BELGIUM Law and Practice Contributed by: Wim Nauwelaerts, Alston & Bird LLP
Conformity Assessment and CE Marking All PDEs must undergo a conformity assessment to demonstrate compliance with the CRA’s essen - tial cybersecurity requirements. Public EU guidance makes clear that: • default category PDEs may undergo self-assess - ment by the manufacturer, irrespective of whether harmonised standards exist; • important category PDEs may also use self- assessment only when the manufacturer fully applies harmonised standards or common specifi - cations, or holds qualifying European cybersecurity certifications; • important and critical PDEs (eg, identity manage - ment tools, password managers, firewalls, operat - ing systems and smart meters) may require third- party conformity assessment by a notified body; and • once conformity is demonstrated, the manufacturer must issue an EU Declaration of Conformity and affix the CE mark before placing the PDE on the market. These conformity assessment obligations become mandatory from 11 December 2027, when the CRA enters into full application. Transparency and Information Requirements Manufacturers of PDEs must provide users with clear and accessible information, including: • instructions for secure installation and configura - tion; • the PDE’s batch or serial number; • the end of support date, specifying how long secu - rity updates will be provided; and • contact details and documentation enabling users to understand the PDE’s cybersecurity posture. These disclosures aim to support more informed pro - curement decisions by Belgian businesses and public entities.
• maintain a formal Coordinated Vulnerability Disclo - sure (CVD) process; • issue security updates and patches without undue delay following discovery or notification of vulner - abilities; • provide security support throughout the declared support period, which must be communicated transparently to customers; and • maintain appropriate logging, monitoring and diag - nostic functionality. As of 11 September 2026, manufacturers will also be required to report actively exploited vulnerabilities and severe cybersecurity incidents through the EU’s new single reporting platform. This includes: • an early warning within 24 hours of becoming aware of the incident; • a full incident notification within 72 hours; and • a final report, submitted once the investigation is concluded. Post-Market Surveillance Obligations Manufacturers of PDEs are required under the CRA to conduct post-market monitoring and ensure contin - ued cybersecurity throughout the product’s support period. This includes: • ongoing assessment of vulnerabilities affecting the PDE and its components; • deploying remediation measures and issuing patches or updates without undue delay once vul - nerabilities are discovered or reported; • maintaining detailed technical documentation, including the results of post-market surveillance and actions taken; and • monitoring cybersecurity-related anomalies and incidents, and reporting actively exploited vul - nerabilities and severe incidents to the relevant authorities. Importers and distributors operating in Belgium must ensure that any PDE they place on the EU market: • bears the CE marking; • is accompanied by required documentation; and • is not supplied if non-compliant with CRA require - ments.
45 CHAMBERS.COM
Powered by FlippingBook