Cyber Resilience Act (CRA)
Table of Contents
Chapter I – GENERAL PROVISIONS
Chapter II – OBLIGATIONS OF ECONOMIC OPERATORS AND PROVISIONS IN RELATION TO FREE AND OPEN-SOURCE SOFTWARE
Chapter III – CONFORMITY OF THE PRODUCT WITH DIGITAL ELEMENTS
Chapter IV – NOTIFICATION OF CONFORMITY ASSESSMENT BODIES
Chapter V – MARKET SURVEILLANCE AND ENFORCEMENT
Chapter VI – DELEGATED POWERS AND COMMITTEE PROCEDURE
Chapter VII – CONFIDENTIALITY AND PENALTIES
Chapter VIII – TRANSITIONAL AND FINAL PROVISIONS
Recitals (130)
Annexes
Recital 22
(22) In view of the public cybersecurity objectives of this Regulation and in order to improve the situational awareness of Member States as regards the Union’s dependency on software components and in particular on potentially free and open-source software components, a dedicated administrative cooperation group (ADCO) established by this Regulation should be able to decide to jointly undertake a Union dependency assessment. Market surveillance authorities should be able to request manufacturers of categories of products with digital elements established by ADCO to submit the software bills of materials (SBOMs) that they have generated pursuant to this Regulation. In order to protect the confidentiality of SBOMs, market surveillance authorities should submit relevant information about dependencies to ADCO in an anonymised and aggregated manner.