Skip to content

What qualifies a product as Important or Critical? #165

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
tobie opened this issue Mar 15, 2025 · 1 comment
Open

What qualifies a product as Important or Critical? #165

tobie opened this issue Mar 15, 2025 · 1 comment

Comments

@tobie
Copy link
Contributor

tobie commented Mar 15, 2025

Proposed answer:

Per Article 7 and 8, Important and Critical products are part of the product categories listed in Annex III and IV and defined in the draft implementing regulation. Product in these categories perform functions that are either:

  1. critical to cybersecurity or
  2. carry a significant risk of adverse effects to a large number of other products or to the the health, security or safety of their users

Note

Most products in scope of the CRA are not classified as Important or Critical.

👉 ORC WG is providing input to the draft implementing regulation.

@github-project-automation github-project-automation bot moved this to Needs triaging in FAQ Mar 15, 2025
@tobie tobie moved this from Needs triaging to Needs PR in FAQ Mar 16, 2025
@ilu33
Copy link

ilu33 commented Mar 28, 2025

In light of the misunderstanding in #169 it should be noted that the lists in the Annexes are - at this point in time - exhaustive. And that the reasons you gave in the second sentence do not mean that anything can be added to those lists without the formal procedure described in Art. 8 no. 2 CRA. So maybe you should drop your explanation because the sole criteria is: Is it in the list or not?
Or restructure it like
Per Article 7 and 8, Important and Critical products are part of the product categories listed in Annex III and IV. These lists are exhaustive. They are further defined in the draft implementing regulation.
The commision may add further products to these lists if they perform functions that are either:
critical to cybersecurity or
carry a significant risk of adverse effects to a large number of other products or to the the health, security or safety of their users
but hasn't done so yet.

@tobie tobie assigned bukka and tobie Apr 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: Needs PR
Development

No branches or pull requests

3 participants