ANSSI publishes CRA notification process requirements for notified bodies
Original title: Exigences du CRA : processus de notification pour les organismes notifiés
ANSSI has published guidance on the notification process requirements for organisations notified under the Cybersecurity Requirements Act (CRA). The document addresses the notification procedures that notified bodies must follow in the context of increasing vulnerability exploitation affecting digital products with insufficient cybersecurity levels. Notified bodies must understand and comply with these requirements to fulfil their obligations under the CRA framework.
What changed
- ANSSI publishes formal requirements for the CRA notification process applicable to notified bodies, clarifying procedures for compliance with the Cybersecurity Requirements Act.
Who is affected
Notified bodies designated to assess compliance with the Cybersecurity Requirements Act in France; digital product manufacturers and distributors subject to CRA requirements; organisations handling digital products with cybersecurity obligations.
Summary generated by a language model; the official text prevails. Not legal advice.