Cyber Resilience Act

13 march 2024

The regulation, already agreed with Council in December 2023, aims to ensure that products with digital features are secure to use, resilient against cyber threats and provide enough information about their security properties.

Important and critical products will be put into different lists based on their criticality and the level of cybersecurity risk they pose. The two lists will be proposed and updated by the European Commission. Products deemed to pose a higher cybersecurity risk will be examined more stringently by a notified body, while others may go through a lighter conformity assessment process, often managed internally by the manufacturers.

During the negotiations, MEPs made sure that products such as identity management systems software, password managers, biometric readers, smart home assistants and private security cameras are covered by the new rules. Products should also have security updates installed automatically and separately from functionality updates.

MEPs also pushed for the European Union Agency for Cybersecurity (ENISA) to be more closely involved when vulnerabilities are found and incidents occur. The agency will be notified by the member state concerned and receive information so it can assess the situation and, if it identifies a systemic risk, will inform other member states so they are able to take the necessary steps.

To emphasise the importance of professional skills in the cybersecurity field, MEPs also introduced education and training programmes, collaborative initiatives, and strategies to enhance workforce mobility in the regulation.

News archive

 

Firm news

set17

17/09/2025

Guerra in Ucraina: il Tribunale conferma le misure restrittive nei confronti di Positive Group PAO, un’entità che opera nel settore informatico russo ed è titolare di una licenza rilasciata dai servizi di intelligence nazionali russ

Sentenza del Tribunale nella causa T-573/23 | Positive Group / Consiglio A seguito dell’aggressione militare della Russia nei confronti dell’Ucraina nel 2022, l’Unione europea ha adottato

set17

17/09/2025

Indagini Patrimoniali: si a Cerebro

  Il Garante privacy ha dato parere favorevole al Ministero dell’Interno sulla valutazione d’impatto (DPIA) relativa a CEREBRO: il Sistema di analisi ed elaborazione dati

set17

17/09/2025

Ordinanza ingiunzione nei confronti della società Enel Energia S.p.A. per la violazione dell’art. 98 – octies decies, del decreto legislativo 1° agosto 2003, n. 259, in combinato disposto con gli artt. 3, 4 e 8-bis, dell’allegato b alla Delibera n. 307/23

Con la delibera 195/25/Cons,l'Agcom ha  ingiunto alla società Enel Energia S.p.A.., in persona del legale rappresentante pro tempore, di versare entro 30 giorni dalla notificazione

Lawyer News

set17

17/09/2025

La variabile fiscale nella gestione della crisi d'impresa

Strumenti a confronto e strategie operative

set17

17/09/2025

Avvocati: divieto di espressioni offensive anche nella vita privata

La dignità e il decoro della professione

set17

17/09/2025

Il principio di proporzionalità nel procedimento tributario

L’art. 10-ter dello Statuto del contribuente: