Source: OJ L 2024/2847, 20.11.2024

Current language: FR

Article 25 Attestation de sécurité des logiciels libres et ouverts


Summary What does Article 25 of the CRA regulation say?

This article is a short enabling provision that directly supports the due diligence obligation placed on manufacturers under Article 13(5), specifically those who integrate free and open-source software components into their products.

It empowers the Commission to create, via delegated acts, voluntary security attestation programmes.

These programmes would allow developers, users, or other third parties to assess whether free and open-source software products meet some or all of the essential cybersecurity requirements set out in the regulation.

Important points:

  • The Commission is empowered to adopt delegated acts establishing voluntary security attestation programmes for free and open-source software products.
  • Manufacturers integrating free and open-source software components into their products benefit from this article, as it is designed to ease their due diligence obligations under Article 13(5).
  • Participation in these attestation programmes is voluntary and open to developers, users, and other third parties.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

Afin de faciliter le respect de l’obligation de diligence raisonnable énoncée à l’article 13, paragraphe 5, en particulier en ce qui concerne les fabricants qui intègrent des composants logiciels libres et ouverts dans leurs produits comportant des éléments numériques, la Commission est habilitée à adopter des actes délégués conformément à l’article 61 afin de compléter le présent règlement en mettant en place des programmes volontaires d’attestation de sécurité permettant aux développeurs ou aux utilisateurs de produits comportant des éléments numériques répondant aux critères de logiciel libre et ouvert ainsi qu’à d’autres tiers d’évaluer la conformité de ces produits à l’ensemble ou à une partie des exigences essentielles de cybersécurité ou d’autres obligations prévues par le présent règlement.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod