POSITION | DIGITALISATION | CYBERSICHERHEIT
Cyber Resilience Act German industry’s recommendations for the trilogue negotiations
September 2023 Executive Summary With the adoption of the General Approach by the European Council on July 13, 2023 and the adoption of the ITRE Committee’s report on July 19, 2023, the co-legislators have now formulated their opinions on the EU Commission’s proposal for the Cyber Resilience Act. German industry continues the European Union’s (EU) aspiration to enhance Europe’s cyber-resilience holistically by introducing cybersecurity requirements for all products with digital elements. For the upcoming interinstitutional negotiations, German industry encourages all policymakers to stick to the principles of proportionality and practicality of the requirements. Instead of introducing over-arching bureaucratic requirements, the colegislators should aim at risk-based solutions that help significantly enhance Europe’s cyber-resilience. On the one side, such an approach would support essential and important entities in their steps to implement the requirements under the NIS 2-Directive; while on the other side it would ensure that manufacturers of products with digital elements can dedicate their efforts into developing and producing cyber-resilient products rather than in fulfilling administrative duties. The CRA should create a simple, coherent, and effective legal framework that horizontally regulates the cybersecurity of all covered products when placed on the market. It should be designed in such a way that existing, product-specific regulations are not taking precedence according to the “lex specialis” principle. This includes existing and upcoming legislation (e.g., RED Delegated Regulation, Machinery Regulation, Artificial Intelligence Act). Simplification of the existing legal framework is crucial to allow a correct implementation by all stakeholders to strengthen cyber resilience. Our top seven recommendations at a glance:
Art. 2 covers all products that possess an indirect logical or physical data connection. This broad scope of application of the CRA will lead to significant problems and delays in implementation, especially in standardization, and consequently in conformity assessment. Limit the scope to products connected to a public telecommunication network, at least in the first step.
The CRA should equally address harmonised standards, common specifications, and certification schemes with respect to the presumption of conformity. CSA schemes and common specifications need to be subject to the same test procedure and assessment with regard to the coverage of essential requirements of the CRA as harmonised standards.
Exclude “security updates” and “minor functionality updates” from the definition of substantial modification, to ensure a swift dissemination of such updates among users and thereby to maintain the cyber-resilience of such products;
Steven Heckler | Deputy Head of Department | Digitalisation and Innovation | s.heckler@bdi.eu | www.bdi.eu