{"id":97862,"date":"2025-03-24T14:23:03","date_gmt":"2025-03-24T13:23:03","guid":{"rendered":"https:\/\/www.ictrechtswijzer.be\/?page_id=97862"},"modified":"2025-03-25T10:21:27","modified_gmt":"2025-03-25T09:21:27","slug":"cra","status":"publish","type":"page","link":"https:\/\/www.ictrechtswijzer.be\/en\/cra\/","title":{"rendered":"The Cyber Resilience Act (CRA): a new European regulatory framework for cybersecurity"},"content":{"rendered":"<h3 class=\"wp-block-heading\" id=\"h-inleiding\">Introduction<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The European Union continues its ambition to strengthen the digital single market through a robust regulatory framework that places cybersecurity at its core. Following previous initiatives such as the <a href=\"https:\/\/www.ictrechtswijzer.be\/en\/niche2\/\" target=\"_blank\" rel=\"noreferrer noopener\">NIS2 directive<\/a> and <a href=\"https:\/\/www.ictrechtswijzer.be\/en\/dora-digital-operational-resilience-for-the-financial-sector\/\">Digital Operational Resilience Act (DORA).<\/a>, is on December 10, 2024 the <a href=\"https:\/\/eur-lex.europa.eu\/eli\/reg\/2024\/2847\/oj\" target=\"_blank\" rel=\"noreferrer noopener\">regulation on horizontal cybersecurity requirements for products with digital elements<\/a>, or Regulation Cyber Resilience officially went into effect. This <strong>Cyber Resilience Act (CRA).<\/strong> has far-reaching implications for companies marketing \"products with digital elements\" in the European market.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The CRA is the <strong>First EU legislation to impose horizontal cybersecurity obligations for products with digital elements<\/strong>. It aims not only to protect consumers, but also to raise the overall level of cybersecurity within the internal market.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Purpose and scope of the CRA<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The CRA applies to <strong>all products with digital elements<\/strong>, including both hardware and software that can be directly or indirectly connected to a network. For example.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Internet of Things (IoT) devices such as smart thermostats or smart watches.<\/li>\n\n\n\n<li>Operating systems and applications for laptops, smartphones or servers.<\/li>\n\n\n\n<li>Software development kits (SDKs).<\/li>\n\n\n\n<li>Industrial automation products.<\/li>\n\n\n\n<li>And even AI applications, if connected to networks.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The scope is thus extremely broad, touching both classic IT players and manufacturers in sectors such as healthcare, mobility, energy or construction, once their products incorporate digital functionalities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Exceptions are provided for products already covered by specific EU legislation, such as medical devices (MDR), aerospace products or automotive parts, provided they already contain similar cybersecurity requirements.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-op-wie-is-de-cra-van-toepassing\">To whom does the CRA apply?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The CRA imposes obligations on various actors in the supply chain, including.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Manufacturers<\/strong> Of products with digital elements.<\/li>\n\n\n\n<li><strong>Importers<\/strong> and <strong>distributors<\/strong> of such products in the EU market.<\/li>\n\n\n\n<li>To a limited extent also <strong>open-source software providers<\/strong>, although these are largely outside the scope if the software is provided free of charge and non-commercially.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For Belgian companies that develop, sell or distribute digital products, it is therefore essential to check whether they are covered by this new regulation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Read more about <a href=\"https:\/\/www.ictrechtswijzer.be\/en\/the-cyber-resilience-act-cra-and-software-development\/\" target=\"_blank\" rel=\"noreferrer noopener\">the impact of the CRA on software development<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Key obligations under the CRA<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The CRA contains a series of <em>ex-ante<\/em> and <em>ex-post<\/em> obligations that cover the entire product life cycle.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1. <strong>Security requirements by design<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Manufacturers must integrate cybersecurity from product design and development (\"security by design and by default\"). This includes.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Protection against unauthorized access or tampering.<\/li>\n\n\n\n<li>Security updates must be able to be installed in a secure and automated manner.<\/li>\n\n\n\n<li>The software must be resistant to known vulnerabilities and have incident detection mechanisms.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">2. <strong>Risk assessment and conformity assessment<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Manufacturers are required to provide a <strong>cybersecurity risk assessment<\/strong> perform a conformity assessment of each product they wish to market. Depending on the risk class (standard or high risk), a product must undergo conformity assessment through.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Internal technical documentation and self-certification.<\/li>\n\n\n\n<li>Or - for higher risk products - through a <strong>accredited conformity assessment body<\/strong> (Notified Body).<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">3. <strong>Vulnerability handling and reporting requirements<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">The CRA also introduces a mandatory <strong>vulnerability management system<\/strong>, including.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Active monitoring of vulnerabilities throughout the product life cycle (at least 5 years).<\/li>\n\n\n\n<li>The obligation to <strong>serious vulnerabilities within 24 hours<\/strong> after discovery to report to the European Cybersecurity Agency (<strong><a href=\"https:\/\/www.enisa.europa.eu\/\" target=\"_blank\" rel=\"noreferrer noopener\">ENISA<\/a><\/strong>);<\/li>\n\n\n\n<li>Communication to users in the event of risks or necessary security updates.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">4. <strong>Providing information to users<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">The manufacturer must provide clear and accessible information on.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The expected life of the product.<\/li>\n\n\n\n<li>The period during which security updates will be delivered.<\/li>\n\n\n\n<li>Recommended security settings and procedures.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Relationship to other European regulations<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The CRA is part of a broader strategy to strengthen digital resilience in the EU. It should <strong>be read in conjunction with other regulations<\/strong>, including.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><a href=\"https:\/\/www.ictrechtswijzer.be\/en\/niche2\/\" target=\"_blank\" rel=\"noreferrer noopener\">NIS2 directive<\/a><\/strong>: for vital industries, with emphasis on operational security.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.ictrechtswijzer.be\/en\/dora-digital-operational-resilience-for-the-financial-sector\/\" target=\"_blank\" rel=\"noreferrer noopener\">DORA<\/a><\/strong>: for the financial sector.<\/li>\n\n\n\n<li><strong><a href=\"https:\/\/www.ictrechtswijzer.be\/en\/the-ai-act\/\">AI Act<\/a><\/strong>: if the digital product contains AI functionality.<\/li>\n\n\n\n<li><strong>CE marking and product safety<\/strong>: products that meet the CRA requirements will bear the CE mark, indicating that they conform to European cybersecurity standards.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Timeline and transition period<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Although the CRA entered into force on December 10, 2024, the obligations are not immediately applicable. A phased implementation is planned.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>June 11, 2026:<\/strong> Conformity assessment bodies must comply with the new requirements as of this date.<\/li>\n\n\n\n<li><strong>Sept. 11, 2026:<\/strong> Manufacturers are required to report serious vulnerabilities and security incidents to the European Cybersecurity Agency (ENISA) as of this date. <\/li>\n\n\n\n<li><strong>Dec. 11, 2027:<\/strong> The other obligations, including cybersecurity requirements for products and the duty of care for security updates, are in full effect from this date.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This transition period allows companies to adapt their products and processes to the new requirements and fully integrate cybersecurity into their product development and operations.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Sanctions for non-compliance<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Cyber Resilience Act provides significant penalties for companies that fail to comply.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Violation of essential cybersecurity requirements or obligations:<\/strong> Fines can be as high as <strong>\u20ac15 million<\/strong> or <strong>2.5% of total global annual sales<\/strong>, using the highest amount.<\/li>\n\n\n\n<li><strong>Providing incorrect, incomplete or misleading information to notified bodies and supervisory authorities:<\/strong> This can also result in fines of up to <strong>\u20ac15 million<\/strong> or <strong>2.5% of total global annual sales<\/strong>, depending on which amount is higher.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">In addition to financial penalties, national authorities can take additional measures, such as recalling noncompliant products or imposing temporary or permanent sales bans. These strict enforcement measures underscore the importance for companies to comply with CRA requirements in a timely manner to minimize legal and financial risks.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What does this mean concretely for Belgian companies?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For Belgian companies developing, distributing or implementing digital products, it is important to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Already a <strong>internal audit process<\/strong> up their products in function of the CRA;<\/li>\n\n\n\n<li>The necessary <strong>cybersecurity practices and procedures<\/strong> implement, including vulnerability management;<\/li>\n\n\n\n<li>Consider whether they need to update their CE markings;<\/li>\n\n\n\n<li>Train legal and technical staff around the new obligations.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Although the CRA will not take effect until 2026, the <strong>act now essential<\/strong>. After all, product development processes are long and complex, and early preparation provides a competitive advantage and reduces the risk of market disruption.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Conclusion<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Cyber Resilience Act represents a significant step forward in strengthening digital security within the European Union. It is crucial for Belgian companies to start implementing the required measures in time to comply with the new regulations and ensure the security of their products. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our attorneys are ready to assist you in analyzing CRA obligations, drafting internal procedures, or reconciling your CE compliance. <\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link has-white-color has-text-color has-background has-link-color wp-element-button\" href=\"https:\/\/www.ictrechtswijzer.be\/en\/contact\/\" style=\"background-color:#5f82bc\" target=\"_blank\" rel=\"noreferrer noopener\">Contact our attorneys specializing in cybersecurity for more advice.<\/a><\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>","protected":false},"excerpt":{"rendered":"<p>Inleiding De Europese Unie zet haar ambitie voort om de digitale interne markt te versterken door middel van een robuust regelgevend kader dat cyberbeveiliging centraal plaatst. Na eerdere initiatieven zoals de NIS2-richtlijn en de Digital Operational Resilience Act (DORA), is op 10 december 2024 de verordening betreffende horizontale cyberbeveiligingsvereisten voor producten met digitale elementen, oftewel [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":97864,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[104],"tags":[],"class_list":["post-97862","page","type-page","status-publish","has-post-thumbnail","hentry","category-cyberbeveiliging"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v28.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>De Cyber Resilience Act (CRA): een nieuw Europees regelgevend kader voor cybersecurity - ICT Rechtswijzer Advocaat<\/title>\n<meta name=\"description\" content=\"De Cyber Resilience Act (CRA) is een EU-verordening die uniforme cybersecurity-eisen stelt aan producten met digitale elementen, om consumenten en bedrijven te beschermen tegen cyberdreigingen.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.ictrechtswijzer.be\/en\/cra\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"De Cyber Resilience Act (CRA): een nieuw Europees regelgevend kader voor cybersecurity\" \/>\n<meta property=\"og:description\" content=\"De Cyber Resilience Act (CRA) is een EU-verordening die uniforme cybersecurity-eisen stelt aan producten met digitale elementen, om consumenten en bedrijven te beschermen tegen cyberdreigingen.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.ictrechtswijzer.be\/en\/cra\/\" \/>\n<meta property=\"og:site_name\" content=\"ICT Rechtswijzer Advocaat\" \/>\n<meta property=\"article:modified_time\" content=\"2025-03-25T09:21:27+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/03\/cyber-4867294_1280.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"640\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/cra\\\/\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/cra\\\/\",\"name\":\"De Cyber Resilience Act (CRA): een nieuw Europees regelgevend kader voor cybersecurity - ICT Rechtswijzer Advocaat\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/cra\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/cra\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/cyber-4867294_1280.jpg\",\"datePublished\":\"2025-03-24T13:23:03+00:00\",\"dateModified\":\"2025-03-25T09:21:27+00:00\",\"description\":\"De Cyber Resilience Act (CRA) is een EU-verordening die uniforme cybersecurity-eisen stelt aan producten met digitale elementen, om consumenten en bedrijven te beschermen tegen cyberdreigingen.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/cra\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.ictrechtswijzer.be\\\/cra\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/cra\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/cyber-4867294_1280.jpg\",\"contentUrl\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/cyber-4867294_1280.jpg\",\"width\":1280,\"height\":640},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/cra\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"De Cyber Resilience Act (CRA): een nieuw Europees regelgevend kader voor cybersecurity\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#website\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/\",\"name\":\"ICT Rechtswijzer Advocaat\",\"description\":\"Advocaten in IP, AI, IT, privacy &amp; media\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Organization\",\"LegalService\"],\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#organization\",\"name\":\"ICT Rechtswijzer\",\"alternateName\":\"ICT Rechtswijzer, kennisplatform van Everest Advocaten\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/joris-deene-auteursrecht-in-een-digitale-omgeving-1-638.jpg\",\"contentUrl\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/wp-content\\\/uploads\\\/2018\\\/08\\\/joris-deene-auteursrecht-in-een-digitale-omgeving-1-638.jpg\",\"width\":638,\"height\":479,\"caption\":\"ICT Rechtswijzer\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ictrechtswijzer.be\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/be.linkedin.com\\\/company\\\/everest-law\",\"https:\\\/\\\/www.everest-law.eu\\\/\"],\"description\":\"Kennisplatform van het departement intellectuele eigendom, IT-recht, AI-recht, gegevensbescherming en mediarecht van Everest Advocaten, onder leiding van mr. Joris Deene.\",\"parentOrganization\":{\"@type\":\"LegalService\",\"name\":\"Everest Advocaten\",\"url\":\"https:\\\/\\\/www.everest-law.eu\",\"address\":{\"@type\":\"PostalAddress\",\"streetAddress\":\"Bollebergen 2A bus 20\",\"postalCode\":\"9052\",\"addressLocality\":\"Gent\",\"addressCountry\":\"BE\"}}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"The Cyber Resilience Act (CRA): a new European regulatory framework for cybersecurity - ICT Lawyer's Guide","description":"The Cyber Resilience Act (CRA) is an EU regulation that imposes uniform cybersecurity requirements on products with digital elements to protect consumers and businesses from cyber threats.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.ictrechtswijzer.be\/en\/cra\/","og_locale":"en_US","og_type":"article","og_title":"De Cyber Resilience Act (CRA): een nieuw Europees regelgevend kader voor cybersecurity","og_description":"De Cyber Resilience Act (CRA) is een EU-verordening die uniforme cybersecurity-eisen stelt aan producten met digitale elementen, om consumenten en bedrijven te beschermen tegen cyberdreigingen.","og_url":"https:\/\/www.ictrechtswijzer.be\/en\/cra\/","og_site_name":"ICT Rechtswijzer Advocaat","article_modified_time":"2025-03-25T09:21:27+00:00","og_image":[{"width":1280,"height":640,"url":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/03\/cyber-4867294_1280.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.ictrechtswijzer.be\/cra\/","url":"https:\/\/www.ictrechtswijzer.be\/cra\/","name":"The Cyber Resilience Act (CRA): a new European regulatory framework for cybersecurity - ICT Lawyer's Guide","isPartOf":{"@id":"https:\/\/www.ictrechtswijzer.be\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.ictrechtswijzer.be\/cra\/#primaryimage"},"image":{"@id":"https:\/\/www.ictrechtswijzer.be\/cra\/#primaryimage"},"thumbnailUrl":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/03\/cyber-4867294_1280.jpg","datePublished":"2025-03-24T13:23:03+00:00","dateModified":"2025-03-25T09:21:27+00:00","description":"The Cyber Resilience Act (CRA) is an EU regulation that imposes uniform cybersecurity requirements on products with digital elements to protect consumers and businesses from cyber threats.","breadcrumb":{"@id":"https:\/\/www.ictrechtswijzer.be\/cra\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.ictrechtswijzer.be\/cra\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ictrechtswijzer.be\/cra\/#primaryimage","url":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/03\/cyber-4867294_1280.jpg","contentUrl":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2025\/03\/cyber-4867294_1280.jpg","width":1280,"height":640},{"@type":"BreadcrumbList","@id":"https:\/\/www.ictrechtswijzer.be\/cra\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.ictrechtswijzer.be\/"},{"@type":"ListItem","position":2,"name":"De Cyber Resilience Act (CRA): een nieuw Europees regelgevend kader voor cybersecurity"}]},{"@type":"WebSite","@id":"https:\/\/www.ictrechtswijzer.be\/#website","url":"https:\/\/www.ictrechtswijzer.be\/","name":"ICT Lawyer","description":"Lawyers in IP, AI, IT, privacy &amp; media","publisher":{"@id":"https:\/\/www.ictrechtswijzer.be\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.ictrechtswijzer.be\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Organization","LegalService"],"@id":"https:\/\/www.ictrechtswijzer.be\/#organization","name":"ICT Legal Guide","alternateName":"ICT Rechtswijzer, kennisplatform van Everest Advocaten","url":"https:\/\/www.ictrechtswijzer.be\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ictrechtswijzer.be\/#\/schema\/logo\/image\/","url":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2018\/08\/joris-deene-auteursrecht-in-een-digitale-omgeving-1-638.jpg","contentUrl":"https:\/\/www.ictrechtswijzer.be\/wp-content\/uploads\/2018\/08\/joris-deene-auteursrecht-in-een-digitale-omgeving-1-638.jpg","width":638,"height":479,"caption":"ICT Rechtswijzer"},"image":{"@id":"https:\/\/www.ictrechtswijzer.be\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/be.linkedin.com\/company\/everest-law","https:\/\/www.everest-law.eu\/"],"description":"Knowledge platform of the Intellectual Property, IT Law, AI Law, Data Protection, and Media Law department at Everest Advocaten, led by Joris Deene, Esq.","parentOrganization":{"@type":"LegalService","name":"Everest Advocaten","url":"https:\/\/www.everest-law.eu","address":{"@type":"PostalAddress","streetAddress":"Bollebergen 2A bus 20","postalCode":"9052","addressLocality":"Gent","addressCountry":"BE"}}}]}},"_links":{"self":[{"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/pages\/97862","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/comments?post=97862"}],"version-history":[{"count":0,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/pages\/97862\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/media\/97864"}],"wp:attachment":[{"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/media?parent=97862"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/categories?post=97862"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ictrechtswijzer.be\/en\/wp-json\/wp\/v2\/tags?post=97862"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}