Rättskällor med officiella primärkällor

Utskrivet ·

Hoppa till innehåll
Hoppa till svaret

Do the CERT-In directions cover the EU Cyber Resilience Act?

No. CERT-In regulates the operator, with a six-hour incident report and 180-day log retention in India. The Cyber Resilience Act regulates the product, with secure design, vulnerability handling and a 24-hour report to ENISA. Both chains have to be in place before an incident, not after.

What has to be done

  • Run a cybersecurity risk assessment for the product and document it as part of the technical file.
  • Ship secure by default: no universal factory passwords, and attack surface reduced to what the product needs.
  • Maintain a vulnerability handling process and a software bill of materials for the whole support period, and state that period plainly to the buyer.

Citations

Full requirement

Source and version

Read date
2026-08-26
Address
/in/questions/cert-in-versus-cra

Continue

Nästa steg

Vill ni använda registret i eget arbete finns tre vägar in.

Börja med din uppgift