have appropriate policies and procedures, including coordinated vulnerability disclosure policies, referred to in Part II, point (5), of Annex I of the Cyber Resilience Act, to process and remediate potential vulnerabilities in the product with digital elements reported from internal or external sources.
Proof of compliance: Declaration / certification
Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidences about the provisions covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail:
(a) documented policies and procedures to process and remediate potential vulnerabilities in the product with digital elements reported from internal or external sources;
(b) a documented and enforced policy on coordinated vulnerability disclosure, as referred to in Part II, point (5), of Annex I of the Cyber Resilience Act.
Permissible Standards: N/A
|
|
|
CRA6
Article 14 - Reporting Obligations Of Manufacturers
|
Criterion XX. The Manufacturer shall ensure there are specific provisions regarding the procedures that guarantee notification of any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator1 and to ENISA, via the single reporting platform, including early warning notification, vulnerability notification, and final report as required under Article 14 of the Cyber Resilience Act.
Proof of compliance: Declaration/certification
Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidence about the provision covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail:
(a) documented process ensuring that, without undue delay and in any event within 24 hours of becoming aware of an actively exploited vulnerability, an early warning notification is submitted via the single reporting platform, indicating, where applicable, the Member States on the territory of which the Manufacturer is aware that their product with digital elements has been made available;
(b) documented process ensuring that, unless the information has already been provided, a vulnerability notification, without undue delay and in any event within 72 hours of the Manufacturer becoming aware of the actively exploited vulnerability, which shall provide general information, as available, about the product with digital elements concerned; the general nature of the exploit and of the vulnerability concerned as well as any corrective or mitigating measures taken, and corrective or mitigating measures that users can take, and which shall also indicate, where applicable, how sensitive the manufacturer considers the notified information to be;
(c) documented process ensuring that, unless the relevant information has already been provided, a final report, no later than 14 days after a corrective or mitigating measure is available, including at least the following:
(i) a description of the vulnerability, including its severity and impact;
(ii) where available, information concerning any malicious actor that has exploited or that is exploiting the vulnerability;
(iii) details about the security update or other corrective measures that have been made available to remedy the vulnerability.
Permissible Standards: N/A
|
|
|
CRA7
Article 14 - Reporting Obligations Of Manufacturers
|
Criterion XX. The Manufacturer shall ensure there are specific provisions regarding the procedures that guarantee the notification of any severe incident having an impact on the security of the product with digital elements, without undue delay and in any event within 24 hours of the Manufacturer becoming aware of simultaneously to the CSIRT designated as coordinator and to ENISA, via the single reporting platform, including early warning notification, vulnerability notification, and final report as required under Article 14(3) and (4) of the Cyber Resilience Act.
Proof of compliance: Declaration/certification
Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidence about the provision covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail:
(a) documented process ensuring that, without undue delay and in any event within 24 hours of the Manufacturer becoming aware of it, an early warning notification of a severe incident having an impact on the security of the product with digital elements is submitted including as least whether the incident is suspected of being caused by unlawful or malicious acts, which shall also indicate, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available;
(b) documented process ensuring that, unless the information has already been provided, and incident notification is submitted, without undue delay and in any event within 72 hours of the Manufacturer becoming aware of the incident, which shall provide general information, where available, about the nature of the incident, an initial assessment of the incident, as well as any corrective or mitigating measures taken, and corrective or mitigating measures that users can take, and which shall also indicate, where applicable, how sensitive the Manufacturer considers the notified information to be;
(c) documented process ensuring that, unless the relevant information has already been provided, a final report, within one month after the submission of the incident notification under point (b), including at least the following:
(i) a detailed description of the incident, including its severity and impact;
(ii) the type of threat or root cause that is likely to have triggered the incident;
(iii) applied and ongoing mitigation measures.
Permissible Standards: N/A
Note: An incident having an impact on the security of a product with digital elements shall be considered to be severe where: (i) it negatively affects or is capable of negatively affecting the ability of a product with digital elements to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions; or (ii) it has led or it is capable of leading to the introduction or execution of malicious code in a product with digital elements or in the network and information systems of a user of the product with digital elements.
|
|
|
CRA8
Article 18 - Authorised Representatives
|
Criterion XX. In the case that a manufacturer appoints an authorised representative, the manufacturer shall do so by a written mandate.
Proof of compliance: Declaration/certification
Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidences about the provisions covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail:
• documentation of the written mandate appointing the authorised representative, containing the following:
a. signature of the manufacturer;
b. identification details of the manufacturer and the authorised representative;
c. the date of signature;
d. period of validity of the mandate;
e. explicit confirmation that the obligations laid down in Article 13(1) to (11), Article 13(12), first subparagraph, and Article 13(14) of the Cyber Resilience Act do not form part of the authorised representative’s mandate.
f. explicit confirmation that the authorized representative is allowed to:
i. keep the EU declaration of conformity referred to in Article 28 and the technical documentation referred to in Article 31 of the Cyber Resilience Act at the disposal of the market surveillance authorities for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer;
ii. further to a reasoned request from a market surveillance authority, provide that authority with all the information and documentation necessary to demonstrate the conformity of the product with digital elements;
iii. cooperate with the market surveillance authorities, at their request, on any action taken to eliminate the risks posed by a product with digital elements covered by the authorised representative’s mandate.
Permissible Standards: N/A
|
|
|
CRA9
Article 23 - Identification Of Economic Operators
|
Criterion XX. The Provider shall identify economic operators involved in the supply chain of products with digital elements and make this information available upon request to competent authorities.
Proof of compliance: Declaration/certification
Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidences about the provisions covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail:
(a) the Provider’s capability to supply, upon request, the name and address of any economic operator that has supplied the Provider with a product with digital elements;
(b) where available, the name and address of any economic operator to whom the Provider has supplied a product with digital elements;
(c) the retention period ensuring that the above information can be presented for a minimum of ten (10) years after receipt of the product with digital elements and for ten (10) years after supply of the product with digital elements.
Permissible Standards: N/A
Note: This requirement applies to economic operators involved in the upstream and downstream supply chain of products with digital elements, as relevant to the Service Offering.
|
|
|
CRA10
Article 28 - Eu Declaration Of Conformity
|
Criterion XX. The Manufacturer shall draw up the EU declaration of conformity in accordance with Article 13(12) of the Cyber Resilience Act and shall state that the fulfilment of the applicable essential cybersecurity requirements set out in Annex I of the Cyber Resilience Act has been demonstrated.
Proof of compliance: Declaration/certification
Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidences about the provisions covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail:
(a) documentation of the EU declaration of conformity drawn up in accordance with Article 13(12) of the Cyber Resilience Act, containing an explicit statement that the fulfilment of the applicable essential cybersecurity requirements set out in Annex I of the Cyber Resilience Act has been demonstrated.
Permissible Standards: N/A
Note: Where a product with digital elements is subject to more than one Union legal act requiring an EU declaration of conformity, the Provider shall draw up a single EU declaration of conformity in respect of all such Union legal acts and shall ensure that the declaration contains the identification of the Union legal acts concerned, including their publication references.
Note: By drawing up the EU declaration of conformity, the manufacturer shall assume responsibility for the compliance of the product with digital elements
|
|
|
CRA11
Article 63 - Confidentiality
|
Criterion XX. The Provider shall ensure the confidentiality of information and data obtained in the context of regulatory compliance activities and related cooperation with authorities.
Proof of compliance: Declaration/certification
Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidence about the provisions covering the criterionby providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail:
(a) measures and controls ensuring the protection of intellectual property rights, confidential business information, and trade secrets, including source code, except where disclosure is required under applicable law;
(b) safeguards to preserve the effectiveness of regulatory implementation activities, including inspections, investigations, and audits;
(c) provisions protecting public and national security interests, as well as the integrity of criminal or administrative proceedings;
(d) internal policy governing the exchange of confidential information with market surveillance authorities and other competent bodies, including the requirement that such information is not disclosed without the prior agreement of the originating authority.
Permissible Standards: N/A
|
|