
The Cyber Resilience Act (CRA) establishes a risk-based framework that significantly impacts various stakeholders within the cybersecurity ecosystem for digital products and software on the EU market. This includes manufacturers, importers, authorized representatives, distributors, market surveillance authorities and cybersecurity organizations like the European Union Agency for Cybersecurity (ENISA) and Cyber Security Incident Response Teams (CSIRTs). Each stakeholder has a unique yet interconnected role in confirming compliance and enhancing resilience.
These relationships are both regulatory and collaborative, creating a complex web of responsibilities and information sharing. In the following infographic, we will examine how these stakeholders interact, support one another and work together to uphold the CRA’s objectives of improving cybersecurity across the European Union.
First stakeholder | Second stakeholder | Relationship between first stakeholder and second stakeholder |
---|---|---|
Non EU-based manufacture | Authorized representative | Formally appoints |
Authorized representative | Market Surveillance Authority | Provides technical documentation and responds to product issue |
Non EU/EU-based manufacturer | Notified Body | Provides technical security documentation for assessment |
Non EU/EU-based manufacturer | Market Surveillance Authority | Provides assessment documents for inspection and compliance enforcement |
Authorized representative | CSIRTs | Reports actively exploited vulnerabilities and cybersecurity incidents |
EU-based manufacturer | CSIRTs | Reports actively exploited vulnerabilities and cybersecurity incidents |
Authorized representative | ENISA | Shares notification of actively exploited vulnerabilities and cybersecurity incidents |
EU-based manufacturer | ENISA | Shares notification of actively exploited vulnerabilities and cybersecurity incidents |
CSIRTs | ENISA | Shares data on threats, vulnerabilities and incidents |
Market Surveillance Authority | ENISA | Collaborates with ENISA in case of significant cybersecurity incidents and threat intelligence |
Importer | ENISA | Reports suspected cybersecurity risk |
Distributor | ENISA | Reports suspected cybersecurity risk |
Distributor | Importer | Reports suspected cybersecurity risk |
Importer | Distributor | Supplies product |
Non EU-based manufacturer | Importer | Shares CE marking and documentation for product placement |
Want to know more about how we can help you reach CRA compliance?
Prepare for the CRA and contact us today.