---
title: サイバーレジリエンス法 CRA －要求事項が明確に－
description: CRAサイバーレジリエンス法の要求事項が明確になり、ネットワーク製品の継続的なサイバーセキュリティリスク評価が必要となった。企業にとって早期の準備が可能かつ重要。
image: https://insights.tuv.com/hubfs/JP-Images/2024/tuev-rheinland-pressrelease-cyber-resilience-act.jpg
---

[![TUV Rheinland](https://insights.tuv.com/hs-fs/hubfs/Images/TUEVRL-516low.jpg?width=388&height=432&name=TUEVRL-516low.jpg "TUV Rheinland")](https://www.tuv.com/japan/jp/)

Connect with us [![linkedin](https://insights.tuv.com/hs-fs/hubfs/linkedin-grey.png?width=24&name=linkedin-grey.png) ](https://www.linkedin.com/company/tuv-rheinland-asia) [![linkedin_af](https://insights.tuv.com/hs-fs/hubfs/linkedin_af-grey.png?width=24&name=linkedin_af-grey.png) ](https://www.linkedin.com/company/tuv-rheinland-africa/) [![twitter](https://insights.tuv.com/hs-fs/hubfs/twitter-grey.png?width=24&name=twitter-grey.png) ](https://twitter.com/tuvcom_japan) [![youtube](https://insights.tuv.com/hs-fs/hubfs/youtube-grey.png?width=24&name=youtube-grey.png) ](https://www.youtube.com/playlist?list=PLTKalGrW57kv2D83jZbpoFQKQrYh56nAx)

[**](https://insights.tuv.com/jpblog/industry002#left-menu)

- [Home](https://apac.tuv.com/blog)
- [About Us](https://www.tuv.com/en/corporate/about_us_1/facts_figures_1/facts_figures.html)
- [Contact Us](https://apac.tuv.com/contact-us)

Connect with us [![linkedin](https://insights.tuv.com/hs-fs/hubfs/linkedin-grey.png?width=24&name=linkedin-grey.png) ](https://www.linkedin.com/company/tuv-rheinland-asia) [![linkedin_af](https://insights.tuv.com/hs-fs/hubfs/linkedin_af-grey.png?width=24&name=linkedin_af-grey.png) ](https://www.linkedin.com/company/tuv-rheinland-africa/) [![twitter](https://insights.tuv.com/hs-fs/hubfs/twitter-grey.png?width=24&name=twitter-grey.png) ](https://twitter.com/tuvcom_japan) [![youtube](https://insights.tuv.com/hs-fs/hubfs/youtube-grey.png?width=24&name=youtube-grey.png) ](https://www.youtube.com/playlist?list=PLTKalGrW57kv2D83jZbpoFQKQrYh56nAx)

![tuv-jp-blog-banner](https://insights.tuv.com/hs-fs/hubfs/JP-Images/2018%20template/tuv-jp-blog-banner.jpg?width=1440&name=tuv-jp-blog-banner.jpg "tuv-jp-blog-banner")

# サイバーレジリエンス法 CRA －要求事項が明確に－

Posted by [TUV Rheinland Japan](https://insights.tuv.com/jpblog/author/tuv-rheinland-japan) on 2024/05/30 8:27:12

![TUV Rheinland Japan](https://insights.tuv.com/hubfs/Images/TRlogo2.jpg)

- [Tweet](https://twitter.com/share)

EUサイバーセキュリティ機関、規格の適用に関する重要な問題を明確化｜今後はネットワーク製品の継続的なサイバーセキュリティリスク評価が必要｜  
企業にとって早期の準備が可能かつ重要

 

 

2024年4月23日付 テュフ ラインランドのプレスリリースの日本語訳です。[原文はこちら](https://www.tuv.com/press/en/press-releases/tuev-rheinland-cyber-resilience-act.html)。

疑問点等については原文を参照ください。

 

欧州連合サイバーセキュリティ庁（ENISA）が新たに発行した文書（以下マッピング）は、基本的なサイバーセキュリティ要件と、サイバーレジリエンス法に基づき適用可能な標準について、より明確にしました。「このマッピングは、サイバーレジリエンス法に基づく標準化プロセスに関する洞察を初めて提供するものです。ENISAは、提案されている要件と整合規格への実装について、有益な概要を提供しています。」テュフ ラインランドのサイバーセキュリティ専門家であるフェリックス・ブロムバッハは述べています。

![tuev-rheinland-pressrelease-cyber-resilience-act](https://insights.tuv.com/hs-fs/hubfs/JP-Images/2024/tuev-rheinland-pressrelease-cyber-resilience-act.jpg?width=400&height=267&name=tuev-rheinland-pressrelease-cyber-resilience-act.jpg)

求められる「セキュリティ・バイ・デザイン」

この背景には、2024年3月にEU議会を通過したサイバーレジリエンス法（CRA）があります。CRAの目的は、相互接続やインターネット接続が可能な製品のサイバーセキュリティを向上させることです。これは最終消費者向けの製品だけでなく、例えば企業が生産に使用する製品にも適用されます。CRAは、「セキュリティ・バイ・デザイン」の原則を初めて欧州の技術法に取り入れました。今後デジタル要素を含む製品のCRA適合性は、市場参入時のみでは不十分となり、継続的なリスク評価が必要となります。

サイバーレジリエンス法は、そのような製品を製造する企業や、生産に使用するすべての企業に関わってきます。しかし、CRAの基本的な要件について情報が不足しており、企業は対応に備える準備が不足していました。このマッピングとその中で説明されている 「ガードレール」によって、自社のデジタル・ネットワーク製品がすでにCRAが要求する基準を満たしている可能性が高いかどうかを分析することが可能になりました。

 

ギャップを早期に認識  

 テュフ ラインランドのサイバーセキュリティ専門家によると、企業はこのマッピングで示された国際的に認知された基準にできるだけ早く対応し、それに従って製品を保護する必要があるということです。企業はすでにCRAに対応するセキュリティレベルを達成することができます。もしくは、適切なタイミングでギャップを特定することができます。CRAは欧州理事会で採択されてから24ヶ月以内に発効する予定です。CRAは規則であるため、すべての欧州加盟国に直接適用されます。

 

ENISA が新たに発効した文書（マッピング）はこちらよりご覧いただけます[　Cyber Resilience Act Requirements Standards Mapping - ENISA](https://www.enisa.europa.eu/publications/cyber-resilience-act-requirements-standards-mapping)

 

<https://www.tuv.com/content-media-files/japan/pdfs/lp-academy-lifecare/seminar/p04/0626%E6%9C%80%E6%96%B0%E5%8B%95%E5%90%91cra%E3%82%BB%E3%83%9F%E3%83%8A%E3%83%BC%E3%80%90%E3%82%AA%E3%83%B3%E3%83%A9%E3%82%A4%E3%83%B3%E3%80%91.pdf>CRAオンラインセミナー 6月26日開催

第2回目では、3月12日に発行された最終版ドラフトをもとに、さらに明確になった内容について解説！

[![CRA blog image](https://insights.tuv.com/hs-fs/hubfs/JP-Images/2024/CRA%20blog%20image.png?width=688&height=220&name=CRA%20blog%20image.png)](https://www.tuv.com/content-media-files/japan/pdfs/lp-academy-lifecare/seminar/p04/0626%E6%9C%80%E6%96%B0%E5%8B%95%E5%90%91cra%E3%82%BB%E3%83%9F%E3%83%8A%E3%83%BC%E3%80%90%E3%82%AA%E3%83%B3%E3%83%A9%E3%82%A4%E3%83%B3%E3%80%91.pdf)

 

　関連ブログ｜[サイバーレジリエンス法とは](https://insights.tuv.com/jpblog/cyberresillienceact)

お問い合わせ：カスタマーサービス（TEL: 045-470-1850 E-Mail: [info@jpn.tuv.com](mailto:info@jpn.tuv.com?subject=[Blog]CRAサイバーレジリエンス法（PR）)）

更新日 : 5/30/2024

 

 Topics: [cybersecurity](https://insights.tuv.com/jpblog/topic/cybersecurity), [サイバーセキュリティ](https://insights.tuv.com/jpblog/topic/サイバーセキュリティ), [製品安全](https://insights.tuv.com/jpblog/topic/製品安全)

© 2026 TÜV Rheinland

![](https://dc.ads.linkedin.com/collect/?pid=428209&fmt=gif)