Source: OJ L 2024/2847, 20.11.2024

Current language: FR

Article 70 Évaluation et réexamen


Summary What does Article 70 of the CRA regulation say?

This article sets out the Commission's obligations to review and report on the regulation's implementation and effectiveness.

It establishes two distinct reporting duties: a broader evaluation of the regulation as a whole, and a more targeted assessment of the single reporting platform established under Article 16, which is the centralised mechanism for manufacturers to notify vulnerabilities and incidents.

Important points:

  • The Commission is required to submit a general evaluation and review report to the European Parliament and Council by 11 December 2030, and every four years after that, with all reports made public.
  • The Commission must also submit a separate, earlier report by 11 September 2028, specifically assessing the effectiveness of the single reporting platform referenced in Article 16.
  • The second report must be prepared after consulting ENISA and the CSIRTs network, and must examine how CSIRTs designated as coordinators have applied cybersecurity-related grounds to delay dissemination of notifications.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. Au plus tard le 11 décembre 2030 et tous les quatre ans par la suite, la Commission présente un rapport sur l’évaluation et le réexamen du présent règlement au Parlement européen et au Conseil. Ces rapports sont rendus publics.

    1. Au plus tard le 11 septembre 2028, la Commission, après consultation de l’ENISA et du réseau des CSIRT, présente au Parlement européen et au Conseil un rapport pour évaluer l’efficacité de la plateforme unique de signalement prévue à l’article 16, ainsi que les répercussions de l’application des motifs liés à la cybersécurité visés à l’article 16, paragraphe 2, par les CSIRT désignés comme coordinateurs sur l’efficacité de la plateforme unique de signalement en ce qui concerne la diffusion en temps utile des notifications reçues à d’autres CSIRT concernés.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod