TechCrunch News 2024年12月10日
EU cybersecurity rules for smart devices enter into force
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

欧盟《网络韧性法案》生效,要求产品制造商为消费者提供安全支持,如更新软件修复漏洞。该法案旨在加强智能设备安全,适用于多种产品,规定了生命周期内的要求,违反标准将面临罚款。

🦾《网络韧性法案》对产品制造商规定安全义务,如软件更新

🎯法案适用于多种连接设备,部分产品有例外

💲违反法案的标准将面临不同程度的罚款

✅设备可通过CE标志表明符合法案要求

Rules for boosting the security of connected devices have entered into force in the European Union.

The Cyber Resilience Act (CRA) puts obligations on product makers to provide security support to consumers, such as by updating their software to fix security vulnerabilities. Although the deadline for compliance with the main obligations of the law is still three years out — December 11, 2027 — to allow device makers time to comply. 

The legislation was proposed a little over two years ago, with the goal of amping up the security of devices such as smartwatches, internet-connected toys and home appliances that can be controlled by an app.

The proliferation of connected devices has led to worries over rising hacking risks, with quasi-regular headlines about hacked baby monitors and kids toys amping up concerns that profits were being put before consumer security.

The pan-E.U. law puts mandatory cybersecurity requirements on products with digital elements. Requirements apply throughout in-scope products’ lifecycles, from design, development, and operation. Distributors and retailers must also ensure the stuff that they supply or stock abides by the EU’s rules.

The CRA applies to connected devices broadly — meaning products that connect directly or indirectly to another device or network — with exceptions in the case of products that are covered by other existing E.U. rules, such as medical devices, cars, and some open-source software.

Devices can display the E.U.’s CE mark to communicate that they are abiding by the CRA. Regional consumers should then have less leg work to ensure they are purchasing a more secure product if they look out for the CE marking.

The bloc has said it wants the law to “rebalance responsibility” for cybersecurity towards manufacturers, who must ensure products with digital elements meet the legal standards if they wish to access the E.U. market.

Penalties for failing to meet the CRA’s standards will fall to Member State-level oversight bodies, which will be responsible for compliance checks. But the law states that breaches of “essential cybersecurity requirements” can risk fines of up to 2.5% of global annual turnover (or up to €15 million if greater). Breaches of other requirements risk fines of 2% (up to €10 million). Failure to respond properly to regulatory requests risks 1% (or €5 million).

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

欧盟 智能设备安全 网络韧性法案 CE标志 罚款
相关文章