Cyber Resilience Act

13 marzo 2024

The regulation, already agreed with Council in December 2023, aims to ensure that products with digital features are secure to use, resilient against cyber threats and provide enough information about their security properties.

Important and critical products will be put into different lists based on their criticality and the level of cybersecurity risk they pose. The two lists will be proposed and updated by the European Commission. Products deemed to pose a higher cybersecurity risk will be examined more stringently by a notified body, while others may go through a lighter conformity assessment process, often managed internally by the manufacturers.

During the negotiations, MEPs made sure that products such as identity management systems software, password managers, biometric readers, smart home assistants and private security cameras are covered by the new rules. Products should also have security updates installed automatically and separately from functionality updates.

MEPs also pushed for the European Union Agency for Cybersecurity (ENISA) to be more closely involved when vulnerabilities are found and incidents occur. The agency will be notified by the member state concerned and receive information so it can assess the situation and, if it identifies a systemic risk, will inform other member states so they are able to take the necessary steps.

To emphasise the importance of professional skills in the cybersecurity field, MEPs also introduced education and training programmes, collaborative initiatives, and strategies to enhance workforce mobility in the regulation.

Archivio news

 

News dello studio

lug20

20/07/2026

Sintesi della consultazione pubblica indetta con la delibera n. 59/26/CONS concernente l’impiego di frequenze nella banda 40,5-43,5 GHz per sistemi terrestri in grado di fornire servizi di comunicazione elettronica a banda larga wireless ai sensi della de

Il documento riporta una sintesi delle posizioni espresse e delle informazioni fornite dai rispondenti alla consultazione pubblica di cui alla delibera n. 59/26/CONS concernente l’impiego

lug20

20/07/2026

NIS2: Organi di amministrazione e direttivi

L'Agenzia per la Cybersicurezza Nazionale ha aggiornato le FAQ relative agli obblighi degli organi di amministrazione e direttivi dei soggetti NIS, integrando le FAQ ODA.8 e ODA.9 e introducendo

lug20

20/07/2026

Garante a Enel Energia: il cliente può avere accesso all’audio delle conversazioni

La richiesta di accesso ai dati personali contenuti in registrazioni audio o video può essere soddisfatta anche mediante la consegna della trascrizione della conversazione, purché siano

News Giuridiche

lug20

20/07/2026

Nel CCNL Studi professionali la formazione diventa welfare

<p><span>Il CCNL con il supporto

lug20

20/07/2026

L’avvocato non è mai in pausa: la toga senza scrivania

Per l'iscrizione e la permanenza nell’albo

lug20

20/07/2026

Esame avvocato e pratica forense: le nuove disposizioni

<p>Con il <a href="https://onelegale.wolterskluwer.it/document/10LX0001006304SOMM"