Cyber Resilience Act (CRA)
Table of Contents
Chapter I – GENERAL PROVISIONS
Chapter II – OBLIGATIONS OF ECONOMIC OPERATORS AND PROVISIONS IN RELATION TO FREE AND OPEN-SOURCE SOFTWARE
Chapter III – CONFORMITY OF THE PRODUCT WITH DIGITAL ELEMENTS
Chapter IV – NOTIFICATION OF CONFORMITY ASSESSMENT BODIES
Chapter V – MARKET SURVEILLANCE AND ENFORCEMENT
Chapter VI – DELEGATED POWERS AND COMMITTEE PROCEDURE
Chapter VII – CONFIDENTIALITY AND PENALTIES
Chapter VIII – TRANSITIONAL AND FINAL PROVISIONS
Recitals (130)
Annexes
Recital 51
(51) Products with digital elements classified as high-risk AI systems pursuant to Article 6 of AI Act of the European Parliament and of the Council which fall within the scope of this Regulation should comply with the essential cybersecurity requirements set out in this Regulation. Where those high-risk AI systems fulfil the essential cybersecurity requirements set out in this Regulation, they should be deemed to comply with the cybersecurity requirements set out in Article 15 of AI Act in so far as those requirements are covered by the EU declaration of conformity or parts thereof issued under this Regulation. For that purpose, the assessment of the cybersecurity risks associated with a product with digital elements classified as a high-risk AI system pursuant to AI Act that is to be taken into account during the planning, design, development, production, delivery and maintenance phases of such product, as required under this Regulation, should take into account risks to the cyber resilience of an AI system as regards attempts by unauthorised third parties to alter its use, behaviour or performance, including AI specific vulnerabilities such as data poisoning or adversarial attacks, as well as, as relevant, risks to fundamental rights, in accordance with AI Act. As regards the conformity assessment procedures relating to the essential cybersecurity requirements for a product with digital elements that falls within the scope of this Regulation and that is classified as a high-risk AI system, Article 43 of AI Act should apply as a rule instead of the relevant provisions of this Regulation. However, that rule should not result in a reduction of the necessary level of assurance for important or critical products with digital elements as referred to in this Regulation. Therefore, by way of derogation from that rule, high-risk AI systems that fall within the scope of AI Act which are also important or critical products with digital elements as referred to in this Regulation and to which the conformity assessment procedure based on internal control referred to in Annex VI to AI Act applies, should be subject to the conformity assessment procedures provided for in this Regulation in so far as the essential cybersecurity requirements set out in this Regulation are concerned. In such a case, for all the other aspects covered by AI Act the relevant provisions on conformity assessment based on internal control set out in Annex VI to that Regulation should apply.