Estonian Free PressEstonian Free Press
  • National Security
    • United States
    • United Kingdom
    • Europe
    • Estonia
    • Latvia
    • Lithuania
    • Moldova
    • Poland
    • Russia
    • Ukraine
  • Counterterrorism
  • Cybersecurity
  • Intelligence

Subscribe to Updates

Get the latest National Security News directly to your inbox.

What's Hot

The World of Saint Javelin

March 20, 2023

One of the Dark Web’s Largest Cryptocurrency Laundromats Taken Down

March 20, 2023

Food tsar blames Tory approach to obesity will cause ‘huge harm’ as he quits

March 20, 2023
Facebook Twitter Instagram
  • Privacy Policy
  • Terms and Conditions
  • Contact
Monday, March 20
Estonian Free PressEstonian Free Press
  • National Security
    • United States
    • United Kingdom
    • Europe
    • Estonia
    • Latvia
    • Lithuania
    • Moldova
    • Poland
    • Russia
    • Ukraine
  • Counterterrorism
  • Cybersecurity
  • Intelligence
en English
en Englishet Estonianlv Latvianlt Lithuanianpl Polishro Romanianru Russianuk Ukrainian
Trending
  • The World of Saint Javelin
  • One of the Dark Web’s Largest Cryptocurrency Laundromats Taken Down
  • Food tsar blames Tory approach to obesity will cause ‘huge harm’ as he quits
  • Usatîi: Moldova trebuie să trăiască cu propria minte
  • V.Blinkevičiūtė apie konservatorių pasirodymą rinkimuose: tai yra pralaimėjimas
  • Keir Starmer accuses Boris Johnson of attempting to ‘intimidate’ MPs probing Partygate scandal
  • Connection Protection
  • A.Vaitkus apie konservatorius: ši politinė jėga yra etikečių klijavimo specialistai
Subscribe
Facebook Twitter Instagram
Estonian Free PressEstonian Free Press
Home » EU Council reconsiders critical products in new cybersecurity law

EU Council reconsiders critical products in new cybersecurity law

February 13, 20234 Mins Read Cybersecurity
Share
Facebook Twitter LinkedIn Pinterest Email

The Swedish presidency of the EU Council of ministers shared a new compromise text with hefty changes on the categorisation of critical and highly critical products under the Cyber Resilience Act.

The draft law is designed to establish baseline cybersecurity requirements for connected devices, such as the fact that Internet of Things (IoT) products that connect and exchange data with other devices cannot be launched on the market with any known exploitable vulnerability.

Whilst for most connected devices, manufacturers will be able to self-assess the compliance to such requirements, for some specific products deemed ‘critical’ or ‘highly critical’ an external audit will be needed. The way and which products would qualify for these two crucial categories were at the centre of the latest compromise text, seen by EURACTIV.

The compromise was shared on Friday (10 February) and will be discussed on Wednesday at the Cybersecurity Working Party, a technical body that lays the preparatory work for approval at the ministerial level.

Critical products

According to the compromise text, certain products will be deemed ‘critical’ if they perform a key security function, for instance, authentication, intrusion prevention or network protection.

That is the case for malware detection software, network traffic monitoring systems for throughput and flow control, security information and event management systems, systems rolling out updates and security patches, firewalls, digital certificates, and smart home devices with security functionalities like alarm systems.

Another subgroup of Internet of Things products is considered ‘critical’ if they play a central role in the management of a broader system or if they have the potential to damage several other products, such as network management and configuration control.

This second criterion relates to standalone and embedded browsers, network resource management including software-designed networking technology, application configuration management systems for centralised systems configuration, remote access software, physical and virtual network interfaces, routers, microprocessors, microcontrollers, operating systems and industrial products and control systems not covered in the ‘highly critical’ category.

Highly critical products

Another group of products would be considered ‘highly critical’ if they meet both aforementioned criteria, namely, they have an important security function and are central in a broader IoT environment.

This class of products includes identity management systems, authentication tools, Virtual Private Networks (VPNs), network management systems for the configuration, monitoring and updating of network devices, hypervisors, microprocessors for secure elements, devices based on tamper-secure chips, hardware security models, secure crypto-processors, and smartcard readers.

Firewalls for industrial use will be categorised ‘highly critical’ if they have both a cybersecurity-related function and are used in sensitive environments, including industrial control setting for entities designated as ‘essential’ under the recently revised Networks and Information Directive (NIS2).

A final group of products would be classified as ‘highly critical’ if they meet the double condition of being used in a sensitive environment and central to managing a broader system. Application-specific integrated circuits, field-programmable gate arrays, industrial automation and control systems, industrial IoT devices and smart meters are part of this group of products.

The list of critical and highly critical products was included in the annexe to the draft law, as annexes can be more easily updated than the body of the text. The European Commission would have to consider these criteria when amending the products listed in the annexe.

Certification scheme

To demonstrate compliance with some of the regulation’s essential requirements, the Commission might mandate specific categories of highly critical products to obtain an EU cybersecurity certificate with a level ‘substantial’ or ‘high’ as defined under the Cybersecurity Act.

To determine which categories of highly critical products should be requested for these certificates, the EU executive will need to consider the above-mentioned criteria and whether the product could disrupt the essential entities identified under NIS2 or supply chains critical for the EU market.

Simplified declaration

The Swedish presidency included a template for a simplified EU declaration of conformity, displaying the URL where the full declaration will be accessible online.

[Edited by Nathalie Weatherald]

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email

Articles Liés

One of the Dark Web’s Largest Cryptocurrency Laundromats Taken Down

March 20, 2023 Cybersecurity

NSA Releases Recommendations for Maturing Identity, Credential, and Access Management in Zero Trust

March 17, 2023 Cybersecurity

PERSPECTIVE: What Industry and Government Collaboration Can Look Like Under the National Cybersecurity Strategy

March 17, 2023 Cybersecurity

Threat Actors Exploited Progress Telerik Vulnerability in U.S. Government IIS Server

March 16, 2023 Cybersecurity

EU Council extends product lifetime, clarifies scope in cybersecurity law

March 16, 2023 Cybersecurity

CISA Releases SCuBA Hybrid Identity Solutions Architecture Guidance Document for Public Comment

March 16, 2023 Cybersecurity
Don't Miss
Cybersecurity

One of the Dark Web’s Largest Cryptocurrency Laundromats Taken Down

By woe whMarch 20, 20230

U.S. and German authorities, supported by Europol, have targeted ChipMixer, a cryptocurrency mixer well-known in…

Food tsar blames Tory approach to obesity will cause ‘huge harm’ as he quits

March 20, 2023

Usatîi: Moldova trebuie să trăiască cu propria minte

March 20, 2023

V.Blinkevičiūtė apie konservatorių pasirodymą rinkimuose: tai yra pralaimėjimas

March 20, 2023
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Our Picks

Connection Protection

March 20, 2023

A.Vaitkus apie konservatorius: ši politinė jėga yra etikečių klijavimo specialistai

March 20, 2023

The Art of Logistics

March 20, 2023

R.Karbauskis: net jei naujiems rinkimams į Seimą reikės išleisti „milijonus“, tai – gyventojų valia

March 20, 2023

Subscribe to Updates

Get the latest National Security News directly to your inbox.

© 2023 Estonian Free Press. All rights reserved.
  • Privacy Policy
  • Terms and Conditions
  • Contact

Type above and press Enter to search. Press Esc to cancel.