DSOs strongly support Regulation (EU) 2024/2847, the Cyber Resilience Act. Its requirements are necessary to raise the cybersecurity baseline of digital products, improve vulnerability handling and strengthen the resilience of European supply chains.
In primary and secondary electrical substations, however, CRA implementation creates a specific transition challenge (e.g. stranded investment). Protection, control, automation, monitoring and managed power-supply equipment are part of tightly integrated operational architectures, with long engineering, qualification, industrialisation and construction cycles.
The resulting impact for DSOs is therefore primarily indirect but potentially high. If manufacturers and the wider supply chain cannot make CRA-compliant digital products available, qualified and industrialized at the required scale in time, DSOs may be unable to execute regulated substation investment plans, including projects scheduled for 2028 and 2029.
DSOs therefore request a narrow, evidence-based and risk-managed transitional framework. A mitigation strategy not to lower the CRA ambition, but to avoid supply-chain disruption, preserve investment plan execution and ensure that compliant solutions can be standardised, validated and industrialised before becoming mandatory at scale. This framework should be applied only to clearly identified equipment and already committed projects, with documented risk assessment, compensating controls, traceability, vendor support and a binding migration path to full CRA compliance.
To make this framework workable in practice, regulatory clarity is also needed on product classification, conformity-assessment routes and evidence expectations for transitional use.
Download the full report at: Link
Source: EU DSO Entity
Write a comment
Các trường bắt buộc được đánh dấu *