Do the CERT-In directions cover the EU Cyber Resilience Act?
No. CERT-In regulates the operator, with a six-hour incident report and 180-day log retention in India. The Cyber Resilience Act regulates the product, with secure design, vulnerability handling and a 24-hour report to ENISA. Both chains have to be in place before an incident, not after.
What has to be done
- Run a cybersecurity risk assessment for the product and document it as part of the technical file.
- Ship secure by default: no universal factory passwords, and attack surface reduced to what the product needs.
- Maintain a vulnerability handling process and a software bill of materials for the whole support period, and state that period plainly to the buyer.
Citations
Full requirement
Source and version
- Read date
- 2026-08-26
- Address
- /in/questions/cert-in-versus-cra
Continue
Nästa steg
Vill ni använda registret i eget arbete finns tre vägar in.
Börja med din uppgift
Advokat, tvist
Hitta stöd i avgörande
Sök i vägledande domar, se vad som vunnit laga kraft och följ ändringar i rättsläget.
Bolagsjurist, transaktion
Kartlägg regelverket i affären
Gå från tema till rättsakt och vidare till artikeln som bär kravet.
Compliance
Bedöm risken i en behandling
Riskklassning per rättsområde, med källorna bakom varje poäng.