La UE presentó una nueva Caja de Herramientas de Seguridad de la Cadena de Suministro de TIC, que proporciona un enfoque de la UE para identificar, evaluar y mitigar los riesgos de ciberseguridad en las cadenas de suministro de TIC
https://administracionelectronica.gob.es/pae_Home/pae_Actualidad/pae_Noticias/2026/Febrero/noticia-2026-02-16-UE-herramientas-seguridad-cadena-suministro-TIC.html
Alcance:
For the purpose of the ICT Supply Chain Security Toolbox, the subject matter of the risk assessments are ICT services, ICT systems or ICT products supply chains,
encompassing hardware, software including free and open-source software (FOSS) ...
The CRA will play a key role in securing ICT supply chains by:
... Providing a light-touch regulatory regime on the FOSS and the so-called open-
source software stewards.
ICT supply chain and Supply chain entities:
.. (e.g. microchip manufacturers, open-source libraries, or third-country
subcontractors).
A resilient, trusted, and transparent industrial base
Promote the security and visibility of open-source software and hardware, particularly where this could help secure the supply chain of critical entities, and promote the adoption of secure open-source alternatives, for instance by
▪ open-sourcing existing public sector solutions,
▪ through the creation of open-source programme offices, and
▪ diversifying digital internet infrastructures, such as code
repositories or encryption certificate authorities
#LeyDeCiberseguridad #CRA #SupplyChain #CadenaDeSuministro #NIS2 #ENISA