Source: OJ L 2024/2847, 20.11.2024

Current language: SV

Artikel 25 Säkerhetsintyg för programvara med fri och öppen källkod


Summary What does Article 25 of the CRA regulation say?

This article is a short enabling provision that directly supports the due diligence obligation placed on manufacturers under Article 13(5), specifically those who integrate free and open-source software components into their products.

It empowers the Commission to create, via delegated acts, voluntary security attestation programmes.

These programmes would allow developers, users, or other third parties to assess whether free and open-source software products meet some or all of the essential cybersecurity requirements set out in the regulation.

Important points:

  • The Commission is empowered to adopt delegated acts establishing voluntary security attestation programmes for free and open-source software products.
  • Manufacturers integrating free and open-source software components into their products benefit from this article, as it is designed to ease their due diligence obligations under Article 13(5).
  • Participation in these attestation programmes is voluntary and open to developers, users, and other third parties.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

I syfte att underlätta den skyldighet att visa tillbörlig aktsamhet som anges i artikel 13.5, särskilt när det gäller tillverkare som införlivar komponenter av programvara med fri och öppen källkod i sina produkter med digitala element, ges kommissionen befogenhet att anta delegerade akter i enlighet med artikel 61 för att komplettera denna förordning genom att inrätta frivilliga program för säkerhetsintyg som gör det möjligt för utvecklare eller användare av produkter med digitala element som klassificeras som programvara med fri och öppen källkod samt andra tredje parter att bedöma sådana produkters överensstämmelse med alla eller vissa väsentliga cybersäkerhetskrav eller andra skyldigheter som fastställs i denna förordning.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod