ESD Comment on the Commission Draft Implementing Regulation Based on the Cyber Resilience Act (CRA)

Written by

in

Additional Regulation Should Deliver Additional Cybersecurity BenefitsWhere It Does Not, Avoid Duplicating Existing High-Assurance Requirements.

Consultation Responses · April 13, 2025

Strong cybersecurity is essential for Europe’s digital infrastructure — but stronger security does not necessarily mean adding overlapping regulatory layers. In its comments on the CRA Implementing Regulation, ESD highlights that Qualified Trust Service Providers already operate under a comprehensive high-assurance security, supervision and conformity-assessment framework under eIDAS and related standards. Applying additional CRA requirements to the same regulated services and their necessary software components risks duplicating compliance obligations without delivering corresponding cybersecurity benefits. ESD therefore calls for a clear delineation between the horizontal CRA framework and the sector-specific eIDAS regime.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *