GREECE Law and Practice Contributed by: Orfeas Mavredakis and Evangelos Katsaras, ALG Manousakis Law Firm
4.2 Key Obligations Under Legislation Pursuant to the CRA, manufacturers and distributors of PDE in Greece must comply with a set of baseline cybersecurity obligations designed to ensure product security throughout its life cycle. The key obligations for manufacturers are outlined below. Vulnerability Management and Reporting Obligations • Identify, document, and continuously monitor vulnerabilities in all software and hardware compo - nents. • Design products with security by design and security by default principles, including eliminat - ing default passwords, minimising attack surfaces, enforcing authentication and encryption, and ensuring security throughout the life cycle. • Ensure the resilience of essential product func - tions even during cyberattacks (eg, DoS hardening, watchdog systems). • Maintain and provide a complete Software Bill of Materials (SBOM) that tracks vulnerabilities in all components, including open-source elements. • From 11 September 2026, report actively exploited vulnerabilities and severe cybersecurity incidents via the CRA Single Reporting Platform to the com - petent CSIRT: (a) Within 24 hours: initial notification. (b) Within 72 hours: update with available informa - tion. (c) No later than 14 days after notification: final report including mitigation measures and cor - rective actions. Patching and Update Obligations • Provide free security updates without undue delay for the full duration of the declared support period (minimum expected product lifetime). • Ensure ongoing life cycle support. Post-Market Surveillance Obligations Actively monitor PDEs after market release for: • exploited vulnerabilities; • security incidents; and • weaknesses observed in deployment environ - ments.
Documentation Duties Maintain secure and up-to-date: • development documentation; • life cycle security evidence; • vulnerability logs; and • update histories, to support market surveillance Manufacturers, importers, and distributors must co- operate with market surveillance authorities – includ - ing those in Greece – by providing technical informa - tion and remediation plans when requested. Conformity Assessments • Classify their PDE based on the technical cri - teria outlined in Implementing Regulation (EU) 2025/2392 to determine whether it is a: (a) standard product; (b) important product (Class I or Class II); or (c) critical product. • Conduct self-assessments for non-critical products with lower cyber risk. activities and potential audits. Co-operation With Authorities • Co-ordinate a notified-body assessment for critical products where cybersecurity failure could have significant systemic impact. • Issue an EU Declaration of Conformity (DoC) con - firming the PDE complies with CRA requirements. Marking and Certification • Apply the CE mark to CRA-compliant products before they are sold in Greece or any EU member state. • Non-compliant products cannot be placed on the EU market beginning 11 December 2027. Importers and distributors also have responsibilities: they must not make available products that clearly fail to meet the requirements, must co-operate in cor - rective actions, and must support traceability. Where non-compliance or serious risks are identified, cor - rective measures may include market withdrawal or recall, with mandatory co-operation and notification to the competent market surveillance authorities.
178 CHAMBERS.COM
Powered by FlippingBook