{
  "slug": "bsi-tr-03183-cra-anforderungen",
  "title": "BSI TR-03183 – Technische Richtlinie zum Cyber Resilience Act (Teil 1 „General Requirements\", Version 1.0.0)",
  "topic_area": "datenschutz",
  "topic_label": "Datenschutz",
  "language": "de",
  "legal_status": "in_force",
  "valid_from": "2026-08-05",
  "valid_to": null,
  "last_reviewed": "2026-08-15",
  "factcheck_status": "ok",
  "authority_level": "A",
  "license": "CC-BY-4.0",
  "license_url": "https://creativecommons.org/licenses/by/4.0/deed.de",
  "attribution": "Nexvyra (https://nexvyra.de, Wikidata Q139919900)",
  "wikidata_subjects": [
    "Q118945294",
    "Q257906",
    "Q3510521"
  ],
  "summary": "Die Technische Richtlinie **BSI TR-03183 „Cyber Resilience Requirements for Manufacturers and Products\"** beschreibt die Auslegung des **Bundesamts für Sicherheit in der Informationstechnik (BSI)** zu den Cyber-Resilienz-Anforderungen an…",
  "urls": {
    "html": "https://nexvyra.de/fakten/bsi-tr-03183-cra-anforderungen.html",
    "markdown": "https://nexvyra.de/fakten/bsi-tr-03183-cra-anforderungen.md",
    "json": "https://nexvyra.de/fakten/bsi-tr-03183-cra-anforderungen.json"
  },
  "sources": [
    {
      "url": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "authority": "A"
    },
    {
      "url": "https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=CELEX%3A32024R2847",
      "authority": "A"
    },
    {
      "url": "https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr03183/TR-03183_node.html",
      "authority": "B"
    },
    {
      "url": "https://www.bsi.bund.de/DE/Service-Navi/Presse/Alle-Meldungen-News/Meldungen/2026/TR-03183_Einstiegshilfe_CRA_260805.html",
      "authority": "B"
    },
    {
      "url": "https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/TechGuidelines/TR03183/BSI-TR-03183-1_v1_0_0.pdf?__blob=publicationFile&v=3",
      "authority": "B"
    },
    {
      "url": "https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/TechGuidelines/TR03183/BSI-TR-03183-2_v2_1_0.pdf?__blob=publicationFile&v=6",
      "authority": "B"
    },
    {
      "url": "https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/TechGuidelines/TR03183/BSI-TR-03183-3_v1_0_0.pdf?__blob=publicationFile&v=4",
      "authority": "B"
    },
    {
      "url": "https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/TechGuidelines/TR03183/BSI-TR-03183-H_v1_1_0.pdf?__blob=publicationFile&v=3",
      "authority": "B"
    },
    {
      "url": "https://github.com/BSI-Bund/tr-03183-cyclonedx-property-taxonomy",
      "authority": "D"
    }
  ],
  "facts": [
    {
      "claim": "Vollständiger Titel: BSI TR-03183 „Cyber Resilience Requirements for Manufacturers and Products\"",
      "label": "Vollständiger Titel",
      "value": "BSI TR-03183 „Cyber Resilience Requirements for Manufacturers and Products\"",
      "source_url": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "source_authority": "A",
      "confidence": "high",
      "inline_source_label": "BSI, Themenseite TR-03183, abgerufen 2026-08-15",
      "last_verified": "2026-08-15"
    },
    {
      "claim": "Herausgeber: Bundesamt für Sicherheit in der Informationstechnik (BSI)",
      "label": "Herausgeber",
      "value": "Bundesamt für Sicherheit in der Informationstechnik (BSI)",
      "source_url": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "source_authority": "A",
      "confidence": "high",
      "last_verified": "2026-08-15"
    },
    {
      "claim": "Rechtlicher Charakter: unverbindliche Orientierungshilfe; „is not binding or mandatory. It cannot be used as presumption of conformity\"",
      "label": "Rechtlicher Charakter",
      "value": "unverbindliche Orientierungshilfe; „is not binding or mandatory. It cannot be used as presumption of conformity\"",
      "source_url": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "source_authority": "A",
      "confidence": "high",
      "inline_source_label": "BSI, Themenseite TR-03183",
      "last_verified": "2026-08-15"
    },
    {
      "claim": "Bezugsrechtsakt: Verordnung (EU) 2024/2847 (Cyber Resilience Act)",
      "label": "Bezugsrechtsakt",
      "value": "Verordnung (EU) 2024/2847 (Cyber Resilience Act)",
      "source_url": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "source_authority": "A",
      "confidence": "high",
      "inline_source_label": "EUR-Lex, CELEX:32024R2847",
      "last_verified": "2026-08-15"
    },
    {
      "claim": "Teil 1 „General Requirements\": Version 1.0.0, veröffentlicht 05.08.2026",
      "label": "Teil 1 „General Requirements\"",
      "value": "Version 1.0.0, veröffentlicht 05.08.2026",
      "source_url": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "source_authority": "A",
      "confidence": "high",
      "inline_source_label": "BSI-Meldung vom 05.08.2026",
      "last_verified": "2026-08-15"
    },
    {
      "claim": "Teil 2 „Software Bill of Materials (SBOM)\": Version 2.1.0",
      "label": "Teil 2 „Software Bill of Materials (SBOM)\"",
      "value": "Version 2.1.0",
      "source_url": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "source_authority": "A",
      "confidence": "high",
      "inline_source_label": "BSI, Themenseite TR-03183, abgerufen 2026-08-15",
      "last_verified": "2026-08-15"
    },
    {
      "claim": "Teil 3 „Vulnerability Reports and Notifications\": Version 1.0.0",
      "label": "Teil 3 „Vulnerability Reports and Notifications\"",
      "value": "Version 1.0.0",
      "source_url": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "source_authority": "A",
      "confidence": "high",
      "inline_source_label": "BSI, Themenseite TR-03183, abgerufen 2026-08-15",
      "last_verified": "2026-08-15"
    },
    {
      "claim": "Teil H „Conformity based on full quality assurance (Module H)\": Version 1.1.0",
      "label": "Teil H „Conformity based on full quality assurance (Module H)\"",
      "value": "Version 1.1.0",
      "source_url": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "source_authority": "A",
      "confidence": "high",
      "inline_source_label": "BSI, Themenseite TR-03183, abgerufen 2026-08-15",
      "last_verified": "2026-08-15"
    },
    {
      "claim": "Neu in Teil 1 v1.0.0: risikobasierter Ansatz zur Auswahl von IT-Sicherheitsmaßnahmen + Erstauswahl generischer Sicherheitsmaßnahmen im maschinenlesbaren OSCAL-Format (GitHub-Supplement)",
      "label": "Neu in Teil 1 v1.0.0",
      "value": "risikobasierter Ansatz zur Auswahl von IT-Sicherheitsmaßnahmen + Erstauswahl generischer Sicherheitsmaßnahmen im maschinenlesbaren OSCAL-Format (GitHub-Supplement)",
      "source_url": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "source_authority": "A",
      "confidence": "high",
      "inline_source_label": "BSI, Themenseite TR-03183, Abschnitt „Controls\"",
      "last_verified": "2026-08-15"
    },
    {
      "claim": "Zugang zu den OSCAL-Controls: per E-Mail an `tr03183@bsi.bund.de`",
      "label": "Zugang zu den OSCAL-Controls",
      "value": "per E-Mail an `tr03183@bsi.bund.de`",
      "source_url": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "source_authority": "A",
      "confidence": "high",
      "inline_source_label": "BSI, Themenseite TR-03183, Abschnitt „Controls\"",
      "last_verified": "2026-08-15"
    },
    {
      "claim": "Konformitätsvermutung: nur bei Übereinstimmung mit harmonisierten Normen, deren Fundstellen im Amtsblatt veröffentlicht sind",
      "label": "Konformitätsvermutung",
      "value": "nur bei Übereinstimmung mit harmonisierten Normen, deren Fundstellen im Amtsblatt veröffentlicht sind",
      "source_url": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "source_authority": "A",
      "confidence": "high",
      "inline_source_label": "Art. 27 Abs. 1 CRA",
      "last_verified": "2026-08-15"
    },
    {
      "claim": "Ablösung geplant: TR wird „gradually developed further and replaced by the corresponding harmonized European standards as soon as they become available\"",
      "label": "Ablösung geplant",
      "value": "TR wird „gradually developed further and replaced by the corresponding harmonized European standards as soon as they become available\"",
      "source_url": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "source_authority": "A",
      "confidence": "high",
      "inline_source_label": "BSI, Themenseite TR-03183",
      "last_verified": "2026-08-15"
    },
    {
      "claim": "CRA – Inkrafttreten: 20. Tag nach Veröffentlichung im Amtsblatt [Art. 71 Abs. 1 CRA] – damit 10.12.2024",
      "label": "CRA – Inkrafttreten",
      "value": "20. Tag nach Veröffentlichung im Amtsblatt [Art. 71 Abs. 1 CRA] – damit 10.12.2024",
      "source_url": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "source_authority": "A",
      "confidence": "high",
      "last_verified": "2026-08-15"
    },
    {
      "claim": "CRA – Geltung Art. 14 (Meldepflichten): 11. September 2026",
      "label": "CRA – Geltung Art. 14 (Meldepflichten)",
      "value": "11. September 2026",
      "source_url": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "source_authority": "A",
      "confidence": "high",
      "inline_source_label": "Art. 71 Abs. 2 Satz 2 CRA",
      "last_verified": "2026-08-15"
    },
    {
      "claim": "CRA – Geltung Kapitel IV (Art. 35–51, notifizierte Stellen): 11. Juni 2026",
      "label": "CRA – Geltung Kapitel IV (Art. 35–51, notifizierte Stellen)",
      "value": "11. Juni 2026",
      "source_url": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "source_authority": "A",
      "confidence": "high",
      "inline_source_label": "Art. 71 Abs. 2 Satz 2 CRA",
      "last_verified": "2026-08-15"
    },
    {
      "claim": "CRA – Geltung im Übrigen: 11. Dezember 2027",
      "label": "CRA – Geltung im Übrigen",
      "value": "11. Dezember 2027",
      "source_url": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "source_authority": "A",
      "confidence": "high",
      "inline_source_label": "Art. 71 Abs. 2 Satz 1 CRA",
      "last_verified": "2026-08-15"
    },
    {
      "claim": "SBOM-Pflicht im CRA: Ermittlung und Dokumentation von Schwachstellen und Komponenten „u. a. durch Erstellung einer Software-Stückliste in einem gängigen maschinenlesbaren Format, aus der zumindest die obersten Abhängigkeiten der Produkte hervorgehen\"",
      "label": "SBOM-Pflicht im CRA",
      "value": "Ermittlung und Dokumentation von Schwachstellen und Komponenten „u. a. durch Erstellung einer Software-Stückliste in einem gängigen maschinenlesbaren Format, aus der zumindest die obersten Abhängigkeiten der Produkte hervorgehen\"",
      "source_url": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "source_authority": "A",
      "confidence": "high",
      "inline_source_label": "Anhang I Teil II Nr. 1 CRA",
      "last_verified": "2026-08-15"
    },
    {
      "claim": "Konformitätsbewertungsverfahren: interne Kontrolle (Modul A), EU-Baumusterprüfung + interne Fertigungskontrolle (Modul B/C), umfassende Qualitätssicherung (Modul H) oder europäisches Cybersicherheits-Zertifizierungsschema",
      "label": "Konformitätsbewertungsverfahren",
      "value": "interne Kontrolle (Modul A), EU-Baumusterprüfung + interne Fertigungskontrolle (Modul B/C), umfassende Qualitätssicherung (Modul H) oder europäisches Cybersicherheits-Zertifizierungsschema",
      "source_url": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj",
      "source_authority": "A",
      "confidence": "high",
      "inline_source_label": "Art. 32 Abs. 1 CRA i. V. m. Anhang VIII",
      "last_verified": "2026-08-15"
    }
  ],
  "generated_at": "2026-09-04T14:16:45Z"
}