Members' Research Service By / December 16, 2022

EU cyber-resilience act [EU Legislation in Progress]

According to one industry forecast, the total number of internet of things (IoT) connected devices worldwide is set to more than double from 14.6 billion in 2022 to 30.2 billion by 2030.

© Artur / Adobe Stock

Written by Polona Car and Stefano De Luca (4th edition, updated on 20.12.2024).

New technologies come with new risks, and the impact of cyber-attacks through digital products has increased dramatically in recent years. Consumers are increasingly falling victim to security flaws linked to digital products such as baby monitors, robo-vacuum cleaners, Wi-Fi routers and alarm systems. For businesses, the importance of ensuring that digital products in the supply chain are secure has become pivotal, considering three in five vendors have already lost money as a result of product security gaps.

The European Union’s lawmakers signed the ‘cyber-resilience act’ in October 2024. The regulation imposes cybersecurity obligations on all products with digital elements whose intended and foreseeable use includes direct or indirect data connection to a device or network. The regulation introduces cybersecurity by design and by default principles and imposes a duty of care for the lifecycle of products.

The Cyber Resilience Act was published in the EU’s Official Journal on 20 November 2024. It entered into force in December 2024 and will apply in full as of 11 December 2027.

Complete version

Horizontal cybersecurity requirements for products with digital elements
Committee responsible:Committee on Industry, Research and Energy (ITRE)COM(2022)454
15.9.2022
Rapporteur:Nicola Danti (Renew, Italy)2022/0272(COD)
Shadow rapporteurs:Henna Virkkunen (EPP, Finland)
Beatrice Covassi (S&D, Italy)
Ignazio Corrao (Greens/EFA, Italy)
Matteo Gazzini (ID, Italy)
Evžen Tošenovský (ECR, Czechia)
Marc Botenga (GUE/NGL, Belgium)
Ordinary legislative
procedure (COD)
(Parliament and Council
on equal footing
– formerly ‘co-decision’)
Procedure completed:
Regulation (EU) 2024/2847
OJ L, 2024/2847, 20.11.2024
Stage: procedure completed

Related Articles

Be the first to write a comment.

Leave a Reply

Discover more from Epthinktank

Subscribe now to keep reading and get access to the full archive.

Continue reading

EPRS Logo
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.