Cyber Resilience Act

13 march 2024

The regulation, already agreed with Council in December 2023, aims to ensure that products with digital features are secure to use, resilient against cyber threats and provide enough information about their security properties.

Important and critical products will be put into different lists based on their criticality and the level of cybersecurity risk they pose. The two lists will be proposed and updated by the European Commission. Products deemed to pose a higher cybersecurity risk will be examined more stringently by a notified body, while others may go through a lighter conformity assessment process, often managed internally by the manufacturers.

During the negotiations, MEPs made sure that products such as identity management systems software, password managers, biometric readers, smart home assistants and private security cameras are covered by the new rules. Products should also have security updates installed automatically and separately from functionality updates.

MEPs also pushed for the European Union Agency for Cybersecurity (ENISA) to be more closely involved when vulnerabilities are found and incidents occur. The agency will be notified by the member state concerned and receive information so it can assess the situation and, if it identifies a systemic risk, will inform other member states so they are able to take the necessary steps.

To emphasise the importance of professional skills in the cybersecurity field, MEPs also introduced education and training programmes, collaborative initiatives, and strategies to enhance workforce mobility in the regulation.

News archive

 

Firm news

mag6

06/05/2026

Approvazione della proposta di impegni presentata dalla società Iliad Italia S.p.A., ai sensi dell’art. 14-bis del decreto legge 4 luglio 2006, n. 223, in relazione al procedimento sanzionatorio avviato con atto di contestazione n. 3/25/DT

Con delibera 88/26/cons, l' Agcom  ha approvato la proposta di impegni presentata dalla società Iliad Italia S.p.A. nell’ambito del procedimento sanzionatorio n. 3/25/DTC avviato

mag6

06/05/2026

ITALIAN STRATEGY FOR ARTIFICIAL INTELLIGENCE 2024-2026

  The Italian Supervisory Agency (Agid) issued the ITALIAN STRATEGY FOR ARTIFICIAL INTELLIGENCE 2024-2026. The document reviews the global context and Italy's positioning and defines strategic

mag4

04/05/2026

No alla conservazione di copia dei documenti degli ospiti

lberghi, B&B e affittacamere non possono conservare copie dei documenti d’identità degli ospiti oltre il tempo strettamente necessario alla comunicazione dei dati alle autorità

Lawyer News

mag7

07/05/2026

Rapporto Censis-Cassa Forense: il PIL dell'avvocatura cresce più del PIL italiano

I dati del decimo report, raccolti da oltre

mag7

07/05/2026

Il diritto di accesso alla posta elettronica aziendale post-cessazione

Il confine tra proprietà dei mezzi e dignità

mag7

07/05/2026

Maltrattamenti in presenza di minori: è sufficiente la mera esposizione percettiva

Il giudice non è tenuto a valutare la concreta