Cyber Resilience Act trilogue negotiations

With the Cyber Resilience Act, the European Union aims to establish mandatory cyber security requirements for all products with digital elements for the first time. The objective is to close the existing regulatory gap in the area of cyber security at EU level and at the same time achieve a high level of cyber security in the European single market.

©️ Philipp Katzenberger via Unsplash

The EU Commission published its proposal for the Cyber Resilience Act in September 2022. After in-depth negotiations, the Council and the EU Parliament defined their respective positions in July and September 2023, respectively. The upcoming trilogue negotiations are to be advanced under the Spanish Council Presidency.

The TÜV Association has already taken a comprehensive position on the Cyber Resilience Act in the current legislative process. This statement provides concrete recommendations to create a robust, effective and risk-adequate regulatory framework. The priority objective of the EU legislator must be to ensure that only cyber-secure products are placed on the market thereby strengthening the level of trust of people in products with digital elements. This requires not only ambitious cybersecurity requirements but also reliable assessment mechanisms, especially for critical products.

 

Download

Recommendations on the Cyber Resilience Act trilogue negotiations