CRAã»NIS2ã»CSA2ãèªåè»æ¥çã«äžãã圱é¿ãšã¯ïŒ OEMãä»ããåããã¹ãEUãµã€ããŒã»ãã¥ãªãã£èŠå¶
EUã§æ°ãã«åœ¢æããã€ã€ããããµã€ããŒã»ãã¥ãªãã£ã»ãã©ã€ã¢ãïŒãµã€ããŒã»ãã¥ãªãã£ã®äžäœäžäœèŠå¶ ïŒãã§ããCRAïŒCyber Resilience ActïŒãNIS2ïŒNetwork and Information Security Directive 2ïŒãCSA2ïŒEU Cyber Security Act 2ïŒã¯ãèªåè»æ¥çã«ããããµã€ããŒã»ãã¥ãªãã£å¯Ÿçãšãµãã©ã€ãã§ãŒã³ã³ã³ãã©ã€ã¢ã³ã¹ã®ããæ¹ã倧ããå€ããããšããŠããŸãããããã®èŠå¶ã«ãããã»ãã¥ã¢ã»ãã€ã»ãã¶ã€ã³ã«åºã¥ãè»äž¡éçºãã€ã³ã·ãã³ãå ±åãSBOMã®éææ§ç¢ºä¿ããããŠé«ãªã¹ã¯ãµãã©ã€ã€ãŒã®ç®¡çã«é¢ãã峿 ŒãªèŠä»¶ãå°å ¥ãããŸããç¹ã«ãæ°ããªã€ã³ã·ãã³ãå ±åèŠä»¶ã§ããSRPïŒSecurity Reporting ProcessïŒã¯2026幎9æã«æœè¡äºå®ã§ãããèªåè»ã¡ãŒã«ãŒã¯ä»ããæºåãé²ããå¿ èŠããããŸãã察å¿ãé ããã°ãèŠå¶éåã«ãã眰åã ãã§ãªãããµãã©ã€ãã§ãŒã³ã®æ··ä¹±ãEUåžå Žãžã®ã¢ã¯ã»ã¹åªå€±ãšãã£ããªã¹ã¯ã«ãçŽé¢ããããŸãããPlaxidityXã¯ãå®çžŸããèªåè»åããµã€ããŒã»ãã¥ãªãã£æè¡ãšå°éç¥èãéããŠãèªåè»ã¡ãŒã«ãŒãããã¢ã¯ãã£ããªè匱æ§ç®¡çãå®çŸããããã«ãµãã©ã€ãã§ãŒã³ã®å¯èŠå匷åãèŠå¶å¯Ÿå¿ã®è¿ éåã®å®æœã«å¯Ÿãæ¯æŽãããŠããŸãã
è¿å¹Žã欧å·ã®ãµã€ããŒã»ãã¥ãªãã£èŠå¶ã¯å€§ããé²åããŠãããããµã€ããŒã»ãã¥ãªãã£ã»ãã©ã€ã¢ãããšãåŒã¹ãæ°ããªèŠå¶äœç³»ã圢æããã€ã€ãããŸãããã®åœ±é¿ã¯ãèªåè»æ¥çã ãã«ãšã©ãŸããŸããã乳幌å ã®èŠå®ãã«ã¡ã©ãã¹ããŒããŠã©ãããšãã£ãIoTæ©åšãããã³ã³ãã¥ãŒã¿ãŒãããã«ã¯ãœãããŠã§ã¢å®çŸ©è»äž¡ïŒSDVïŒã«è³ããŸã§ãã»ãŒãã¹ãŠã®ããžã¿ã«è£œåã察象ãšãªããŸãã
ãã®èŠå¶ãã©ã€ã¢ããæ§æããã®ããCyber Resilience ActïŒCRAïŒãNetwork and Information Security Directive 2ïŒNIS2ïŒããããŠEU Cyber Security Act 2ïŒCSA2ïŒã®3ã€ã§ãããããã¯çžäºã«è£å®ãåããªãããå€å±€çãªé²åŸ¡äœå¶ãæ§ç¯ããããšãç®çãšããŠããŸããã€ã¡ãŒãžãšããŠã¯ã3ã€ã®åå¿åã§æ§æãããé²åŸ¡ã¢ãã«ãšèãããšåãããããã§ããããæãå åŽã®åã§ããCRAã¯è£œåãã®ãã®ã®ã»ãã¥ãªãã£ãæ ä¿ããäžéã®åã§ããNIS2ã¯äŒæ¥ã¬ãã«ã®ã»ãã¥ãªãã£ã匷åããŸãããããŠæãå€åŽã®åã§ããCSA2ã¯ããµãã©ã€ãã§ãŒã³å šäœãšå°æ¿åŠçãªãµã€ããŒæŠç¥ãæ¯ãã圹å²ãæãããŸãã
ãµã€ããŒã»ãã¥ãªãã£ã»ãã©ã€ã¢ãã¯èªåè»æ¥çã«ã©ã®ãããªåœ±é¿ãäžããã®ã
ãµã€ããŒã»ãã¥ãªãã£ã»ãã©ã€ã¢ããããããæå€§ã®å€åã¯ãèªåè»ãåç¬ã§æ©èœããæ©æ¢°è£œåãããèŠå¶å¯Ÿè±¡ãšãªãéèŠã€ã³ãã©ã®äžéšãžãšäœçœ®ä»ãçŽãããšã«ãããŸããNIS2ã®äžã§ã¯ãèªåè»æ¥çã¯æ£åŒã«ãEssentialïŒéèŠäºæ¥è ïŒããŸãã¯ãImportantïŒéèŠæ§ã®é«ãäºæ¥è ïŒããšããŠåé¡ãããŸããããã«ãããèªåè»ã¡ãŒã«ãŒãTier 1ãµãã©ã€ã€ãŒã¯æçµè£œåã§ããè»äž¡ã ãã§ãªããçç£ãšã³ã·ã¹ãã å šäœã®ãµã€ããŒã¬ãžãªãšã³ã¹ã«å¯ŸããŠæ³ç責任ãè² ãããšã«ãªããŸãã
äžæ¹ãCRAã¯è£œåã¬ãã«ã§ã®ã»ãã¥ãªãã£å¯Ÿå¿ã蚌æããããšãæ±ããŸããåECUãã³ãã¯ãã£ããã£ã¢ãžã¥ãŒã«ã«å¯ŸããŠSBOMïŒSoftware Bill of MaterialsïŒ ã®æŽåãæ±ãããããããã»ãã¥ã¢ã»ãã€ã»ãã¶ã€ã³ã®ååãå®éã«å®ãããŠãããã©ããããèŠå¶åœå±ã®ç£æ»ã«å¯Ÿå¿ã§ãã圢ã§èšŒæããªããã°ãªããŸããããããŠãæã倧ããªå€é©ãããããå¯èœæ§ãããã®ã¯CSA2ã§ããCSA2ã¯åŸæ¥ã®ãµã€ããŒã»ãã¥ãªãã£èŠå¶ã«å ããå°æ¿åŠçã»æŠç¥çãªèŠç¹ãå°å ¥ããŠããŸããå ·äœçã«ã¯ãèªåè»ãµãã©ã€ãã§ãŒã³å ã«ååšãã第äžåœã®ãé«ãªã¹ã¯ãµãã©ã€ã€ãŒïŒHigh-Risk SuppliersïŒããç¹å®ããå ±åãããšãšãã«ãå°æ¥çã«æé€ããããšãæ±ããããå¯èœæ§ããããŸãã
ãããŠãæåã®éèŠãªã³ã³ãã©ã€ã¢ã³ã¹æéã¯ç®åã«è¿«ã£ãŠããŸãã2026幎9æãŸã§ã«ãèªåè»ã¡ãŒã«ãŒããã³ãµãã©ã€ã€ãŒã®ã€ã³ã·ãã³ã察å¿ããŒã ã¯ãENISAïŒæ¬§å·é£åãµã€ããŒã»ãã¥ãªãã£æ©é¢ïŒãéå¶ããSingle Reporting PlatformïŒSRPïŒãšã®é£æºãå®äºããªããã°ãªããŸããããã®æ°ããªEUåºæºã§ã¯ãã³ãã¯ãããã«ãŒã®éçšç°å¢ã«ãããŠæªçšãããè匱æ§ã確èªãããå Žåã補é äºæ¥è ã¯24æé以å ã«å ±åãè¡ãããšãæ±ããããŸããSRPã¯ã補åå®å šã察象ãšããCRAãäŒæ¥ã¬ããã³ã¹ã察象ãšããNIS2ããããŠåœå®¶å®å šä¿éã®èгç¹ãå«ãCSA2ãæšªæçã«çµã³ä»ããçµ±äžå ±ååºç€ãšããŠæ©èœããŸãã
CSA2ã®è©³çŽ°è§£èª¬
EU Cybersecurity Act 2ïŒCSA2ïŒã¯ã2026幎1æ20æ¥ã«æ¬§å·å§å¡äŒãææ¡ããå æ¬çãªãµã€ããŒã»ãã¥ãªãã£é¢é£æ³æ¡ã§ãã2019幎ã«å¶å®ãããçŸè¡ã®EU Cybersecurity ActãæŽæ°ã»çœ®ãæããããšãç®çãšããŠãããåŸæ¥ã®ä»»æåå åã®ãèªèšŒã»ã©ããªã³ã°å¶åºŠãããããã匷å¶åã䌎ããæŠç¥çé²è¡ãã¬ãŒã ã¯ãŒã¯ããžã®è»¢æãå³ããã®ã§ãã
CSA2ã§ã¯ãICTïŒæ å ±éä¿¡æè¡ïŒãµãã©ã€ãã§ãŒã³ã®ã»ãã¥ãªãã£ã«é¢ããæ°ããªæ çµã¿ãå°å ¥ãããŸããç¹ã«ãå€åœæ¿åºã«ãã圱é¿åè¡äœ¿ãç¹å®åœãžã®äŸåãšãã£ããæè¡çãªè匱æ§ã ãã§ã¯æããããªãéæè¡çãªã¹ã¯ãžã®å¯Ÿå¿ãéèŠããŠããç¹ãç¹åŸŽã§ããäž»ãªå¯Ÿè±¡ãšãªãã®ã¯ããšãã«ã®ãŒãé茞ãéèãªã©ã®éèŠã€ã³ãã©åéã§ããèªåè»æ¥çã«ã€ããŠã¯ããèŒžéæ©åšè£œé ïŒManufacturing of Transport EquipmentïŒãã察象ç¯å²ãšããŠæç€ºãããŠãããèªåè»ã¡ãŒã«ãŒãäž»èŠãµãã©ã€ã€ãŒããã®åœ±é¿ãåããããšã«ãªããŸãã
CSA2ã¯ãEUã«ããããµã€ããŒã¬ãžãªãšã³ã¹ããµãã©ã€ãã§ãŒã³ã»ãã¥ãªãã£ãèªèšŒå¶åºŠã®å¯Ÿè±¡ç¯å²ãã補åãã®ãã®ã®æè¡çã»ãšã³ãžãã¢ãªã³ã°çãªèŠçŽ ãè¶ ããŠåºããŸãããã®ç®çã¯ããœãããŠã§ã¢ã®è匱æ§ã ãã§ã¯è©äŸ¡ã§ããªãå°æ¿åŠçãªã¹ã¯ããµãã©ã€ãã§ãŒã³äžã®äŸåé¢ä¿ãå«ãããä¿¡é Œã§ããICTãµãã©ã€ãã§ãŒã³ã®æ§ç¯ã§ããæ¬§å·å§å¡äŒã¯ä»åŸãEUã®æŠç¥çã€ã³ãã©ã«ãšã£ãŠéèŠãªICTã³ã³ããŒãã³ããç¹å®ããŠããäºå®ã§ãã察象ãšããŠã¯ã5Gã³ã¢ãããã¯ãŒã¯ãã¯ã©ãŠãã³ã³ãããŒã©ãŒããšãã«ã®ãŒã€ã³ããŒã¿ãŒãªã©ãäŸç€ºãããŠããŸãããŸãããšãã«ã®ãŒãå»çãé茞ãªã©ã®éèŠã»ã¯ã¿ãŒã§ã¯ããé«ãªã¹ã¯ãµãã©ã€ã€ãŒïŒHigh-Risk SuppliersïŒãã«åé¡ãããäŒæ¥ã®è£œåãã³ã³ããŒãã³ãã®å©çšãå¶éãŸãã¯çŠæ¢ãããå¯èœæ§ããããŸããæ¢åã€ã³ãã©ã«ã€ããŠããæå€§3幎éã®ç§»è¡æéå ã«æ®µéçãªæé€ã矩åä»ããããèŠèŸŒã¿ã§ãã
CSA2ã¯ã欧å·ãµã€ããŒã»ãã¥ãªãã£èªèšŒãã¬ãŒã ã¯ãŒã¯ïŒEuropean Cybersecurity Certification FrameworkïŒECCFïŒããECCF 2.0ããžãšé²åãããåãªãèªèšŒå¶åºŠã§ã¯ãªãã³ã³ãã©ã€ã¢ã³ã¹å¯Ÿå¿ã®ããã®å®åçãªæ çµã¿ãžãšå€åãããŸããç¹ã«æ³šç®ãã¹ãç¹ã¯ããããŸã§ã®ããã«åå¥è£œåã ããèªèšŒå¯Ÿè±¡ãšããã®ã§ã¯ãªããäŒæ¥å šäœã®ãµã€ããŒã»ãã¥ãªãã£æç床ãè©äŸ¡ã»èªèšŒã§ããããã«ãªãããšã§ããCSA2èªèšŒãååŸããäŒæ¥ã«ã¯ãNIS2ããã³CRAãžã®é©åã瀺ãäžã§æ³çãªãã»ãŒãããŒããŒããšããŠæ©èœããã¡ãªãããäžããããäºå®ã§ãã
CSA2ã®äžã§ãENISAïŒæ¬§å·é£åãµã€ããŒã»ãã¥ãªãã£æ©é¢ïŒã¯ããµã€ããŒã»ãã¥ãªãã£ã»ãã©ã€ã¢ãå šäœãæ¯ãããéçšé¢ã§ã®çµ±æ¬æ©é¢ããšããŠã®åœ¹å²ãæ ããŸããå ·äœçã«ã¯ãCRAãNIS2ãCSA2ã«é¢é£ãããã¹ãŠã®ã€ã³ã·ãã³ãå ±åãåãä»ããçµ±äžããŒã¿ã«ãéå¶ãããšãšãã«ãå€§èŠæš¡ãªè¶å¢ãµã€ããŒè åšãçºçããéã«ã¯EUå šåãžã®èŠåçºä¿¡ãè¡ããŸãããŸããæ°éã»ã¯ã¿ãŒã®å°éå®¶ã§æ§æããããCybersecurity Reserveãã®èª¿æŽãéå¶ãæ ãã»ããEUã¬ãã«ã§çµ±äžãããè匱æ§ããŒã¿ããŒã¹ããã³è匱æ§ç®¡çãµãŒãã¹ãæäŸããäºå®ã§ãã
CRAã»NIS2ã»CSA2ã¯ã©ã®ããã«é£æºããã®ã
| èŠå¶ | äž»ãªå¯Ÿè±¡é å | 解決ããããšããåã |
| CRAïŒè£œåãšã³ãžãã¢ãªã³ã°èŠä»¶ïŒ | ããŒããŠã§ã¢ã»ãœãããŠã§ã¢è£œå | ãã®ããžã¿ã«è£œåã¯å®å šã«èšèšã»éçºãããŠãããïŒ |
| NIS2ïŒäŒæ¥ã¬ããã³ã¹èŠä»¶ïŒ | éèŠãªãµãŒãã¹ãæäŸããŠããäŒæ¥ | ãã®äŒæ¥ã¯ãµã€ããŒæ»æã«å¯ŸããŠååãªã¬ãžãªãšã³ã¹ãåããŠãããïŒ |
| CSA2ïŒæŠç¥ã»å°æ¿åŠçèŠä»¶ïŒ | èªèšŒãšãµãã©ã€ãã§ãŒã³ã®ä¿¡é Œæ§ | ãµãã©ã€ãã§ãŒã³ã«ååšãããã³ããŒããµãã©ã€ã€ãŒãä¿¡é Œã§ãããïŒ |
3ã€ã®èŠå¶ãã©ã®ããã«é£æºããŠæ©èœããã®ããçè§£ããããã«ãç©æµäŒæ¥åãã«è²©å£²ãããã³ãã¯ãããã«ãŒãäŸã«èããŠã¿ãŸãããã
ã¹ããã1ïŒCRA
ãŸããèªåè»ã¡ãŒã«ãŒã¯ãè»äž¡ã®ãœãããŠã§ã¢ããã»ãã¥ã¢ã»ãã€ã»ãã¶ã€ã³ãã®ååã«åºã¥ããŠéçºãããŠããããšã蚌æããªããã°ãªããŸããããã®ããã«ãSBOMãæŽåãããšãšãã«ãEUåžå Žã§ã®è²©å£²ã«å¿ èŠãªCEããŒãã³ã°ãååŸããŸããããã«ãäžå ·åãçºèŠãããå Žåã«ã¯ãCRAã§å®ãããã24æé以å ã®å ±åèŠä»¶ã«åŸããéããã«åœå±ãžå ±åããå¿ èŠããããŸãã
ã¹ããã2ïŒNIS2
次ã«ããã®è»äž¡ãè³Œå ¥ããç©æµäŒæ¥ã¯ãNIS2ã®äžã§ãImportant EntityïŒéèŠäºæ¥è ïŒãã«åé¡ãããŸãããã®å ŽåãäŒæ¥ã¯èªç€Ÿã®æ¥åãããã¯ãŒã¯ãéçšç°å¢ãååã«ä¿è·ãããŠããããšã蚌æããªããã°ãªããŸãããèªåè»ã¡ãŒã«ãŒãæäŸããã»ãã¥ãªãã£ææžã¯ãNIS2ãªã¹ã¯ãããžã¡ã³ãç£æ»ã«ãããŠéèŠãªèšŒè·¡ãšããŠæŽ»çšãããŸãã
ã¹ããã3ïŒCSA2
ããã«ãEUå§å¡äŒãè»äž¡ã«æèŒãããç¹å®ã®5Gãããããé«ãªã¹ã¯ãµãã©ã€ã€ãŒïŒHigh-Risk SupplierïŒãç±æ¥ã®ã³ã³ããŒãã³ãã§ãããšå€æãããšããŸãããã®å ŽåãEUã®æŠç¥çèªåŸæ§ã確ä¿ãããããCSA2ã«åºã¥ããOEMã¯åœè©²ãããã®å©çšã36ãæä»¥å ã«ä»£æ¿ãœãªã¥ãŒã·ã§ã³ãžç§»è¡ããããšãæ±ããããŸãã
ãŸããªãå§åãããSingle Reporting PlatformïŒSRPïŒã
ãããŸã§äŒæ¥ã¯ããµã€ããŒã»ãã¥ãªãã£ã€ã³ã·ãã³ããçºçããéãè€æ°ã®åœã®åœå±ãæ©é¢ãžåå¥ã«å ±åããªããã°ãªããã倧ããªäºåè² æ ãæ±ããŠããŸããããããã課é¡ãè§£æ¶ãããããEUã¯2026幎ã«Single Reporting PlatformïŒSRPïŒãå°å ¥ããŸãããENISAãéå¶ãããã®ãã©ãããã©ãŒã ã«ããã補é äºæ¥è ã¯æªçšãããè匱æ§ãé倧ãªã»ãã¥ãªãã£ã€ã³ã·ãã³ãã«ã€ããŠãäžåºŠå ±åããã ãã§æžãããã«ãªããŸããæåºãããæ å ±ã¯ããã®åŸãèªåçã«é¢ä¿ããååœåœå±ãžæ¯ãåããããŸãã
2026幎9æ11æ¥ä»¥éãSRPã¯CRAãNIS2ãCSA2ã®3ã€ã®èŠå¶ãã¹ãŠã«å¯Ÿå¿ããçµ±äžå ±åçªå£ãšããŠæ©èœããŸããäŸãã°ãããã»ãã¥ãªãã£ã€ã³ã·ãã³ãã補åã®è匱æ§ã«èµ·å ãïŒCRAã®å¯Ÿè±¡ïŒãããã«äŒæ¥ãæäŸããéèŠãµãŒãã¹ã«ã圱é¿ãäžããå ŽåïŒNIS2ã®å¯Ÿè±¡ïŒãäŒæ¥ã¯SRPäžã§1åã®å ±åãè¡ãã ãã§æžã¿ãŸããSRPã¯æåºãããæ å ±ãèªåçã«åé¡ããããããé©åãªæ©é¢ãžè»¢éããŸãã補åã®è匱æ§ã«é¢ããæ å ±ã¯ã該åœããååœCSIRTïŒComputer Security Incident Response TeamïŒãžéä¿¡ããããµãŒãã¹ãäºæ¥éå¶ãžã®åœ±é¿ã«é¢ããæ å ±ã¯ãNIS2ã®äž»ç®¡åœå±ãžéä¿¡ãããŸãã
ãµã€ããŒã»ãã¥ãªãã£ã»ãã©ã€ã¢ãã®äžã§ã¯ãã24/72/1ãã®å ±åãµã€ã¯ã«ãæ°ããªæšæºãšãªãã€ã€ãããŸãïŒè©³çްã¯åŸè¿°ã®è¡šãåç §ïŒãCRAã§ã¯ãè匱æ§ãæ»æã®æªçšãèªèããæç¹ããå ±åæéã®ã«ãŠã³ãããŠã³ãå§ãŸããŸãã
| å ±åæé | CRA | NIS2 | CSA2 |
| 24æé以å | åæèŠåïŒEarly WarningïŒïŒæªçšã確èªãããè匱æ§ãå ±å | åæèŠåïŒEarly WarningïŒïŒäºæ¥éå¶ã«åœ±é¿ãäžããé倧ã€ã³ã·ãã³ããå ±å | åæèŠåïŒEarly WarningïŒïŒäŸµå®³ã«é«ãªã¹ã¯ãµãã©ã€ã€ãŒç±æ¥ã®ã³ã³ããŒãã³ããé¢äžããŠããå Žåã«å ±å |
| 72æé以å | è©³çŽ°å ±åïŒDetailed ReportïŒïŒæè¡ç圱é¿ããªã¹ã¯ã«é¢ããåæè©äŸ¡ãæåº | ã€ã³ã·ãã³ãéç¥ïŒIncident NotificationïŒïŒæ·±å»åºŠè©äŸ¡ãè¶å¢ç圱é¿ãå«ã詳现æ å ±ãæåº | ãµãã©ã€ãã§ãŒã³èŠåïŒSupply Chain AlertïŒïŒãéèŠICTè³ç£ããžã®åœ±é¿è©äŸ¡ãæåº |
| 14æ¥ä»¥å ïŒ1ãæä»¥å | æçµå ±åïŒFinal ReportïŒïŒæ ¹æ¬åå åæããã³ä¿®æ£ãããæäŸç¶æ³ãå ±åïŒ14æ¥ä»¥å ïŒ | æçµå ±åïŒFinal ReportïŒïŒå®å šãªäºåŸåæããã³åŸ©æ§ç¶æ³ãå ±åïŒ1ãæä»¥å ïŒ | æ¯æ£æªçœ®å ±åïŒMitigation ReportïŒïŒåœ±é¿ãåããé«ãªã¹ã¯ã³ã³ããŒãã³ãã®ä»£æ¿ã»æé€èšç»ãå ±å |
èŠå¶éåã®ä»£åã¯éåžžã«å€§ãã
CRAãNIS2ãCSA2ã§å®ããããŠããå¶è£éã¯ãããããç¬ç«ããŠé©çšãããã ãã§ãªããçžäºã«éãªãåãå¯èœæ§ããããŸãããšããã®ããåäžã®ãµã€ããŒã»ãã¥ãªãã£ã€ã³ã·ãã³ãããåæã«ã補åãïŒCRAïŒããäºæ¥äœã»çµç¹ãïŒNIS2ïŒãããµãã©ã€ãã§ãŒã³ãïŒCSA2ïŒã®3ã€ã®èгç¹ã§èŠå¶éåã«è©²åœããã±ãŒã¹ãæ³å®ãããããã§ãããã®çµæãäŒæ¥ã¯çµç¹ã®ç°ãªãã¬ãã«ã«å¯ŸããŠè€æ°ã®å¶è£æªçœ®ãåãããããã°ãè€åçãªããã«ãã£ãã«çŽé¢ããå¯èœæ§ããããŸãã
EUã«ã¯äžè¬çã«ãåãéåè¡çºã«å¯ŸããŠäºéã«åŠçœ°ãããªãããšããæ³ååãååšããŸããããããCRAãNIS2ãCSA2ã¯ããããç°ãªãæ³ç矩åãšèŠå¶ç®çãæã£ãŠããŸãããã®ãããåäžã®ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã§ãã£ãŠããèŠå¶åœå±ã¯ç°ãªãæ³ç芳ç¹ããéåãèªå®ããããããã«å¯ŸããŠå¶è£æªçœ®ãç§ãããšãå¯èœã§ãã2026幎çŸåšãå çåœã®èŠå¶åœå±éã§é£æºäœå¶ãæŽåãããŠãããäžè¬çã«ãæ¯äŸååãã«åºã¥ããŠå¶è£ã倿ããè€æ°ã®èŠå¶éåãèªããããå Žåã§ããæãé«é¡ãªå¶è£äžéãæã€èŠå¶ãäžå¿ã«å·è¡ããåŸåããããŸãã
以äžã§ã¯ãCRAãNIS2ãCSA2ããããã®å¶è£ã¡ã«ããºã ãšãäŒæ¥ã«ã©ã®ãããªåœ±é¿ãäžããã®ãã詳ããèŠãŠãããŸãã
| èŠå¶ | å¶è£éã®äžé | äž»ãªéåå 容 |
| CRA | 1,500äžãŠãŒããŸãã¯å šäžç幎é売äžé«ã®2.5%ã®ããããé«ãæ¹ | ãè匱æ§ãå«ã補åãåžå Žã«æå ¥ããé©åãªä¿®æ£å¯Ÿå¿ãè¡ããªãã£ãã |
| NIS2 | 1,000äžãŠãŒããŸãã¯å šäžç幎é売äžé«ã®2%ã®ããããé«ãæ¹ | ãäžååãªã¬ããã³ã¹ããªã¹ã¯ç®¡çäœå¶ã«ãã£ãŠã€ã³ã·ãã³ãã®çºçãèš±ããã |
| CSA2 | å šäžç幎é売äžé«ã®7%ïŒ2026å¹Žæ³æ¡ããŒã¹ïŒ | ãé«ãªã¹ã¯ãµãã©ã€ã€ãŒã«å¯ŸããèŠå¶ã䜿çšçŠæ¢æªçœ®ãç¡èŠããã |
çµå¶å±€ã«åã¶ãããŒãã«ãŒã ã»ããã«ãã£ã
CRAãNIS2ãCSA2ã®3ã€ã®èŠå¶ã¯æçµçã«äŒæ¥ã®çµå¶å±€ã«åœ±é¿ããŸããç¹ã«NIS2ã§ã¯ããµã€ããŒã»ãã¥ãªãã£ã«é¢ããé倧ãªé倱ãèªããããå ŽåãCEOãåç· åœ¹äŒã¡ã³ããŒãªã©ã®äžçŽç®¡çè·ãå人ãšããŠè²¬ä»»ãåãããå¯èœæ§ããããŸããäŸãã°ãäŒæ¥ãæ¢ç¥ã®è£œåè匱æ§ãæŸçœ®ããå ŽåïŒCRAéåïŒãã䜿çšãçŠæ¢ãããé«ãªã¹ã¯ãµãã©ã€ã€ãŒã®è£œåãæå³çã«å©çšããå ŽåïŒCSA2éåïŒãååœåœå±ã¯çµå¶é£ã«å¯Ÿããäžå®æéã«ãããçµå¶è·ãžã®å°±ä»»ãçŠæ¢ããæªçœ®ãè¬ããããšãã§ããŸããããã«NIS2ã§ã¯ãçµå¶å±€ã«å¯Ÿããèªå®ããããµã€ããŒã»ãã¥ãªãã£ç ä¿®ãåè¬ãããã®ç¥èãšçè§£ã蚌æããããšãæ±ããŠããŸãããã®çŸ©åã¯å®éã®ã€ã³ã·ãã³ãçºçã®æç¡ãšã¯ç¡é¢ä¿ã§ãå¿ èŠãªæè²ãç ä¿®ãåè¬ããŠããªãå Žåãããã ãã§NIS2éåãšå€æãããå¯èœæ§ããããŸãã
åžå Žã¢ã¯ã»ã¹ãäºæ¥ç¶ç¶ã«é¢ããéééçããã«ãã£
EUã®ãµã€ããŒã»ãã¥ãªãã£èŠå¶ã«ããããªã¹ã¯ã¯ãå¶è£éã ãã§ã¯ãããŸãããèªåè»æ¥çã§ã¯UN R155ã«åºã¥ãååŒèªèšŒãåžå Žåå ¥ã®åæãšãªã£ãŠããŸãããCRAã®é©çšå¯Ÿè±¡ãšãªã補åã«ã€ããŠããã³ã³ãã©ã€ã¢ã³ã¹èŠä»¶ãæºãããªãå Žåã«ã¯EUåžå Žãžã®ã¢ã¯ã»ã¹ãã®ãã®ã倱ãå¯èœæ§ããããŸããäŸãã°ãèŠå¶ã«é©åããŠããªã補åã«ã€ããŠã¯ãEUå çåœå šåã§ã®ãªã³ãŒã«ãåœããããå¯èœæ§ããããŸãããŸããé«ãªã¹ã¯ãµãã©ã€ã€ãŒèŠå¶ãžã®éåãèªå®ãããäŒæ¥ã¯ãEUå ç27ãåœã«ãããæ¿åºé¢é£å¥çŽãžã®åå è³æ Œãæä¹ çã«å€±ãå¯èœæ§ããããŸãã
ããã«æ³šæãã¹ããªã®ã¯ã1ã€ã®èŠå¶éåãä»ã®èŠå¶ã«ãæ³¢åããå¯èœæ§ãããããšã§ããäŸãã°ãCSA2ã«åºã¥ããµã€ããŒã»ãã¥ãªãã£èªèšŒã倱ã£ãå Žåããã®çµæãšããŠNIS2äžã§ããã³ã³ãã©ã€ã¢ã³ã¹äžé©åããšèŠãªãããä¿éºãžã®å å ¥ãå°é£ã«ãªãããEssential EntityïŒéèŠäºæ¥è ïŒããžã®ãµãŒãã¹æäŸãæ³çã«å¶éãããããšã«ãã€ãªãããŸãã
ãããããªã¹ã¯ã軜æžããæã广çãªæ¹æ³ã¯ãåé¡çºçåŸã«å¯Ÿå¿ããã®ã§ã¯ãªãããããããèŠå¶ãžã®é©åæ§ã蚌æããŠããããšã§ãããã®ä»£è¡šäŸããCSA2ã«ããããCyber Posture CertificateïŒãµã€ããŒãã¹ãã£èªèšŒïŒãã§ãããã®èªèšŒã¯ååŸã矩åä»ããããŠããããã§ã¯ãããŸããããèªåè»ã¡ãŒã«ãŒã«ãšã£ãŠã¯èŠå¶å¯Ÿå¿ãè£ä»ãã匷åãªèšŒæ ãšãªããæ³çãªã¹ã¯ã軜æžãããçŸããšããŠæ©èœããŸããèªèšŒãååŸããããã«ã¯ãèªå®ããã第äžè è©äŸ¡æ©é¢ïŒConformity Assessment BodyïŒCABïŒã«ããå æ¬çãªè©äŸ¡ãåãããµã€ããŒã»ãã¥ãªãã£äœå¶ãéçšããã»ã¹ãé©åã§ããããšã蚌æããªããã°ãªããŸããã
OEMãä»ããåãçµãã¹ãã¢ã¯ã·ã§ã³ãã©ã³
2026幎9æ11æ¥ãŸã§ã®ã«ãŠã³ãããŠã³ã¯ããã¯ããæ°å¹Žå ãã®è©±ã§ã¯ãããŸãããæ®ãããæéã¯ãæ°é±éåäœã§èããã¹ã段éã«å ¥ã£ãŠããŸããèªåè»ã¡ãŒã«ãŒã«ãšã£ãŠãCRAã®æ¬æ Œé©çšãå§ãŸã2027幎ãŸã§å¯Ÿå¿ãå éãããããšã¯ã極ããŠãªã¹ã¯ã®é«ã倿ãšèšããã§ããããäŸãã°ã2026幎9æ12æ¥ã«åžå Žã§éçšäžã®è»äž¡çŸ€ã«ãããŠãå®éã«æªçšãããŠããè匱æ§ãçºèŠãããå Žåããã®ç¬éãã24æé以å ã®å ±å矩åãçºçããŸããé©åãªå ±åãè¡ããªããã°ãå šäžç幎é売äžé«ã®2.5ïŒ ã«çžåœããå¶è£éã®å¯Ÿè±¡ãšãªãå¯èœæ§ããããŸããããããå¿ èŠãªããã»ã¹ãã·ã¹ãã ãæ§ç¯ãããã¹ããè¡ããçµç¹å šäœãžå®çãããããšã¯äžæäžå€ã§ã¯å®çŸã§ããŸãããã ãããããä»ããè¡åãéå§ããããšãéèŠã§ãã
åžå Žã¢ã¯ã»ã¹ãç¶æããçµå¶å±€ã®å人責任ãªã¹ã¯ãåé¿ããããã«ããèªåè»ã¡ãŒã«ãŒã¯ä»¥äžã®3ã€ã®åªå æœçã«çŽã¡ã«çæããããšãåŒ·ãæšå¥šããŸãã
1. ã24æé察å¿ãã€ãã©ã€ã³ããæ§ç¯ãã
ãšã³ãžãã¢ãªã³ã°éšéã®äžå ·å管çã·ã¹ãã ãšãèŠå¶å¯Ÿå¿ã»å ±åéšéãšã®éã«ååšããã®ã£ãããè§£æ¶ããå¿ èŠããããŸããè匱æ§ãæ»æã®æªçšãæ€ç¥ãããå Žåãèªåçã«ãšã¹ã«ã¬ãŒã·ã§ã³ãããSRPãž24æé以å ã«å ±åã§ããä»çµã¿ãæ§ç¯ããªããã°ãªããŸããã
2. SBOMãæŽ»çšããŠå°æ¿åŠçãªã¹ã¯ãå¯èŠåãã
è»äž¡ã®ã³ãã¯ãã£ããã£æ©èœãèªåé転ã·ã¹ãã ã«é¢é£ãããã¹ãŠã®SBOMã察象ã«ãæ©æ¥ãªç£æ»ã宿œããå¿ èŠããããŸããç¹ã«éèŠãªã®ã¯ãé«ãªã¹ã¯ãšèŠãªãããå€åœãã³ããŒã«ç±æ¥ãããœãããŠã§ã¢ã³ã³ããŒãã³ããäŸåé¢ä¿ãææ¡ããããšã§ããããããå¯èŠåãè¡ãããšã§åããŠãCSA2ã§æ±ãããã36ãæä»¥å ã®æ®µéçãªçœ®ãæãèšç»ãçå®ã§ããããã«ãªããŸãã
3. ååçãªç£èŠãããªã¢ã«ã¿ã€ã é²åŸ¡ãžç§»è¡ãã
åŸæ¥åã®ãã°åéãäºåŸåæã ãã§ã¯ããã»ãã¥ã¢ã»ãã€ã»ãã¶ã€ã³ãã®ç£æ»èŠä»¶ãæ¹ãã鲿¢èŠä»¶ãæºããããšã¯å°é£ã«ãªãã€ã€ãããŸããããããã®è»äž¡ã«ã¯ãç°åžžãªãããã¯ãŒã¯éä¿¡ãäžæ£ãªã³ãã³ãããšããžåŽã§ãªã¢ã«ã¿ã€ã ã«æ€ç¥ã»é®æããèœåãæ±ããããŸãã
PlaxidityXãã³ã³ãã©ã€ã¢ã³ã¹å¯Ÿå¿ãæ¯æŽ
EUã®æ°ããªãµã€ããŒã»ãã¥ãªãã£ã»ãã©ã€ã¢ããžã®å¯Ÿå¿ã«ã¯ãèªåè»æ¥çç¬èªã®ç¥èŠãšãéç£ç°å¢ã§éçšå¯èœãªå®è·µçãœãªã¥ãŒã·ã§ã³ã®äž¡æ¹ãæ±ããããŸããPlaxidityXã¯ãè»èŒç£èŠãšã¯ã©ãŠãããŒã¹ã®é«åºŠãªåææ©èœãçµ±åããVehicle Detection & ResponseïŒVDRïŒãã©ãããã©ãŒã ãéããŠãOEMã®èŠå¶å¯Ÿå¿ãæ¯æŽããŠããŸãã
è»èŒã»ã³ãµãŒã¯ãè»äž¡å éšã®éä¿¡ãã©ãã£ãã¯ãã·ã¹ãã ã³ãŒã«ããªã¢ã«ã¿ã€ã ã§ç£èŠããAIããŒã¹ã®è åšã¢ãã«ã«ãã£ãŠèª€æ€ç¥ïŒãã€ãºïŒãæå¶ããªããè åšãæ€åºããŸããããã«ãããè»äž¡ããã¯ã©ãŠããŸã§ã®ãšã³ãããŒãšã³ããªå¯èŠåãå®çŸããæ£ç¢ºãã€è¿ éãªã€ã³ã·ãã³ãå ±åãå¯èœã«ããŸããããã«ãèªååãããTARAïŒè åšåæãšãªã¹ã¯è©äŸ¡ïŒãSSCSïŒSoftware Supply Chain SecurityïŒæ©èœã«ãããOEMã¯ãµãŒãããŒãã£è£œã³ã³ããŒãã³ãã«æœããªã¹ã¯ãæ©æã«ç¹å®ããè匱æ§ã管çããããšã§ãèšè𿮵éããã»ãã¥ãªãã£ãçµã¿èŸŒãããšãã§ããŸãã
EUã®æ°ããªèŠå¶èŠä»¶ããèªç€Ÿã«ãšã£ãŠå®è¡å¯èœãªã¢ã¯ã·ã§ã³ãã©ã³ãžèœãšãèŸŒãæ¹æ³ããæ¢ãã§ãããPlaxidityXã®å°éããŒã ããçŸåšã®ãµã€ããŒã»ãã¥ãªãã£äœå¶ã®è©äŸ¡ãããSRP察å¿ã«åããããŒããããçå®ãŸã§ãæ¯æŽããŸãã2026幎9æã®SRPéçšéå§ã«åããŠãä»ããæºåãå§ããŸãããã
å·çïŒ2026幎06æ04æ¥