This thesis analyses the Cyber Resilience Act within the broader framework of European cybersecurity regulation, with a specific focus on governance and enforcement. It examines the transition from a mainly voluntary and sector-specific approach to a harmonised system of mandatory cybersecurity requirements for products with digital elements. The research explores the obligations imposed on economic operators, as well as the role of market surveillance authorities, ENISA and conformity assessment bodies. Particular attention is given to vulnerability management, product lifecycle security and the accountability mechanisms imposed on manufacturers. The thesis ultimately assesses the CRA’s effectiveness as a legal instrument for strengthening European cyber resilience and protecting the internal market.
La presente tesi analizza il Cyber Resilience Act nel quadro della regolazione europea della cybersicurezza, con particolare attenzione ai profili di governance ed enforcement. L’indagine si concentra sul passaggio da un modello prevalentemente volontario e settoriale a un sistema armonizzato di requisiti obbligatori per i prodotti con elementi digitali. Sono esaminati gli obblighi imposti agli operatori economici, il ruolo delle autorità di vigilanza del mercato, dell’ENISA e degli organismi di valutazione della conformità. Particolare rilievo è attribuito alla gestione delle vulnerabilità, alla sicurezza lungo il ciclo di vita del prodotto e ai meccanismi di responsabilizzazione dei fabbricanti. La tesi valuta infine l’efficacia del CRA come strumento di rafforzamento della cyber-resilienza europea e di tutela del mercato interno.
Il modello di governance ed enforcement della cybersicurezza nel Cyber Resilience Act
PAVAN, ALESSIO
2025/2026
Abstract
This thesis analyses the Cyber Resilience Act within the broader framework of European cybersecurity regulation, with a specific focus on governance and enforcement. It examines the transition from a mainly voluntary and sector-specific approach to a harmonised system of mandatory cybersecurity requirements for products with digital elements. The research explores the obligations imposed on economic operators, as well as the role of market surveillance authorities, ENISA and conformity assessment bodies. Particular attention is given to vulnerability management, product lifecycle security and the accountability mechanisms imposed on manufacturers. The thesis ultimately assesses the CRA’s effectiveness as a legal instrument for strengthening European cyber resilience and protecting the internal market.| File | Dimensione | Formato | |
|---|---|---|---|
|
Pavan_Alessio.pdf
Accesso riservato
Dimensione
821.07 kB
Formato
Adobe PDF
|
821.07 kB | Adobe PDF |
The text of this website © Università degli studi di Padova. Full Text are published under a non-exclusive license. Metadata are under a CC0 License
https://hdl.handle.net/20.500.12608/116423