SPAIN Law and Practice Contributed by: Vicente Moret, Rodrigo González, María Teresa Martínez and Cristina Durante, Deloitte Legal
ity of data processed, stored, or transmitted. It also mandates secure update mechanisms that cannot themselves be exploited, and operational resilience to ensure products remain safe even in degraded conditions. This approach ties security requirements to how products behave over time – how updates, vulnerabilities and incidents are handled – rather than to static feature claims. Vulnerability Handling as a Continuous Obligation The CRA requires manufacturers to maintain an oper - ational co-ordinated vulnerability disclosure process. This must include a publicly available channel through which researchers and users can report vulnerabilities and receive confirmation that their report is being han - dled. The aim is to institutionalise vulnerability man - agement as a routine life cycle function rather than an ad hoc reaction to reputational crises. Once aware of a vulnerability, manufacturers must investigate and remediate it without undue delay, where technically feasible. While the CRA recognises that remediation timelines vary by severity and does not mandate a sin- gle deadline, it enforces a standard of prompt action that can be evaluated through reporting duties and market surveillance. Security Updates and Minimum Support Periods A central provision of the CRA is the obligation to pro - vide security updates for the expected lifetime of the product. Where a product’s expected lifetime is unde - fined or shorter than five years, manufacturers must provide at least five years of security support. This addresses long standing problems caused by prod - ucts losing support while still in active use, leaving sig - nificant residual security risk. The CRA also requires that security updates be offered free of charge and clearly distinguished from feature updates, ensuring users can apply patches without being forced into functional changes. This requires manufacturers to maintain sustainable update delivery models across multiple generations of products – an economic chal -
dents, they must notify ENISA and the relevant nation - al CSIRT quickly. Reporting follows a staged timeline: an early warning within 24 hours, a more detailed noti - fication within 72 hours, and a final report within 14 days. The structure prioritises situational awareness early – when partial information can still help mitigate systemic risk – while allowing more complete analysis to follow. Conformity Assessment and CE Marking Before entering the EU market, products must under - go conformity assessment to demonstrate compli - ance with CRA essential requirements. For most products, manufacturers may self-assess where har - monised standards exist; higher risk product classes require third party involvement, and the highest-risk categories require assessment by a notified body. This introduces a cybersecurity dimension to the CE mark: it becomes a signal of baseline security compliance in addition to safety and electromagnetic compatibility. Early implementation challenges may arise from the timing and scope of harmonised standards, leaving manufacturers uncertain about how to demonstrate conformity against high level requirements. Post-Market Surveillance, Corrective Action, and Withdrawal/Recall The CRA establishes a post-market surveillance framework allowing authorities to monitor products already on the market and intervene when non-com - pliance emerges. If a product presents significant cybersecurity risk, authorities may require corrective measures, restrict availability, or mandate withdrawal or recall. The recall power is particularly significant: it transforms cybersecurity from a reputational issue into a market-access liability that can lead to forced product removal. The effectiveness of this mechanism will depend heavily on national technical capacity and enforcement resources. Penalties and Deterrence The CRA’s penalty structure aims to create strong deterrence. Serious breaches of essential require - ments can result in fines tied to a company’s world - wide turnover, ensuring that penalties are meaning - ful for both large global manufacturers and smaller producers. Additional sanctions apply for failures in vulnerability handling, reporting, or co-operation with
lenge as much as a regulatory one. Incident and Vulnerability Reporting
The CRA links manufacturers to the EU’s incident response infrastructure through mandatory report - ing. When a manufacturer becomes aware of actively exploited vulnerabilities or significant security inci -
339 CHAMBERS.COM
Powered by FlippingBook