Domande Frequenti Frequently Asked Questions
Risposte chiare e tecniche sulle domande più comuni riguardo al Cyber Resilience Act: ambito di applicazione, requisiti, scadenze e percorso di certificazione. Clear, technical answers to the most common questions about the Cyber Resilience Act: scope, requirements, deadlines, and the certification path.
Il CRA definisce "prodotto con elementi digitali" qualsiasi prodotto software o hardware che si connette direttamente o indirettamente a un altro dispositivo o rete. Include: dispositivi IoT, applicazioni software, sistemi operativi, componenti hardware con firmware, app mobili, software industriale (OT/ICS), router, smart device, e qualsiasi prodotto che processa dati digitali.
The CRA defines "product with digital elements" as any software or hardware product that directly or indirectly connects to another device or network. This includes: IoT devices, software applications, operating systems, hardware components with firmware, mobile apps, industrial software (OT/ICS), routers, smart devices, and any product that processes digital data.
Sono esclusi: prodotti già coperti da normative settoriali specifiche (dispositivi medici sotto MDR/IVDR, veicoli a motore sotto il regolamento UE 2019/2144, aviazione civile, equipaggiamento navale) e prodotti sviluppati esclusivamente per scopi di sicurezza nazionale o difesa.
Excluded are: products already covered by sector-specific regulations (medical devices under MDR/IVDR, motor vehicles under EU Regulation 2019/2144, civil aviation, marine equipment) and products developed exclusively for national security or defense purposes.
In linea generale, il SaaS puro — servizi erogati interamente in cloud senza che il cliente installi nulla — non è direttamente soggetto al CRA. Il CRA disciplina i prodotti, non i servizi. Tuttavia, ci sono eccezioni importanti:
In general, pure SaaS — services delivered entirely in the cloud with nothing installed by the customer — is not directly subject to the CRA. The CRA governs products, not services. However, there are important exceptions:
La distinzione è sottile e dipende dall'architettura specifica. Se non sei sicuro, contattaci per una valutazione.
The distinction is subtle and depends on the specific architecture. If unsure, contact us for an assessment.
Il CRA distingue tre classi di prodotti in base al rischio di sicurezza:
The CRA distinguishes three product classes based on security risk:
Il "produttore" (o fabbricante) è la persona fisica o giuridica che sviluppa o fa sviluppare prodotti con elementi digitali e li immette sul mercato UE con il proprio nome o marchio. Questo include:
The "manufacturer" is the natural or legal person who develops or has developed products with digital elements and places them on the EU market under their own name or trademark. This includes:
Il software open source non commerciale sviluppato al di fuori di attività commerciali è escluso dal CRA. Tuttavia, l'esclusione non si applica quando:
Non-commercial open source software developed outside of commercial activity is excluded from the CRA. However, the exclusion does not apply when:
I maintainer di software open source che contribuiscono a titolo personale e senza scopo commerciale non sono soggetti al CRA, ma dovranno rilasciare dichiarazioni appropriate. Esiste una categoria di "steward open source" con obblighi alleggeriti per chi supporta progetti critici.
Open source maintainers who contribute personally and without commercial purpose are not subject to the CRA, but will need to issue appropriate declarations. There is an "open-source steward" category with lighter obligations for those supporting critical projects.
"Secure by Design" è un requisito fondamentale dell'Allegato I, Parte I del CRA. Significa che la sicurezza deve essere integrata nel processo di sviluppo fin dall'inizio, non aggiunta come strato successivo. In pratica richiede:
"Secure by Design" is a fundamental requirement of CRA Annex I, Part I. It means security must be built into the development process from the outset, not bolted on afterwards. In practice it requires:
Sì. L'Allegato I, Parte I del CRA richiede esplicitamente che i produttori identifichino e documentino le componenti software di terze parti, incluse le dipendenze open source. L'SBOM (Software Bill of Materials) è lo strumento standard per soddisfare questo requisito.
Yes. CRA Annex I, Part I explicitly requires manufacturers to identify and document third-party software components, including open-source dependencies. The SBOM (Software Bill of Materials) is the standard tool for meeting this requirement.
Il CRA non specifica un formato obbligatorio, ma i formati più diffusi e raccomandati sono CycloneDX (OWASP) e SPDX (Linux Foundation). L'SBOM deve essere disponibile per le autorità di vigilanza su richiesta e può essere richiesto da clienti B2B o integratori.
The CRA does not mandate a specific format, but the most widely used and recommended formats are CycloneDX (OWASP) and SPDX (Linux Foundation). The SBOM must be available to market surveillance authorities on request and may be required by B2B customers or integrators.
L'SBOM deve essere generato automaticamente nella pipeline CI/CD e aggiornato ad ogni release.
The SBOM should be automatically generated in the CI/CD pipeline and updated with every release.
Il CRA (Art. 14) impone obblighi di notifica molto stringenti per le vulnerabilità sfruttate attivamente (actively exploited):
The CRA (Art. 14) imposes very tight notification obligations for actively exploited vulnerabilities:
Questi obblighi si attivano per le vulnerabilità attivamente sfruttate. Per le vulnerabilità scoperte ma non ancora sfruttate, il produttore deve gestirle nell'ambito del proprio processo CVD (Coordinated Vulnerability Disclosure) e rilasciare patch entro i termini ragionevoli stabiliti dalla propria policy.
These obligations are triggered for actively exploited vulnerabilities. For vulnerabilities discovered but not yet exploited, the manufacturer must manage them within their CVD (Coordinated Vulnerability Disclosure) process and release patches within reasonable timelines defined by their policy.
Sì, è un requisito esplicito dell'Allegato I, Parte II del CRA. I produttori devono:
Yes, it is an explicit requirement of CRA Annex I, Part II. Manufacturers must:
La policy CVD è spesso implementata tramite una pagina /.well-known/security.txt e una sezione dedicata sul sito del prodotto, con un indirizzo email dedicato (es. security@azienda.com).
The CVD policy is often implemented via a /.well-known/security.txt page and a dedicated section on the product website, with a dedicated email address (e.g., security@company.com).
Il CRA richiede che i produttori forniscano aggiornamenti di sicurezza per il periodo di supporto atteso del prodotto, o per un minimo di 5 anni (se il ciclo di vita previsto è inferiore). Il produttore deve dichiarare esplicitamente la durata del periodo di supporto nella documentazione del prodotto.
The CRA requires manufacturers to provide security updates for the expected support period of the product, or for a minimum of 5 years (if the expected lifecycle is shorter). The manufacturer must explicitly declare the duration of the support period in the product documentation.
Gli aggiornamenti devono essere distribuibili separatamente dai feature update, devono essere automatici dove possibile (con il consenso dell'utente), e devono essere accompagnati da informazioni chiare sulla natura della patch e sui rischi che mitiga.
Updates must be distributable separately from feature updates, must be automatic where possible (with user consent), and must be accompanied by clear information on the nature of the patch and the risks it mitigates.
L'Allegato VII del CRA definisce i requisiti della documentazione tecnica. Deve includere:
CRA Annex VII defines the technical documentation requirements. It must include:
La documentazione deve essere conservata per 10 anni dopo l'immissione sul mercato.
The documentation must be retained for 10 years after market placement.
Il CRA (Regolamento UE 2024/2847) è stato pubblicato nella Gazzetta Ufficiale dell'UE il 20 novembre 2024 ed è entrato in vigore il 10 dicembre 2024. Le date rilevanti sono:
The CRA (EU Regulation 2024/2847) was published in the EU Official Journal on 20 November 2024 and entered into force on 10 December 2024. Key dates are:
I prodotti già immessi sul mercato UE prima dell'11 dicembre 2027 non sono soggetti al CRA per quanto riguarda la marcatura CE e la valutazione di conformità, a meno che non subiscano modifiche sostanziali dopo quella data. Una modifica è "sostanziale" se altera le caratteristiche di sicurezza del prodotto o ne cambia la destinazione d'uso prevista.
Products already placed on the EU market before 11 December 2027 are not subject to the CRA regarding CE marking and conformity assessment, unless they undergo substantial modifications after that date. A modification is "substantial" if it alters the security characteristics of the product or changes its intended use.
Tuttavia, gli obblighi di segnalazione delle vulnerabilità (Art. 14) si applicano dal settembre 2026 a tutti i prodotti in commercio, anche quelli pre-CRA. Questo è il requisito più immediato e urgente per i produttori.
However, vulnerability reporting obligations (Art. 14) apply from September 2026 to all products on the market, including pre-CRA ones. This is the most immediate and urgent requirement for manufacturers.
Le sanzioni per la non conformità al CRA sono significative. Le autorità nazionali di vigilanza del mercato possono:
The penalties for non-compliance with the CRA are significant. National market surveillance authorities can:
Per falsa dichiarazione di conformità le sanzioni salgono a 5 milioni o 1% del fatturato.
For false declarations of conformity, penalties rise to €5 million or 1% of turnover.
La marcatura CE indica che il prodotto è conforme al CRA e può essere immesso sul mercato UE. Il percorso per ottenerla dipende dalla classe del prodotto:
The CE marking indicates that the product complies with the CRA and can be placed on the EU market. The path to obtaining it depends on the product class:
Gli standard armonizzati sono norme tecniche europee (EN) che, se rispettate, presumono conformità ai requisiti del CRA. La Commissione Europea ha incaricato CEN/CENELEC di sviluppare questi standard. I principali riferimenti tecnici attuali (che probabilmente confluiranno negli standard armonizzati) includono:
Harmonised standards are European technical standards (EN) that, when followed, presume compliance with CRA requirements. The European Commission has tasked CEN/CENELEC with developing these standards. Current main technical references (likely to feed into harmonised standards) include:
Gli standard armonizzati definitivi per il CRA sono attesi entro il 2025-2026 e saranno pubblicati nella Gazzetta Ufficiale UE.
The definitive harmonised standards for the CRA are expected by 2025-2026 and will be published in the EU Official Journal.
Potenzialmente sì, ma con limitazioni. Il CRA riconosce i schemi europei di certificazione della cybersicurezza definiti nell'ambito del Cybersecurity Act (Regolamento UE 2019/881), come l'EUCS (EU Cloud Scheme). Ottenere una certificazione EUCS al livello appropriato potrebbe essere sufficiente per soddisfare i requisiti del CRA per i prodotti corrispondenti.
Potentially yes, but with limitations. The CRA recognises European cybersecurity certification schemes defined under the Cybersecurity Act (EU Regulation 2019/881), such as the EUCS (EU Cloud Scheme). Obtaining an EUCS certification at the appropriate level could be sufficient to meet CRA requirements for corresponding products.
L'equivalenza però non è automatica e la Commissione deve formalmente riconoscere la corrispondenza tra uno schema specifico e i requisiti CRA. Questo processo è in corso e non ancora completato per la maggior parte degli schemi.
However, equivalence is not automatic and the Commission must formally recognise the correspondence between a specific scheme and CRA requirements. This process is ongoing and not yet complete for most schemes.
I costi variano significativamente in base alla dimensione dell'azienda, alla complessità del prodotto, e al grado di maturità del processo di sviluppo esistente. Indicativamente:
Costs vary significantly based on company size, product complexity, and the maturity of existing development processes. Indicatively:
Le aziende con un SDLC maturo, SBOM automatizzato e processo CVD già operativo affronteranno costi significativamente inferiori. Contattaci per una stima personalizzata.
Companies with a mature SDLC, automated SBOM, and an already-operational CVD process will face significantly lower costs. Contact us for a personalised estimate.