Source: OJ L 2024/2847, 20.11.2024

Current language: DE

Artikel 25 Sicherheitsbescheinigung für freie und quelloffene Software


Summary What does Article 25 of the CRA regulation say?

This article is a short enabling provision that directly supports the due diligence obligation placed on manufacturers under Article 13(5), specifically those who integrate free and open-source software components into their products.

It empowers the Commission to create, via delegated acts, voluntary security attestation programmes.

These programmes would allow developers, users, or other third parties to assess whether free and open-source software products meet some or all of the essential cybersecurity requirements set out in the regulation.

Important points:

  • The Commission is empowered to adopt delegated acts establishing voluntary security attestation programmes for free and open-source software products.
  • Manufacturers integrating free and open-source software components into their products benefit from this article, as it is designed to ease their due diligence obligations under Article 13(5).
  • Participation in these attestation programmes is voluntary and open to developers, users, and other third parties.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

Um die in Artikel 13 Absatz 5 festgelegte Sorgfaltspflicht zu erleichtern, insbesondere in Bezug auf Hersteller, die freie und quelloffene Softwarekomponenten in ihre Produkte mit digitalen Elementen integrieren, wird der Kommission die Befugnis übertragen, gemäß Artikel 61 delegierte Rechtsakte zu erlassen, um diese Verordnung durch die Einführung freiwilliger Programme zur Bescheinigung der Sicherheit zu ergänzen, die es den Entwicklern oder Nutzern von Produkten mit digitalen Elementen, die als freie und quelloffene Software gelten, sowie anderen Dritten ermöglichen, die Konformität dieser Produkte mit allen oder bestimmten grundlegenden Cybersicherheitsanforderungen oder sonstigen in dieser Verordnung festgelegten Verpflichtungen zu bewerten.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod