CEN/CLC/JTC 13/WG 9 - Special Working Group on Cyber Resilience Act
WG9 is responsible for the development of the horizontal standards in response to the European Cyber Resilience Act Standardisation Request M/606, items 1 - 15. WG 9 supports coordination and coherence between the vertical deliverables of the CRA and the horizontal deliverables of WG9
Special Working Group on Cyber Resilience Act
WG9 is responsible for the development of the horizontal standards in response to the European Cyber Resilience Act Standardisation Request M/606, items 1 - 15. WG 9 supports coordination and coherence between the vertical deliverables of the CRA and the horizontal deliverables of WG9
General Information
Frequently Asked Questions
CEN/CLC/JTC 13/WG 9 is a Working Group within the European Committee for Standardization (CEN). It is named "Special Working Group on Cyber Resilience Act" and is responsible for: WG9 is responsible for the development of the horizontal standards in response to the European Cyber Resilience Act Standardisation Request M/606, items 1 - 15. WG 9 supports coordination and coherence between the vertical deliverables of the CRA and the horizontal deliverables of WG9 This committee has published 3 standards.
CEN/CLC/JTC 13/WG 9 develops CEN standards in the area of Information technology. The scope of work includes: WG9 is responsible for the development of the horizontal standards in response to the European Cyber Resilience Act Standardisation Request M/606, items 1 - 15. WG 9 supports coordination and coherence between the vertical deliverables of the CRA and the horizontal deliverables of WG9 Currently, there are 3 published standards from this working group.
The European Committee for Standardization (CEN) is a public standards organization that brings together the national standardization bodies of 34 European countries. CEN provides a platform for developing European Standards (ENs) and other technical documents in relation to various products, materials, services, and processes, supporting the European Single Market.
A Working Group in CEN is a specialized group responsible for developing standards or technical work within a defined scope. These bodies bring together international experts to create consensus-based standards that support global trade, safety, and interoperability.
This document specifies general cybersecurity principles and general risk management activities for all products with digital elements, hereafter also referred to as 'products'. This document covers every stage of the product lifecycle to ensure and maintain an appropriate level of cybersecurity based on the risks.
This document also provides generic elements to support the development of coherent product-category-specific standards (vertical standards).
This document:
— establishes generic cybersecurity principles applicable to all stages of the product lifecycle;
— specifies requirements for risk assessment and treatment of cybersecurity risks;
— specifies requirements on activities that can be applied to ensure an appropriate level of cybersecurity at every phase of the product lifecycle;
— provides elements and considerations for product category specific standards in order to facilitate a harmonized approach.
This document does not provide vertical product category specific activities and elements.
- Draft57 pagesEnglish languagee-Library read for1 day
This document provides the terms and definitions commonly used in the cybersecurity requirements for products with digital elements family of standards.
- Draft8 pagesEnglish languagee-Library read for1 day
This standards shall provide specifications applicable to vulnerability handling processes, covering all relevant product categories, to
be put in place by manufacturers of the products with digital elements. Those processes shall at least allow to:
(a) identify and document vulnerabilities and components contained in the product, including by drawing up a software bill of materials in a commonly used and machinereadable format covering at the very least the top-level dependencies of the product;
(b) in relation to the risks posed to the products with digital elements, address and remediate vulnerabilities without delay, including by providing security updates; where technically feasible, new security updates shall be provided separately from functionality updates;
(c) apply effective and regular tests and reviews of the security of the product with digital elements;
(d) once a security update has been made available, share and publicly disclose information about fixed vulnerabilities, including a description of the vulnerabilities, information allowing users to identify the product with digital elements affected, the impacts of the vulnerabilities, their severity and clear and accessible information helping users to remediate the vulnerabilities; in duly justified cases, where manufacturers consider the security risks of publication to outweigh the security benefits, they may delay making public information regarding a fixed vulnerability until after users have been given the possibility to apply the relevant patch;
(e) put in place and enforce a policy on coordinated vulnerability disclosure;
(f) take measures to facilitate the sharing of information about potential vulnerabilities in their product with digital elements as well as in third party components contained in that product, including by providing a standardised contact address for the reporting of the
vulnerabilities discovered in the product with digital elements;
(g) provide for mechanisms to securely distribute updates for products with digital elements to ensure that vulnerabilities are fixed or mitigated in a timely manner, and, where applicable for security updates, in an automatic manner;
(h) ensure that, where security updates are available to address identified security issues, they are disseminated without delay and, unless otherwise agreed between manufacturer and business user in relation to a tailor-made product with digital elements, free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken.
- Draft37 pagesEnglish languagee-Library read for1 day