Recitals
(1) Cybersecurity is one of the biggest challenges facing the Union. The number and variety of connected devices will increase exponentially in the coming years. Cyber-attacks are an issue of public interest, as they have a critical impact not only on the Union’s economy, but also on democracy and the safety and health of consumers. It is therefore necessary to strengthen the Union’s approach to cybersecurity, to address cyber resilience at Union level and to improve the functioning of the internal market by establishing a uniform legal framework for essential cybersecurity requirements for the placing of products with digital elements on the Union market. This should address two major problems that impose high costs on users and society: a low level of cybersecurity of products with digital elements, which is reflected in widespread vulnerabilities and the insufficient and inconsistent provision of security updates to address them, and a lack of understanding and access to information by users, which prevents them from choosing or safely using products with adequate cybersecurity features.
(2) This Regulation aims to create the framework conditions for the development of secure products with digital elements, so that hardware and software products with fewer vulnerabilities are placed on the market and so that manufacturers consistently take care of security throughout the entire life cycle of a product. It also aims to create conditions that enable users to take cybersecurity into account when choosing and using products with digital elements, for example by increasing transparency regarding the support period for products with digital elements made available on the market.
(3) Existing relevant Union law includes several horizontal provisions regulating certain aspects of cybersecurity from different angles, including measures to enhance the security of the digital supply chain. However, existing Union law on cybersecurity, including Regulation (EU) 2019/881 of the European Parliament and of the Council (3) and Directive (EU) 2022/2555 of the European Parliament and of the Council (4), does not contain directly binding requirements on the security of products with digital elements.
(4) While existing Union law applies to certain products with digital elements, there is no horizontal Union legal framework that would establish comprehensive cybersecurity requirements for all products with digital elements. The various rules adopted and initiatives taken so far at Union and national level only partially address the identified problems and risks related to cybersecurity, creating a legislative patchwork within the internal market that leads to greater legal uncertainty for both producers and users of such products and to a greater unnecessary burden on businesses and organizations that have to comply with a number of different requirements and obligations in relation to similar types of products. The cybersecurity of these products has a particularly strong cross-border dimension because products with digital elements manufactured in a Member State or in a third country are often used by organizations and consumers throughout the internal market. This makes it necessary to regulate the sector at Union level in order to ensure a harmonized legal framework and legal certainty for users, organizations and businesses, including micro, small and medium-sized enterprises as defined in the Annex to Commission Recommendation 2003/361/EC (5). The Union regulatory environment should be harmonized through the introduction of horizontal cybersecurity requirements for products with digital elements. It is also necessary to ensure legal certainty for economic operators and users across the Union and better harmonization of the internal market and proportionality for micro, small and medium-sized enterprises, which would also create better conditions for economic operators wishing to enter that market.
(5) As regards micro, small and medium-sized enterprises, the provisions of the Annex to Recommendation 2003/361/EC should be applied in full when determining the category into which an enterprise falls. Therefore, the provisions of Article 6 of the Annex to Recommendation 2003/361/EC on the compilation of the data of an enterprise with regard to certain types of enterprises, such as partner enterprises or linked enterprises, should also be applied when calculating the number of employees and the financial thresholds for determining the types of enterprises.
(6) The Commission should provide guidance to assist economic operators, in particular micro, small and medium-sized enterprises, in the application of this Regulation. Those guidelines should cover, inter alia, the scope of this Regulation, in particular remote data processing and its impact on developers of free and open source software, the application of the criteria for establishing support periods for products with digital elements, the interaction between this Regulation and other Union legislation, and what constitutes a substantial modification.
(7) At Union level, various programmatic and policy documents, such as the joint communication of the Commission and the High Representative of the Union for Foreign Affairs and Security Policy of 16 December 2020 entitled “The EU Cybersecurity Strategy for the Digital Decade”, the Council conclusions on the cybersecurity of connected devices of 2 December 2020 and the Council conclusions on the development of the European Union’s cyber defense of 23 May 2022 and the European Parliament resolution of 10 June 2021 on the EU Cybersecurity Strategy for the Digital Decade (6 June 2021), have been published. The Council conclusions of 23 December 2020 and the Council conclusions on the development of the European Union’s cyber defense of 23 May 2022 and the European Parliament resolution of 10 June 2021 on the EU Cybersecurity Strategy for the Digital Decade (6) called for specific Union cybersecurity requirements for digital or connected products; at the same time, several third countries have taken measures to address this issue on their own initiative. In the final report of the Conference on the Future of Europe, citizens called for “a stronger role for the EU in countering cybersecurity threats”. In order for the Union to play a leading role internationally in the field of cybersecurity, it is important to create an ambitious legal framework.
(8) In order to increase the overall level of cybersecurity of all products with digital elements placed on the internal market, objective and technology-neutral basic cybersecurity requirements must be introduced for these products, which should then apply horizontally.
(9) All products with digital elements that are integrated into or connected to a larger electronic information system can, under certain circumstances, serve as an attack vector for malicious actors. Consequently, even hardware and software that is considered less critical can facilitate an initial compromise of a device or network and allow malicious actors to gain privileged access to a system or move across systems. Manufacturers should therefore ensure that all products with digital elements are designed and developed in accordance with the essential cybersecurity requirements set out in this Regulation. The obligation applies both to products that can be physically connected via hardware interfaces and to products that are logically connected, e.g. via network sockets, pipes, files, application programming interfaces or other types of software interfaces. Since cyber threats can spread through different products with digital elements before reaching a specific target, e.g. by chaining several exploitable vulnerabilities, manufacturers should also ensure the cyber security of those products with digital elements that are only indirectly connected to other devices or networks.
(10) The establishment of cybersecurity requirements for the placing on the market of products with digital elements is intended to improve the cybersecurity of these products for both consumers and businesses. These requirements will also ensure that cybersecurity is taken into account throughout the supply chain, making end products with digital elements and their components more secure. This also concerns requirements for the placing on the market of consumer products with digital elements intended for vulnerable consumers, such as toys and baby monitor systems. The consumer products with digital elements that are classified as essential products with digital elements in this Regulation are subject to a higher cybersecurity risk, as their functions pose a significant risk of adverse effects in terms of their scope and their potential harm to the health, safety or integrity of users of such products, and should be subject to a more stringent conformity assessment procedure. This applies to products such as smart household appliances with security functions, including smart door locks, baby monitors and alarms, connected toys and wearable medical devices. In addition, the more stringent conformity assessment procedures to which other products with digital elements that are classified as essential or critical products with digital elements in this Regulation must be subject will help to prevent any negative impact on consumers that could result from the exploitation of vulnerabilities.
(11) This Regulation aims to ensure a high level of cybersecurity of products with digital elements and their embedded remote computing solutions. Such remote computing solutions should be defined as remote data processing for which software is designed and developed by the manufacturer of the device with digital elements itself or under its responsibility and without which the device with digital elements could not perform any of its functions. This ensures that such products are adequately secured in their entirety by their manufacturers, regardless of whether the data is processed or stored locally on the user’s device or remotely by the manufacturer. At the same time, remote processing or storage falls within the scope of this Regulation only to the extent that it is necessary for a product with digital elements to perform its functions. Such remote processing or storage occurs when a mobile application requires access to an application programming interface or to a database provided by a service developed by the manufacturer. In this case, the service falls within the scope of this Regulation as a remote data processing solution. The requirements for remote computing solutions falling within the scope of this Regulation shall therefore not include technical, operational or organizational measures to manage the risks to the security of the manufacturer’s network and information systems as a whole.
(12) Cloud solutions shall only be considered as remote data processing solutions within the meaning of this Regulation if they comply with the definition laid down in this Regulation. For example, cloud functionalities offered by the manufacturer of smart household appliances that allow users to control the appliance remotely fall within the scope of this Regulation. In contrast, websites that do not support the functionality of a product with digital elements or cloud services designed and developed outside the responsibility of a manufacturer of a product with digital elements do not fall within the scope of this Regulation. Directive (EU) 2022/2555 applies to cloud computing services and cloud service models such as SaaS (Software as a Service), PaaS (Platform as a Service) or IaaS (Infrastructure as a Service). The entities providing cloud computing services in the Union that qualify as medium-sized enterprises in accordance with Article 2 of the Annex to Recommendation 2003/361/EC or that exceed the thresholds for medium-sized enterprises set out in paragraph 1 of that Article fall within the scope of that Directive.
(13) In line with the objective of this Regulation to remove barriers to the free movement of products incorporating digital elements, Member States should not impede the making available on the market of products incorporating digital elements that comply with this Regulation in the aspects covered by this Regulation. In the areas harmonized by this Regulation, Member States may therefore not impose additional cybersecurity requirements for the making available on the market of products with digital elements. However, any public or private entity may, in addition to the requirements laid down in this Regulation, impose additional requirements for the procurement or use of products with digital elements for its specific purposes and may therefore choose to use products with digital elements that comply with more stringent or more specific cybersecurity requirements than those applicable to the making available on the market under this Regulation. Without prejudice to Directives 2014/24/EU (7) and 2014/25/EU (8) of the European Parliament and of the Council, when procuring products with digital elements that are required to comply with the essential cybersecurity requirements set out in this Regulation, including those for managing security risks, Member States should ensure that those requirements are taken into account in the procurement process and that the ability of manufacturers to effectively apply cybersecurity measures and to manage cyber threats is also considered. In addition, Directive (EU) 2022/2555 sets out cybersecurity risk management measures for the essential and important entities referred to in Article 3 of that Directive, which could include supply chain security measures that require those entities to use products with digital elements that meet more stringent cybersecurity requirements than those set out in this Regulation. In accordance with Directive (EU) 2022/2555 and its principle of minimum harmonization, Member States may therefore lay down additional cybersecurity requirements for the use of information and communication technology (ICT) products by essential or critical entities in accordance with that Directive in order to ensure a higher level of cybersecurity, provided that those requirements are consistent with the obligations of Member States laid down in Union law. Aspects not covered by this Regulation may also include non-technical factors related to products with digital elements and their manufacturers. Member States may therefore lay down national measures, including restrictions on products with digital elements or on suppliers of such products, which take into account non-technical factors. National measures relating to such factors shall be compatible with Union law.
(14) This Regulation should be without prejudice to the responsibility of Member States to ensure national security, in accordance with Union law. Member States should be able to impose additional requirements on products containing digital elements that are procured or used for national security or defense purposes, provided that those requirements are consistent with Member States’ obligations under Union law.
(15) This Regulation applies to economic operators only in relation to products with digital elements that are made available on the market, i.e. supplied in the context of a commercial activity for distribution or use on the Union market. A supply in the context of a commercial activity may not only be characterized by the fact that a price is charged for a product with digital elements, but also by the fact that a fee is charged for technical support services that are not only intended to cover actual costs, for example by providing a software platform, through which the manufacturer offers other services for profit, or that the processing of personal data for purposes other than the sole improvement of the security, compatibility or interoperability of the software is required as a condition of use, or that donations are accepted that exceed the costs associated with the design, development and provision of a product with digital elements. The acceptance of non-profit donations should not be considered a business activity.
(16) Products with digital elements that are provided in the context of the provision of a service for which a fee is charged exclusively to cover the actual costs directly related to the operation of that service, as may be the case for certain products with digital elements provided by public administration bodies, should not be considered to be part of a commercial activity within the meaning of this Regulation on those grounds alone. Furthermore, products with digital elements that are developed or modified by a public administration body exclusively for its own use should not be considered to be made available on the market within the meaning of this Regulation.
(17) Software and data that are openly shared and that users can freely access, use, modify and redistribute, including in modified form, can contribute to research and innovation on the market. In order to encourage the development and use of free and open source software, in particular by micro, small and medium-sized enterprises, including start-ups, individuals, non-profit organizations and academic research institutions, the application of this Regulation to products with digital elements that are classified as free and open source software and made available for distribution or use in the course of a commercial activity should take into account the types of different development models for software distributed and developed under free and open source software licences.
(18) Free and open source software is software whose source code is openly shared and whose license includes all the necessary rights to make it freely accessible, usable, modifiable and redistributable. Free and open source software is developed, maintained and distributed openly, including via online platforms. With regard to economic operators falling within the scope of this Regulation, only free and open source software that is made available on the market and thus made available for distribution or use in the course of a commercial activity should fall within the scope of this Regulation. The mere circumstances in which the product containing digital elements was developed or the way in which the development was financed should therefore not be taken into account when determining the commercial or non-commercial nature of the relevant activity. In particular, for the purposes of this Regulation and in relation to the economic operators falling within its scope, the supply of products incorporating digital elements that are classified as free and open source software and are not monetized by their producers should not be considered a commercial activity, in order to ensure that a clear distinction is made between the development and supply phases. In addition, the supply of products with digital elements that are classified as free and open source software components and are intended for integration by other producers into their own products with digital elements should only be considered as making available on the market if the component is monetized by its original producer. For example, the mere fact that a product of open source software with digital elements is financially supported by the producers or that producers contribute to the development of such a product should not in itself be decisive for establishing that the activity is of a commercial nature. Furthermore, the mere existence of regular releases of versions should not in itself lead to the conclusion that a product with digital elements is supplied in the course of a commercial activity. Finally, for the purposes of this Regulation, the development by non-profit organizations of products with digital elements that qualify as free and open source software should not be considered to be a commercial activity, provided that the organization is set up in such a way as to ensure that all revenues after deduction of costs are used to achieve non-profit objectives. This Regulation shall not apply to natural or legal persons who contribute with source code to products with digital elements that are classified as free and open source software and are not under their responsibility.
(19) Given the importance for cybersecurity of many products with digital elements that are classified as free and open source software and are published but not made available on the market within the meaning of this Regulation, legal entities that support the development of such products intended for commercial activities on a permanent basis and play an important role in ensuring the usability of those products (open source software managers) should be subject to a simplified and tailored regulatory regime. Managers of open source software include certain foundations and entities that develop and publish free and open source software in a commercial context, including non-profit entities. Regulation should take into account their specificities and compatibility with the nature of the obligations imposed. Only products with digital elements that qualify as free and open source software and are ultimately intended for commercial activities, such as integration into commercial services or paid products with digital elements, should be covered. For the purposes of this regulatory regime, intended integration into paid products with digital elements includes cases where the manufacturers integrating a component into their own products with digital elements either regularly contribute to the development of that component or provide regular financial support to ensure the continuity of a software product. Ongoing support for the development of a product with digital elements includes hosting and managing software development collaboration platforms, hosting source code or software, managing or administering products with digital elements that are classified as free and open source software, and managing the development of such products. Since the simplified and tailor-made regulatory regime does not provide for the same obligations for managers of open source software as for manufacturers under this Regulation, they should not be allowed to affix the CE marking on products incorporating digital elements whose development they support.
(20) The mere provision of products with digital elements in open archives, including through package management or on collaborative platforms, does not in itself constitute the provision of a product with digital elements on the market. The providers of such services should only be considered as distributors if they make such software available on the market and thus supply it in the course of a commercial activity for distribution or use on the Union market.
(21) In order to support and facilitate the due diligence of manufacturers integrating free and open source software components that are not subject to the essential cybersecurity requirements laid down in this Regulation into their products incorporating digital items, the Commission should be able to establish voluntary security certification schemes, either by means of a delegated act supplementing this Regulation or by requiring a European cybersecurity certification scheme in accordance with Article 48 of Regulation (EU) 2019/881, which takes into account the specificities of free and open source software development models. The security certification schemes should be designed in such a way that not only natural or legal persons developing or contributing to a product with digital elements classified as free and open source software can initiate or finance a security certification, but also third parties, such as manufacturers integrating such products with digital elements into their own products with digital elements, as well as users or public administrations of the Union and of the Member States.
(22) In view of the objectives of this Regulation in the field of public cybersecurity and in order to improve Member States’ awareness of the Union’s dependency on software components, and in particular on potentially free and open source software components, a special administrative cooperation group (ADCO) established by this Regulation should be able to decide to jointly carry out a Union dependency assessment. Market surveillance authorities should be able to request manufacturers of products with digital elements falling within the categories established by ADCO to submit the software BOMs that they have drawn up in accordance with this Regulation. In order to protect the confidentiality of the software BOMs, market surveillance authorities should submit relevant information on dependencies to ADCO in an anonymized and aggregated form.
(23) The effectiveness of the implementation of this Regulation will also depend on the availability of adequate cybersecurity skills. At Union level, various programmatic and policy documents, including the Commission Communication of 18 April 2023 entitled “Closing the cybersecurity skills gap to boost EU competitiveness, growth and resilience” and the Council Conclusions of 22 May 2023 on EU cyber defense policy, have acknowledged that a cybersecurity skills gap exists in the Union and needs to be addressed as a matter of priority in both the public and private sectors. In order to ensure the effective implementation of this Regulation, Member States should ensure that sufficient resources are available to adequately staff market surveillance authorities and conformity assessment bodies so that they can carry out their tasks set out in this Regulation. As part of those measures, the mobility of the cybersecurity workforce and related career paths should be improved. The measures should also contribute to making the cybersecurity workforce more resilient and inclusive, including in terms of gender equality. Member States should therefore make provisions to ensure that the relevant tasks are carried out by appropriately trained professionals with the necessary cybersecurity skills. Similarly, manufacturers should ensure that their personnel have the necessary skills to fulfill their obligations under this Regulation. Member States and the Commission should, in accordance with their prerogatives and competences and the specific tasks conferred on them by this Regulation, take measures to support manufacturers, in particular micro, small and medium-sized enterprises, including start-ups, including in areas such as capacity building, in order to enable them to comply with their obligations under this Regulation. As Directive (EU) 2022/2555 requires Member States to take measures to promote and develop cybersecurity training and cybersecurity skills as part of their national cybersecurity strategies, Member States may, when adopting such strategies, also consider addressing cybersecurity skills needs arising from this Regulation, including retraining and upskilling needs.
(24) A secure internet is essential for the functioning of critical infrastructures and for society as a whole. Directive (EU) 2022/2555 aims to ensure a high level of cybersecurity of the services of the essential and critical entities referred to in Article 3 of that Directive, including digital infrastructure operators, supporting the core functions of the open internet and ensuring internet access and services. It is therefore important that the products containing digital elements necessary to enable digital infrastructure operators to ensure the functioning of the internet are developed in a secure manner and that they comply with established internet security standards. This Regulation, which applies to all connectable hardware and software products, also aims to make it easier for digital infrastructure operators to comply with the supply chain requirements of Directive (EU) 2022/2555 by ensuring that the products with digital elements that they use to provide their services are developed in a secure manner and that they receive timely security updates for such products.
(25) Regulation (EU) 2017/745 of the European Parliament and of the Council (9) contains rules for medical devices and Regulation (EU) 2017/746 of the European Parliament and of the Council (10) contains rules for in vitro diagnostic medical devices. These regulations are designed to address cybersecurity risks and follow specific approaches that also underlie this Regulation. In particular, Regulations (EU) 2017/745 and (EU) 2017/746 contain essential requirements for medical devices that function by means of an electronic system or that are themselves software. Certain non-embedded software and the whole life cycle approach are also covered by these regulations. According to these requirements, manufacturers must apply risk management principles in the development and design of their products and define requirements for IT security measures and corresponding conformity assessment procedures. In addition, specific guidance on cybersecurity of medical devices has been in place since December 2019, providing guidance to manufacturers of medical devices and in vitro diagnostic medical devices on how to comply with all relevant essential requirements set out in Annex I of these regulations in relation to cybersecurity. Devices with digital elements covered by one of those Regulations should therefore not be covered by this Regulation.
(26) Products containing digital elements developed or modified exclusively for national security or defense purposes or products specifically designed for the processing of classified information shall not fall within the scope of this Regulation. Member States are required to ensure the same or a higher level of protection for those products than for the products falling within the scope of this Regulation.
(27) Regulation (EU) 2019/2144 of the European Parliament and of the Council (11) lays down requirements for the type-approval of motor vehicles and of systems and components for those vehicles and introduces certain cybersecurity requirements, including in relation to the operation of a certified cybersecurity management system, software updates that include the organizations’ policies and procedures for managing cybersecurity risks throughout the life cycle of vehicles, equipment and services in accordance with the applicable United Nations regulations on technical specifications and cybersecurity, in particular UN Regulation No 155 – Uniform provisions concerning the approval of vehicles with regard to cybersecurity and cybersecurity management systems (12), and provides for specific conformity assessment procedures. 155 – Uniform provisions concerning the approval of vehicles with regard to cybersecurity and the cybersecurity management system (12), and provide for specific conformity assessment procedures. In the field of aviation, the main objective of Regulation (EU) 2018/1139 of the European Parliament and of the Council (13) is to establish and maintain a high uniform level of aviation safety in the Union. The Regulation establishes a framework for essential requirements for the airworthiness of aeronautical products, parts and appliances, including software, which includes obligations to protect against information security threats. The certification process under Regulation (EU) 2018/1139 ensures the trustworthiness sought by this Regulation. Products with digital elements covered by Regulation (EU) 2019/2144 and products certified under Regulation (EU) 2018/1139 should therefore not be subject to the essential cybersecurity requirements and conformity assessment procedures laid down in this Regulation.
(28) This Regulation lays down horizontal cybersecurity rules that are not intended to apply specifically to certain sectors or certain products with digital elements. Nevertheless, sector- or product-specific Union legislation could be introduced with requirements that address all or some of the risks covered by the essential cybersecurity requirements laid down in this Regulation. The application of this Regulation to products with digital elements that are covered by other Union legislation imposing requirements relating to all or some of the risks covered by the essential cybersecurity requirements laid down in this Regulation may be restricted or excluded in such cases, provided that the restriction or exclusion is compatible with the general legal framework applicable to those products and that the sector-specific rules achieve at least the same level of protection as is ensured by this Regulation. The Commission should be empowered to adopt delegated acts supplementing this Regulation with regard to the establishment of such products and rules. With regard to existing Union law to which such restrictions or exclusions should apply, this Regulation contains specific provisions to clarify its relationship with that Union law.
(29) In order to ensure that products with digital elements made available on the market can be effectively repaired and their lifetime extended, an exemption should be provided for spare parts. That exemption should apply both to spare parts used for the repair of existing devices made available before the date of application of this Regulation and to spare parts that have already undergone a conformity assessment procedure in accordance with this Regulation.
(30) Commission Delegated Regulation (EU) 2022/30 (14) provides that the essential requirements referred to in Article 3(3)(d), (e) and (f) of Directive 2014/53/EU of the European Parliament and of the Council (15), which relate to harmful effects on the network and misuse of network resources, personal data and privacy and fraud, apply to certain radio equipment. Commission Implementing Decision C(2022) 5637 of 5 August 2022 on a standardization request to the European Committee for Standardization and the European Committee for Electrotechnical Standardization contains requirements for the development of specific standards specifying how these three essential requirements are to be addressed. The essential cybersecurity requirements laid down in this Regulation cover all elements of the essential requirements referred to in Article 3(3)(d), (e) and (f) of Directive 2014/53/EU. In addition, the essential cybersecurity requirements laid down in this Regulation are consistent with the objectives of the requirements for the specific standards provided for in this standardization mandate. Therefore, when the Commission repeals or amends Delegated Regulation (EU) 2022/30 so that it no longer applies to certain products covered by this Regulation, the Commission and the European standardization organisations should take into account the standardization work carried out under Implementing Decision C(2022) 5637 when drafting and developing harmonized standards in order to facilitate the implementation of this Regulation. During the transitional period for the application of this Regulation, the Commission should provide guidance to manufacturers subject to this Regulation and also to Delegated Regulation (EU) 2022/30 in order to facilitate the demonstration of compliance with both Regulations.
(31) Directive (EU) 2024/2853 of the European Parliament and of the Council (16) is complementary to this Regulation. This Directive lays down rules on liability for defective products in order to allow injured persons to claim compensation for damage caused by a defective product. It lays down the principle that the manufacturer of a product is liable, regardless of fault, for damage caused by the lack of safety of his product (“strict liability”). If such a lack of safety consists of a lack of safety updates after the product has been placed on the market and this causes damage, this could result in the manufacturer’s liability. This Regulation should lay down obligations for manufacturers in relation to the provision of such safety updates.
(32) This Regulation should apply without prejudice to Regulation (EU) 2016/679 of the European Parliament and of the Council (17), which contains provisions relating to the establishment of data protection certification mechanisms and of data protection seals and marks to demonstrate that data controllers and processors comply with the provisions of the latter Regulation when processing data. Such processes could be embedded in a product with digital elements. The principles of data protection by design and by default and cybersecurity in general are key elements of Regulation (EU) 2016/679. By protecting consumers and organizations from cybersecurity risks, the essential cybersecurity requirements laid down in this Regulation should also help to improve the protection of personal data and the privacy of individuals. Synergies in the cooperation between the Commission, the European standardization organisations, the European Union Agency for Cybersecurity (ENISA), the European Data Protection Board established by Regulation (EU) 2016/679 and the national data protection supervisory authorities should be taken into account for both standardization and certification of cybersecurity aspects. Synergies between this Regulation and Union data protection law should also be sought in the area of market surveillance and law enforcement. To this end, the national market surveillance authorities designated under this Regulation should cooperate with the authorities supervising the application of Union data protection law. The latter authorities should also have access to information relevant for the performance of their tasks.
(33) To the extent that their products fall within the scope of this Regulation, European digital identity wallet providers (EUid wallets) should comply with both the horizontal essential cybersecurity requirements laid down in this Regulation and the specific security requirements laid down in Article 5a of Regulation (EU) No 910/2014, in accordance with Article 5a(2) of Regulation (EU) No 910/2014 of the European Parliament and of the Council (18). In order to facilitate compliance, providers of EUid wallets should be able to demonstrate the compliance of EUid wallets with the requirements laid down in this Regulation and in Regulation (EU) No 910/2014 by having their products certified under a European cybersecurity certification scheme under Regulation (EU) 2019/881 for which the Commission has established, by means of a delegated act, a presumption of conformity with the requirements of this Regulation to the extent that the certificate or parts thereof cover those requirements.
(34) When integrating components sourced from third parties into devices with digital elements at the design and development stage, manufacturers should exercise due diligence on those components, including free and open source software components that have not been made available on the market, to ensure that the devices are designed, developed and manufactured in compliance with the essential cybersecurity requirements laid down in this Regulation. The appropriate level of due diligence depends on the nature and extent of the cybersecurity risk associated with a particular component and should take into account one or more of the following measures for this purpose: checking, where appropriate, whether the manufacturer of a component has demonstrated compliance with this Regulation, including a check on whether the component already bears the CE marking; checking whether a component is subject to regular security updates, such as by checking past security updates; checking whether a component is free from the vulnerabilities registered in the European vulnerability database established pursuant to Article 12(2) of Directive (EU) 2022/2555 or other publicly available vulnerability databases, or carrying out additional security checks. The vulnerability management obligations laid down in this Regulation, which manufacturers shall comply with when placing a device with digital elements on the market and during the support period, shall apply to devices with digital elements in their entirety, including all integrated components. If the manufacturer of the product with digital elements identifies a vulnerability in a component, including in a free and open source component, as part of its due diligence, it should inform the person or entity that manufactured or maintains the component, fix the vulnerability and, where appropriate, provide the person or entity with the security patch applied.
(35) Immediately after the transitional period for the application of this Regulation, a manufacturer of a device with digital elements that incorporates one or more components sourced from third parties that are also subject to this Regulation may not be able to carry out due diligence to verify that the manufacturers of those components have demonstrated conformity with this Regulation, for example by checking whether the components already bear the CE marking. This may be the case if the constituents have been integrated before this Regulation becomes applicable to the manufacturers of these constituents. In such a case, a manufacturer integrating such components should fulfill his due diligence obligation in another way.
(36) Products incorporating digital elements should, as a general rule, bear the CE marking indicating their conformity with this Regulation in a visible, legible and indelible manner so that they can move freely within the internal market. Member States should not create unjustified obstacles to the placing on the market of products incorporating digital elements which comply with the requirements laid down in this Regulation and bear the CE marking. Furthermore, Member States should not prevent the presentation or use of a product incorporating digital elements that does not comply with this Regulation at trade fairs, exhibitions, demonstrations or similar events, including prototypes, provided that the product bears a visible marking clearly indicating that the product does not comply with this Regulation and may not be made available on the market until it does so.
(37) In order to allow manufacturers to release software for testing purposes before subjecting their devices incorporating digital elements to conformity assessment, Member States should not prevent unfinished software from being made available, for example as alpha, beta or pre-release versions, provided that the unfinished software is made available only for as long as is necessary for testing and collecting feedback. Manufacturers should ensure that software made available under those conditions is released only after a risk assessment and complies as far as possible with the safety requirements of this Regulation in relation to the characteristics of devices incorporating digital elements. Manufacturers should also implement the vulnerability handling requirements as far as possible. Manufacturers should not force users to update to versions that have only been released for testing purposes.
(38) In order to ensure that products with digital elements do not pose cybersecurity risks to persons and organizations when placed on the market, essential cybersecurity requirements should be established for such products. These essential cybersecurity requirements, including vulnerability management requirements, apply to each individual product with digital elements when it is placed on the market, regardless of whether the product with digital elements is manufactured as a single unit or in series. For example, for a product type, each individual product with digital elements should have received all available security patches or updates to address relevant security issues when it is placed on the market. If such products with digital elements are subsequently physically or digitally modified in a way not foreseen by the manufacturer in the original risk assessment and which may result in them no longer meeting the relevant essential cybersecurity requirements, the modification should be considered substantial. For example, repairs could be treated in the same way as maintenance work, provided that they do not modify a product with digital elements that has already been placed on the market in such a way that conformity with the applicable requirements may be affected or the intended purpose for which the product was tested may be changed.
(39) As with physical repairs or modifications, a device with digital elements should be considered to be substantially modified by a software update if the software update changes the intended purpose of the device and these changes were not foreseen by the manufacturer in the original risk assessment, or if the nature of the hazard has changed or the cybersecurity risk has increased due to the software update and the updated version of the device is made available on the market. If a security update intended to reduce the cybersecurity risk of a product with digital elements does not change the intended purpose of a product with digital elements, it is not considered a substantial change. This generally includes cases where a security update only involves minor adjustments to the source code. This could be the case, for example, where a security update addresses a known vulnerability, including by changing the functionality or performance of a product with digital elements for the sole purpose of reducing cybersecurity risk. Similarly, a minor update to functionality, such as a visual improvement or the addition of new languages or new icons to the user interface, should generally not be considered a material change. Conversely, a functional update that changes the originally intended functions or the nature or performance of a product with digital elements and meets the above criteria should be considered a material change, as the addition of new functions usually leads to a larger attack surface and thus increases the cybersecurity risk. This could be the case, for example, if a new input element is added to an application, so that the manufacturer must ensure adequate input validation. When assessing whether a functional update is to be considered a substantial change, it does not matter whether it is provided as a separate update or in combination with a security update. The Commission should issue guidance on how to determine what constitutes a substantial change.
(40) In view of the repetitive nature of software development, manufacturers who have placed new versions of a software product on the market due to a subsequent substantial change to the product should be able to offer security updates during the support period only for the version of the software product that they last placed on the market. They should only be entitled to do so if the users of the relevant earlier versions of the product have access to the last version of the product they placed on the market and if they do not incur additional costs for adapting the hardware or software environment in which they operate the product. This could be the case, for example, if an upgrade of the desktop operating system does not require new hardware, e.g. a faster central processing unit or more memory. Notwithstanding this, the manufacturer should continue to comply with other vulnerability handling requirements during the support period, such as having a coordinated vulnerability disclosure policy or having arrangements in place to facilitate the sharing of information about potential vulnerabilities for any subsequent significantly modified versions of the software product placed on the market. Manufacturers should be able to provide minor security or functional updates that do not constitute a substantial change only for the latest version or sub-version of a software product that has not been substantially changed. At the same time, in cases where a hardware product, such as a smartphone, is not compatible with the latest version of the operating system with which it was originally supplied, the manufacturer should continue to provide security updates during the support period at least for the latest compatible version of the operating system.
(41) In accordance with the generally accepted concept of substantial modification of products subject to Union harmonization legislation, where a substantial modification occurs which could affect the conformity of a product with digital elements with this Regulation, or where the intended purpose of that product changes, it is appropriate to review the conformity of the product with digital elements and, where appropriate, to subject it to a new conformity assessment. Where the manufacturer carries out a conformity assessment involving a third party, a change that could lead to a substantial modification should be notified to the third party.
(42) Subjecting a device with digital elements to ‘overhaul’, ‘maintenance’ and ‘repair’ as defined in points 18, 19 and 20 of Article 2 of Regulation (EU) 2024/1781 of the European Parliament and of the Council (19) does not necessarily result in a substantial change to the device, for example if the intended purpose and functions are not changed and the level of risk remains the same. However, the addition of digital elements to a product by the manufacturer could lead to changes in the design and development of the product and therefore have an impact on its intended purpose and conformity with the requirements laid down in this Regulation.
(43) Products with digital elements should be considered important where the negative impact of exploiting potential cybersecurity vulnerabilities in the product may be severe, including due to its cybersecurity function or a function that poses a significant risk of adverse impact in terms of its scope and opportunity, disrupt, control or harm a large number of other products with digital elements or affect the health, safety or integrity of their users by directly manipulating it, such as a key system function, including network management, configuration control, virtualization or personal data processing. In particular, vulnerabilities in products with digital elements that have a cybersecurity function, such as boot managers, can lead to a proliferation of security issues throughout the supply chain. The severity of the impact of a security incident may also increase if the product primarily performs a key system function, including network management, configuration control, virtualization or personal data processing.
(44) Certain categories of products with digital elements should be subject to stricter conformity assessment procedures, while maintaining proportionality. To that end, critical devices with digital elements should be divided into two classes reflecting the cybersecurity risk associated with those categories of devices. A security incident involving critical devices with digital elements falling into class II could have a greater negative impact than a security incident involving critical devices with digital elements falling into class I, for example because of the nature of their cybersecurity function or the performance of another function that carries a significant risk of adverse effects. An indication of major adverse effects could be that devices with digital elements falling into class II perform either a cybersecurity function or another function associated with a higher risk of adverse effects than devices in class I, or both. Essential devices with digital elements falling within Class II should therefore be subject to a more stringent conformity assessment procedure.
(45) Essential devices with digital elements referred to in this Regulation should be understood as devices that have the core function of a category of essential devices with digital elements defined in this Regulation. For example, this Regulation establishes categories of critical devices with digital elements which are defined by their core function as firewalls or intrusion detection systems or intrusion prevention systems of class II. Consequently, firewalls and intrusion detection and prevention systems are subject to mandatory third party conformity assessment. This does not apply to other products with digital elements which are not classified as critical products with digital elements and which may contain firewalls or intrusion detection systems or intrusion prevention systems. The Commission should adopt an implementing act to specify the technical description of the categories of critical devices with digital elements falling within Classes I and II under this Regulation.
(46) The categories of critical devices with digital elements set out in this Regulation are associated with a cybersecurity function and are used for a function that poses a significant risk of adverse effects in terms of its scope and its ability to disrupt, control or harm a large number of other devices with digital elements by directly manipulating them. In addition, these categories of products with digital elements are considered critical dependencies for the essential facilities referred to in Article 3(1) of Directive (EU) 2022/2555. The categories of critical products with digital elements that are listed in an Annex to this Regulation due to their criticality often already use different forms of certification and are also covered by the European Cybersecurity Certification (EUCC) scheme based on common criteria laid down in Implementing Regulation (EU) 2024/482 (20). In order to ensure a common adequate level of cybersecurity protection of critical products with digital elements in the Union, it could therefore be appropriate and proportionate to subject such product categories to mandatory European cybersecurity certification by means of a delegated act, where a relevant European cybersecurity certification scheme for those products already exists and the Commission has carried out an assessment of the potential impact of the envisaged mandatory certification on the market. This assessment should take into account both the supply and the demand side, including whether there is sufficient demand for the relevant products with digital elements from both Member States and users to require European cybersecurity certification, as well as the purposes for which the products with digital elements are intended to be used, including the critical dependencies thereon by the essential entities referred to in Article 3(1) of Directive (EU) 2022/2555. The assessment should also analyze the potential impact of mandatory certification on the availability of those products on the internal market and the capabilities and readiness of Member States to implement the relevant European cybersecurity certification schemes.
(47) Delegated acts imposing mandatory European cybersecurity certification should identify the products with digital elements that have the core functions of a category of critical products with digital elements defined in this Regulation to be subject to mandatory certification and the required assurance level, which should be at least ‘medium’. The required assurance level should be proportionate to the level of cybersecurity risk associated with the product with digital elements. For example, if the device with digital elements has the core function of a category of critical devices with digital elements defined in this Regulation and is intended for use in a sensitive or critical environment, such as devices intended for use by the essential entities referred to in Article 3(1) of Directive (EU) 2022/2555, the highest assurance level may be required.
(48) In order to ensure common and adequate cybersecurity protection of products with digital elements in the Union that have the core function of a category of critical products with digital elements defined in this Regulation, the power to adopt delegated acts should also be delegated to the Commission in respect of amending this Regulation by adding or deleting categories of critical devices with digital elements for which manufacturers could be required to obtain a European cybersecurity certificate under a European cybersecurity certification scheme pursuant to Regulation (EU) 2019/881 in order to demonstrate compliance with this Regulation. A new category of critical products with digital elements may be added to these categories if there is a critical dependency of the essential facilities referred to in Article 3(1) of Directive (EU) 2022/2555 on these products or if they are affected by security incidents or contain exploited vulnerabilities and this could lead to disruptions of critical supply chains. When assessing whether it is necessary to add or remove categories of critical products with digital elements by means of a delegated act, the Commission should be able to take into account whether Member States have identified at national level products with digital elements that are critical to the resilience of essential facilities within the meaning of Article 3(1) of Directive (EU) 2022/2555 and that are increasingly subject to cyber-attacks on the supply chain, which could result in serious disruptions. In addition, the Commission should have the possibility to take into account the outcome of the coordinated risk assessments on the security of critical supply chains at Union level carried out in accordance with Article 22 of Directive (EU) 2022/2555.
(49) The Commission should ensure that a broad range of relevant stakeholders are consulted in a structured and regular manner when developing measures to implement this Regulation. This should in particular be the case when the Commission considers the possible need to update the lists of categories of important or critical products with digital elements, consulting relevant manufacturers and taking into account their views in order to analyze the cybersecurity risks and the cost-benefit ratio associated with the classification of such categories of products as important or critical.
(50) This regulation specifically addresses cybersecurity risks. However, products with digital elements may present other security risks that are not always related to cybersecurity but may result from a security breach. Those risks should continue to be addressed by other relevant Union harmonization legislation than this Regulation. Where Union harmonization legislation other than this Regulation is not applicable, they should be subject to Regulation (EU) 2023/988 of the European Parliament and of the Council (21). Therefore, given the targeted nature of this Regulation, by way of derogation from point (b) of the third subparagraph of Article 2(1) of Regulation (EU) 2023/988, in relation to security risks not covered by this Regulation, Section 1 of Chapter III, Chapters V and VII and Chapters IX to XI of Regulation (EU) 2023/988 should also apply to products incorporating digital elements where those products are not subject to specific requirements of Union harmonization legislation other than this Regulation within the meaning of point (27) of Article 3 of Regulation (EU) 2023/988.
(51) Products with digital elements classified as high-risk AI-systems in accordance with Article 6 of Regulation (EU) 2024/1689 of the European Parliament and of the Council (22) and falling within the scope of this Regulation should comply with the essential cybersecurity requirements laid down in this Regulation. Where those high-risk AI-systems comply with the essential cybersecurity requirements laid down in this Regulation, they should be deemed to comply with the cybersecurity requirements set out in Article 15 of Regulation (EU) 2024/1689 to the extent that those requirements are covered by the EU declaration of conformity or parts thereof issued pursuant to this Regulation. To that end, when assessing the cybersecurity risks associated with a product with digital elements that is classified as a high-risk AI-system in accordance with Regulation (EU) 2024/1689, to be taken into account during the planning, design, development, production, delivery and maintenance phases of such a product, as required by this Regulation, the risks to the cyber resilience of an AI system are considered in relation to attempts by unauthorized third parties to alter the use, behaviour or performance of the system, including AI-specific vulnerabilities such as data poisoning or adversarial attack, and, where applicable, risks to fundamental rights, in accordance with Regulation (EU) 2024/1689. For the conformity assessment procedures concerning the essential cybersecurity requirements for a device with digital elements that falls within the scope of this Regulation and is classified as a high-risk AI-system, Article 43 of Regulation (EU) 2024/1689 should in principle apply instead of the relevant provisions of this Regulation. However, that rule should not have the effect of reducing the level of assurance required for the important or critical products with digital elements referred to in this Regulation. Therefore, by way of derogation from that rule, high-risk AI-systems which fall within the scope of Regulation (EU) 2024/1689 and which are also important or critical devices with digital elements as referred to in this Regulation and to which the conformity assessment procedure based on internal control set out in Annex VI to Regulation (EU) 2024/1689 is applied should be subject to the conformity assessment procedures of this Regulation as far as the essential cybersecurity requirements laid down in this Regulation are concerned. In that case, for all other aspects covered by Regulation (EU) 2024/1689, the relevant provisions on conformity assessment based on internal control set out in Annex VI to that Regulation should apply.
(52) In order to enhance the security of products with digital elements placed on the internal market, it is necessary to lay down essential cybersecurity requirements applicable to such products. Those essential cybersecurity requirements should be without prejudice to the coordinated risk assessments on the security of critical supply chains at Union level provided for in Article 22 of Directive (EU) 2022/2555, which take into account both technical and, where applicable, non-technical risk factors, such as undue influence of a third country on suppliers. Furthermore, they should be without prejudice to the prerogatives of Member States to lay down additional requirements that take into account non-technical factors to ensure a high level of resilience, including those defined in Commission Recommendation (EU) 2019/534 (23), in the EU-wide coordinated cybersecurity risk assessment of 5G networks and in the EU 5G cybersecurity toolbox adopted by the NIS Cooperation Group established under Article 14 of Directive (EU) 2022/2555.
(53) Manufacturers of devices that fall within the scope of Regulation (EU) 2023/1230 of the European Parliament and of the Council (24) and whose products are also devices with digital elements within the meaning of this Regulation should comply with both the essential cybersecurity requirements laid down in this Regulation and the essential health and safety requirements laid down in Regulation (EU) 2023/1230. The essential cybersecurity requirements laid down in this Regulation and certain essential requirements laid down in Regulation (EU) 2023/1230 may address similar cybersecurity risks. Therefore, compliance with the essential cybersecurity requirements laid down in this Regulation could facilitate compliance with the essential requirements that also cover certain cybersecurity risks laid down in Regulation (EU) 2023/1230, in particular the requirements relating to protection against tampering and the safety and reliability of control systems set out in Sections 1.1.9 and 1.2.1 of Annex III to that Regulation. Such synergy must be demonstrated by the manufacturer, for example through the application of harmonized standards or other technical specifications covering the relevant essential cybersecurity requirements, after a risk assessment for the relevant cybersecurity risks has been carried out. The manufacturer should also follow the applicable conformity assessment procedures in accordance with this Regulation and Regulation (EU) 2023/1230. The Commission and the European standardization organisations should promote consistency in the preparatory work supporting the implementation of this Regulation and Regulation (EU) 2023/1230 and the related standardization procedures as regards the assessment of cybersecurity risks and the way in which those risks are to be covered by harmonized standards with regard to the relevant essential requirements. In particular, the Commission and the European standardization organisations should take into account this Regulation when drafting and developing harmonized standards in order to facilitate the implementation of Regulation (EU) 2023/1230, in particular with regard to the cybersecurity aspects related to protection against corruption and the safety and reliability of control systems listed in Sections 1.1.9 and 1.2.1 of Annex III to that Regulation. The Commission should provide guidance to assist manufacturers subject to this Regulation and also to Regulation (EU) 2023/1230, in particular to facilitate the demonstration of compliance with the relevant essential requirements of this Regulation and of Regulation (EU) 2023/1230.
(54) In order to ensure that products incorporating digital elements are secure both at the time of their placing on the market and during the expected life of the product incorporating digital elements, it is necessary to establish essential cybersecurity requirements for the handling of vulnerabilities and essential cybersecurity requirements relating to the characteristics of products incorporating digital elements. Manufacturers should both comply with all essential cybersecurity requirements related to vulnerability handling throughout the support period and determine which other essential cybersecurity requirements related to product characteristics are relevant for the type of devices with digital elements concerned. To that end, manufacturers should carry out an assessment of the cybersecurity risks associated with a product with digital elements in order to identify relevant risks and essential cybersecurity requirements so that they provide their products with digital elements without known exploitable vulnerabilities that could affect the security of those products and to apply appropriate harmonized standards, common specifications or European or international standards as appropriate.
(55) Where certain essential cybersecurity requirements are not applicable to a device with digital elements, the manufacturer should clearly justify this in the cybersecurity risk assessment accompanying the technical documentation. This could be the case if a basic cybersecurity requirement is incompatible with the nature of a product with digital elements. For example, the intended purpose of a product with digital elements may require the manufacturer to comply with widely recognized interoperability standards, even if its security features are no longer state of the art. Other Union legislation also requires manufacturers to comply with specific interoperability requirements. Where a cybersecurity essential requirement is not applicable to a product with digital elements, but the manufacturer has identified cybersecurity risks related to that cybersecurity essential requirement, it should take measures to address those risks by other means, for example by limiting the intended use of the product to trusted environments or by informing users of those risks.
(56) One of the most important steps users need to take to protect their products with digital elements from cyber-attacks is to install the latest available security updates as quickly as possible. Manufacturers should therefore design their products and set up procedures so that products with digital elements include automatic features for the notification, distribution, download and installation of security updates, especially in the case of consumer products. They should also offer the possibility to authorize the download and installation of security updates as a final step. Users should continue to have the possibility to disable automatic updates, with a clear and easy-to-use process complemented by clear explanations on how users can opt out of updates. The requirements on automatic updates set out in an Annex to this Regulation shall not apply to devices with digital elements that are primarily intended to be integrated as components into other devices. They shall also not apply to devices incorporating digital elements where users would not normally expect automatic updates, including devices incorporating digital elements intended for use in professional ICT networks and in particular in critical and industrial environments where automatic updating could lead to disruption of operations. Regardless of whether a product with digital elements is designed to receive automatic updates or not, its manufacturer should inform users of vulnerabilities and provide security updates without delay. Where a product with digital features has a user interface or similar technical means that allow direct interaction with its users, the manufacturer should use these features to inform users that their product with digital features has reached the end of its support period. The notifications should be limited to what is necessary to ensure the effective receipt of that information and should not have a negative impact on the user experience of the product with digital elements.
(57) In order to make vulnerability handling procedures more transparent and to ensure that users are not forced to install new feature updates just to get the latest security updates, manufacturers should ensure that new security updates are provided separately from feature updates, where technically feasible.
(58) The Joint Communication of the Commission and the High Representative of the Union for Foreign Affairs and Security Policy of 20 June 2023 on a “European Strategy for Economic Security” states that the Union needs to maximize the benefits of its economic openness while minimizing the risks arising from economic dependencies on high-risk suppliers through a common strategic framework for the Union’s economic security. Dependencies on high-risk providers of products with digital elements may constitute a strategic risk that needs to be addressed at Union level, in particular where the products with digital elements are intended for use by the essential entities referred to in Article 3(1) of Directive (EU) 2022/2555. These risks may be related, inter alia, to the jurisdiction applicable to the manufacturer, the characteristics of its corporate ownership and the controlling relationship with the government of a third country in which it is established, in particular where the third country engages in industrial espionage or irresponsible state behavior in cyberspace and its laws allow arbitrary access to business transactions or corporate data of any kind, including commercially sensitive data, including commercially sensitive data, and may impose intelligence obligations without democratic safeguards, oversight mechanisms, due process or the right to appeal to an independent tribunal. When determining the materiality of a cybersecurity risk for the purposes of this Regulation, the Commission and the market surveillance authorities should also take into account non-technical risk factors, in particular those identified as a result of coordinated supply chain security risk assessments at Union level carried out in accordance with Article 22 of Directive (EU) 2022/2555, within the scope of their responsibilities set out in this Regulation.
(59) In order to ensure the safety of products incorporating digital elements after they have been placed on the market, manufacturers should determine the support period, which should take into account the expected lifetime of the product incorporating digital elements. When setting a support period, a manufacturer should take into account, in particular, the legitimate expectations of users, the nature of the product and the relevant Union law defining the lifetime of products incorporating digital elements. Manufacturers should also be able to take into account other relevant factors. The criteria should be applied in such a way as to ensure proportionality when determining the support periods. Upon request, a manufacturer should make available to the market surveillance authorities the information taken into account when determining the support period of a product with digital elements.
(60) The support period for which the manufacturer ensures the effective treatment of vulnerabilities should be at least five years, unless the lifetime of the product with digital elements is less than five years, in which case the manufacturer should ensure the treatment of vulnerabilities for the corresponding lifetime. Where it can reasonably be expected that the product with digital elements will be used for more than five years, as is often the case for hardware components such as motherboards or microprocessors, for network devices such as routers, modems or switches, and for software such as operating systems or video editing tools, manufacturers should ensure correspondingly longer support periods. In particular, products with digital elements intended for use in industrial environments, such as industrial control systems, are often used for much longer periods of time. A manufacturer should only be able to set a support period of less than five years if this is justified by the nature of the digital element product concerned and the product is expected to be in use for less than five years, in which case the support period should correspond to the expected lifetime. For example, the lifetime of a contact tracing app intended for use during a pandemic could be limited to the duration of the pandemic. In addition, some software applications can, by their nature, only be provided on a subscription basis, especially if the application is no longer available to the user after the subscription expires and is therefore no longer used.
(61) For products with digital elements, when the end of the relevant support period is reached, manufacturers should consider releasing the source code of those products with digital elements either to other companies that commit to an extended provision of vulnerability handling services or to the public so that vulnerabilities can be handled even after the end of the support period. If manufacturers share the source code with other companies, they should be able to protect the ownership of the product with digital elements and prevent the disclosure of the source code to the public, for example through contractual agreements.
(62) In order to ensure that manufacturers across the Union set comparable support periods for comparable products with digital elements, ADCO should publish statistics on the average support periods set by manufacturers for categories of products with digital elements and issue guidelines specifying appropriate support periods for those categories. In addition, in order to ensure a harmonized approach across the internal market, the Commission should be able to adopt delegated acts to set minimum support periods for certain categories of devices where data provided by market surveillance authorities indicate either that the support periods set by manufacturers systematically do not comply with the criteria for setting support periods laid down in this Regulation or indicate that manufacturers from different Member States set unjustifiably different support periods.
(63) Manufacturers should set up a single point of contact that allows users to easily communicate with them, for example to report vulnerabilities of the product with digital elements and to obtain information on these vulnerabilities. They should make the single point of contact easily accessible to users, provide clear information on how to reach them and keep this information up to date. If manufacturers choose to offer automated tools such as chat boxes, they should also provide a phone number or other digital contact options such as an email address or contact form. The single point of contact should not rely solely on automated tools.
(64) Manufacturers should make their products with digital elements available on the market with a secure default configuration and provide users with security updates free of charge. Manufacturers should only be able to derogate from the basic cybersecurity requirements in the case of bespoke products tailored for a specific business user for a specific purpose and where both the manufacturer and the user have explicitly agreed to different contractual terms.
(65) Manufacturers should report actively exploited vulnerabilities in products with digital elements and serious security incidents affecting the security of those products simultaneously to both the designated coordinator Computer Security Incident Response Team (CSIRT) and ENISA via the single reporting platform. The reports should be submitted via the electronic reporting endpoint of a CSIRT designated as coordinator and should be accessible to ENISA at the same time.
(66) Manufacturers should actively report exploited vulnerabilities in order to ensure that the CSIRTs designated as coordinators and ENISA have an adequate overview of those vulnerabilities and receive the information they need to carry out their tasks under Directive (EU) 2022/2555 and to enhance the overall level of cybersecurity of essential and critical entities in accordance with Article 3 of that Directive, and to ensure the effective functioning of market surveillance authorities. As most products with digital elements are marketed throughout the internal market, any exploited vulnerability in a product with digital elements should be considered a threat to the functioning of the internal market. In agreement with the manufacturer, ENISA should disclose remedied vulnerabilities in the European vulnerability database established under Article 12(2) of Directive (EU) 2022/2555. The European vulnerability database will assist manufacturers in identifying known exploitable vulnerabilities in their products to ensure that secure products are made available on the market.
(67) Manufacturers should also notify the CSIRT designated as coordinator and ENISA of any serious security incident affecting the security of a product with digital elements. In order to enable users to react quickly to serious security incidents affecting the security of their products with digital elements, manufacturers should also inform their users of such incidents and, where appropriate, of corrective actions that users can take to mitigate the impact of the incident, for example by publishing relevant information on their websites or, if the manufacturer can contact the users and the cybersecurity risks justify it, by contacting the users directly.
(68) Actively exploited vulnerabilities are cases where a manufacturer discovers that a security breach affecting its users or other natural or legal persons is due to a malicious actor taking advantage of a flaw in one of the products with digital elements provided by the manufacturer on the market. Such vulnerabilities may, for example, be weaknesses in the identification and authentication functions of a product. Vulnerabilities identified without malicious intent during good faith testing, investigation, remediation or disclosure aimed at the security and protection of the system owner and its users should not be reportable. Serious security incidents affecting the security of the product with digital elements, on the other hand, refer to situations where a cybersecurity incident affects the manufacturer’s development, manufacturing or maintenance processes in such a way that it could lead to an increased cybersecurity risk to users or others. These serious security incidents include, for example, the case where an attacker has successfully infiltrated a malicious program into the release channel through which the manufacturer releases security updates to users.
(69) In order to ensure that notifications can be quickly forwarded to all relevant CSIRTs designated as coordinators and that manufacturers have the possibility of individual notification at each stage of the notification process, ENISA should establish a single notification platform with national endpoints for electronic notification. The ongoing operation of the single reporting platform should be managed and maintained by ENISA. The CSIRTs designated as coordinators should inform their respective market surveillance authorities of reported vulnerabilities or security incidents. The single reporting platform should be designed in such a way that the confidentiality of reports is maintained, in particular for vulnerabilities for which a security update is not yet available. In addition, ENISA should establish procedures for the secure and confidential handling of information. On the basis of the information it collects, ENISA should produce a technical report every two years on emerging trends in cybersecurity risks for products with digital elements and submit it to the Cooperation Group established under Article 14 of Directive (EU) 2022/2555.
(70) In exceptional circumstances, and in particular at the request of the manufacturer, the CSIRT designated as coordinator that initially receives the notification should be able to decide to defer the transmission through the single notification platform to the other relevant CSIRTs designated as coordinators, where this can be justified for cybersecurity reasons and for a strictly necessary period of time. The CSIRT designated as coordinator should inform ENISA without delay of the decision to defer and the reasons for it, as well as when it intends to re-deploy. The Commission should, by means of a delegated act, develop technical details on the conditions under which cybersecurity grounds could be invoked and cooperate with the CSIRTs network established under Article 15 of Directive (EU) 2022/2555 and ENISA in the preparation of the draft delegated act. Cybersecurity reasons may include an ongoing coordinated vulnerability disclosure process or situations where a manufacturer is expected to take a mitigation action in the near future and the cybersecurity risks associated with an immediate referral through the single notification platform outweigh the benefits of such referral. At the request of the CSIRT designated as coordinator, ENISA should be able to assist the CSIRT in invoking cybersecurity reasons related to the deferral of the forwarding of the notification on the basis of the information received by ENISA from that CSIRT regarding the decision to defer a notification for those cybersecurity-related reasons. In addition, in particularly exceptional circumstances, ENISA should not receive all the details of a notification of an actively exploited vulnerability at the same time. This would be the case if the manufacturer indicates in its notification that the reported vulnerability has been actively exploited by a malicious actor and that, according to the available information, it has not been exploited in any Member State other than that of the CSIRT designated as coordinator to which the manufacturer has notified the vulnerability, if immediate dissemination of the vulnerability report would be likely to lead to a leak of information the disclosure of which would be contrary to the essential interests of that Member State, or if the reported vulnerability would pose an immediate high cybersecurity risk due to the dissemination. In such cases, ENISA shall only have simultaneous access to the information that the manufacturer has made a notification, to general information on the product with digital elements concerned, to the information on the general nature of the exploitation and to information that these security reasons have been invoked by the manufacturer and that the full content of the notification is therefore withheld. The full notification should be made available to ENISA and other relevant CSIRTs designated as coordinators if the CSIRT designated as coordinator initially receiving the notification determines that those safety grounds reflecting particularly exceptional circumstances within the meaning of this Regulation no longer exist. Where ENISA considers, on the basis of the available information, that there is a systemic risk to the security of the internal market, it should recommend to the CSIRT that received the notification to forward the complete notification to the other CSIRTs designated as coordinators and to ENISA itself.
(71) When manufacturers report an actively exploited vulnerability or a serious security incident affecting the security of the product with digital elements, they should indicate how sensitive they consider the reported information to be. The CSIRT designated as coordinator that initially receives the notification should take this information into account when assessing whether the notification suggests exceptional circumstances that justify deferring the forwarding of the notification to the other relevant CSIRTs designated as coordinators for legitimate cybersecurity reasons. It should also take this information into account when assessing whether the notification of an actively exploited vulnerability suggests particularly exceptional circumstances justifying that the full notification is not made available to ENISA at the same time. In addition, the CSIRTs designated as coordinators should be able to take this information into account when determining appropriate measures to mitigate the risks arising from the relevant vulnerabilities and incidents.
(72) In order to simplify the reporting of information required under this Regulation, taking into account other complementary reporting obligations laid down in Union law, such as Regulation (EU) 2016/679, Regulation (EU) 2022/2554 of the European Parliament and of the Council (25), Directive 2002/58/EC of the European Parliament and of the Council (26) and Directive (EU) 2022/2555, and to reduce the administrative burden on institutions, Member States are encouraged to consider establishing national one-stop-shops for such reporting obligations. The use of such national single points of contact for incident reporting under Regulation (EU) 2016/679 and Directive 2002/58/EC should be without prejudice to the application of the provisions of Regulation (EU) 2016/679 and Directive 2002/58/EC, in particular the provisions on the independence of the authorities referred to therein. When establishing the single reporting platform referred to in this Regulation, ENISA should take into account the possibility that the national electronic reporting endpoints referred to in this Regulation may be integrated into national one-stop-shops, which may also include other reporting required under Union law.
(73) In order to benefit from past experience, ENISA should consult other Union institutions or agencies managing platforms or databases subject to strict security requirements, such as the European Union Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice (eu-LISA), when establishing the single reporting platform referred to in this Regulation. ENISA should also assess possible complementarities with the European vulnerability database established under Article 12(2) of Directive (EU) 2022/2555.
(74) Manufacturers and other natural and legal persons should be able to report on a voluntary basis to a CSIRT designated as coordinator or to ENISA any vulnerability contained in a product with digital elements, cyber threats that could affect the risk profile of a product with digital elements, any security incident affecting the security of the product with digital elements and near misses that could have led to such a security incident.
(75) Member States should address as far as possible the challenges faced by vulnerability researchers, including their potential criminal liability, in accordance with national legislation. As natural and legal persons researching vulnerabilities could be subject to criminal and civil liability in some Member States, Member States are encouraged to adopt guidelines on the non-prosecution of information security researchers and to adopt an exemption from civil liability for their activities.
(76) Manufacturers of products with digital elements should implement coordinated vulnerability disclosure schemes to facilitate the reporting of vulnerabilities by natural or legal persons either directly to the manufacturer or indirectly and anonymously, if requested, through the CSIRTs designated as coordinators for the purposes of coordinated vulnerability disclosure in accordance with Article 12(1) of Directive (EU) 2022/2555. The manufacturers’ approach to coordinated vulnerability disclosure should provide for a structured process in which vulnerabilities are reported to the manufacturer in a way that allows the manufacturer to diagnose and address such vulnerabilities before detailed information about the vulnerability is disclosed to third parties or the public. In addition, manufacturers should also consider publishing their security policies in machine-readable format. Given that information about exploitable vulnerabilities in widely used products with digital elements can fetch high prices on the black market, manufacturers of such products should be able to implement programs as part of their coordinated vulnerability disclosure policies to incentivize vulnerability reporting by ensuring that individuals or entities receive recognition and rewards for their efforts. These are so-called “bug bounty programs”.
(77) To facilitate vulnerability analysis, manufacturers should identify and document which components are included in products with digital elements and, where appropriate, draw up a software bill of materials. A software bill of materials can provide those who manufacture, purchase and operate software with information that helps them better understand the supply chain, which has numerous benefits, particularly helping manufacturers and users to track known emerging vulnerabilities and cybersecurity risks. It is particularly important that manufacturers ensure that their products with digital elements do not contain vulnerable components developed by third parties. Manufacturers should not be required to publish the software bill of materials.
(78) In the context of the new complex business models related to online sales, a company operating online can offer a variety of services. Depending on the nature of the services provided in relation to a specific product with digital elements, the same undertaking may fall into different categories of business models or economic operators. Where an undertaking only provides online intermediation services for a specific product with digital elements and that undertaking is only an online marketplace provider within the meaning of Article 3(14) of Regulation (EU) 2023/988, it shall not fall within any of the categories of economic operators within the meaning of this Regulation. Where an undertaking is an online marketplace provider that also acts as an economic operator within the meaning of this Regulation when selling certain products with digital elements, it should be subject to the obligations laid down for that type of economic operator in this Regulation. For example, if the provider of an online marketplace also sells a product with digital elements, it is considered to be a trader in relation to the sale of that product. Similarly, if the company in question sells its own branded products with digital elements, it would be considered a manufacturer and would therefore have to comply with the requirements applicable to manufacturers. In addition, some companies may be considered fulfillment service providers within the meaning of Article 3(11) of Regulation (EU) 2019/1020 of the European Parliament and of the Council (27) if they offer the relevant services. The cases in question would have to be assessed on a case-by-case basis. Given the prominent role that online marketplaces play in enabling e‑commerce, they should endeavor to cooperate with the market surveillance authorities of the Member States to help ensure that products with digital elements purchased through online marketplaces comply with the cybersecurity requirements laid down in this Regulation.
(79) In order to facilitate the assessment of conformity with the requirements laid down in this Regulation, a presumption of conformity should apply to products incorporating digital elements which are in conformity with harmonized standards transposing the essential cybersecurity requirements laid down in this Regulation into detailed technical specifications adopted in accordance with Regulation (EU) No 1025/2012 of the European Parliament and of the Council (28). That Regulation lays down a procedure for objections to harmonized standards where those standards do not fully meet the requirements laid down in this Regulation. The standardization process should ensure a balanced representation of interests and effective involvement of civil society stakeholders, including consumer organizations. International standards that are consistent with the level of cybersecurity protection sought by the essential cybersecurity requirements laid down in this Regulation should also be taken into account in order to support the development of harmonized standards and the implementation of this Regulation and to facilitate compliance by businesses, in particular micro, small and medium-sized enterprises and globally active enterprises.
(80) The timely development of harmonized standards during the transitional period for the application of this Regulation and their availability before the date of application of this Regulation will be particularly important for its effective implementation. This is particularly the case for important products with Class I digital elements. The availability of harmonized standards will allow manufacturers of the products concerned to carry out conformity assessments through the internal control procedure and may thus help to avoid bottlenecks and delays in the activities of conformity assessment bodies.
(81) Regulation (EU) 2019/881 establishes a voluntary European framework for the cybersecurity certification of ICT products, processes and services. The European cybersecurity certification schemes provide a common framework for user confidence in the use of products with digital elements that fall within the scope of this Regulation. This Regulation should therefore create synergies with Regulation (EU) 2019/881. In order to facilitate the assessment of conformity with the requirements laid down in this Regulation, devices with digital elements that have been certified under a European cybersecurity scheme established by the Commission in an implementing act in accordance with Regulation (EU) 2019/881, or for which a declaration of conformity has been issued under such a scheme, are presumed to comply with the essential cybersecurity requirements laid down in this Regulation, provided that the European cybersecurity certificate or declaration of conformity or parts thereof cover those requirements. The need for new European cybersecurity certification schemes for devices with digital elements should be considered in the light of this Regulation, including in the development of the Union rolling work program under Regulation (EU) 2019/881. Where a new scheme for devices with digital elements is needed, for example to facilitate compliance with this Regulation, the Commission may request ENISA to develop possible schemes in accordance with Article 48 of Regulation (EU) 2019/881. Such future European cybersecurity certification schemes for products with digital elements should take into account the essential cybersecurity requirements and conformity assessment procedures laid down in this Regulation and facilitate compliance with this Regulation. For European cybersecurity certification schemes that enter into force before the entry into force of this Regulation, further specifications may be required on detailed aspects concerning the application of a presumption of conformity. The Commission should be empowered to adopt delegated acts to specify the conditions under which the European cybersecurity certification schemes may be used to demonstrate compliance with the essential cybersecurity requirements laid down in this Regulation. Moreover, in order to avoid an excessive administrative burden, manufacturers should not be obliged to have a third-party conformity assessment carried out for the relevant requirements, as provided for in this Regulation, where a European cybersecurity certificate for at least level ‘medium’ has been issued under such European cybersecurity certification schemes.
(82) Upon the entry into force of Implementing Regulation (EU) 2024/482, which concerns products falling within the scope of this Regulation, such as hardware security modules and microprocessors, the Commission should be able to specify, by means of a delegated act, how the EUCC may confer a presumption of conformity with the essential cybersecurity requirements or parts thereof laid down in this Regulation. In addition, such a delegated act may specify how a certificate issued under the EUCC may waive the obligation for manufacturers under this Regulation to have a third-party assessment carried out for the requirements concerned.
(83) The existing European standardization framework, which is based on the principles of the New Approach as set out in the Council Resolution of 7 May 1985 on a new approach to technical harmonization and standardization and Regulation (EU) No 1025/2012, provides the standard framework for the development of standards providing for a presumption of conformity with the relevant essential cybersecurity requirements laid down in this Regulation. European standards should be market-driven, take into account the public interest and the policy objectives set out in the Commission’s mandate to one or more European standardization bodies to develop harmonized standards within a given deadline, and be based on consensus. However, in the absence of relevant references to harmonized standards, the Commission should be able to adopt implementing acts establishing common specifications for the essential cybersecurity requirements laid down in this Regulation in exceptional cases, as a fallback solution and with due respect for the role and tasks of the European standardization organisations, in order to facilitate the manufacturer’s obligation to comply with those essential cybersecurity requirements where the standardization process is blocked or where there is a delay in the development of appropriate harmonized standards. Where such a delay is due to the technical complexity of the standard concerned, the Commission should take this into account before considering the establishment of common specifications.
(84) In order to be as efficient as possible in defining common specifications covering the essential cybersecurity requirements referred to in this Regulation, the Commission should involve relevant stakeholders in the process.
(85) With regard to the publication of the reference of harmonized standards in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012, a reasonable period means a period during which the reference of the standard, its corrigendum or its amendment is expected to be published in the Official Journal of the European Union and which should not exceed one year after the deadline for the preparation of the draft European standard in accordance with Regulation (EU) No 1025/2012.
(86) In order to facilitate the assessment of conformity with the essential cybersecurity requirements laid down in this Regulation, a presumption of conformity should apply to products incorporating digital elements that comply with the common specifications adopted by the Commission pursuant to this Regulation in order to formulate detailed technical specifications for those requirements.
(87) The use of harmonized standards, common specifications or European cybersecurity certification schemes adopted in accordance with Regulation (EU) 2019/881, which provide a presumption of conformity with the essential cybersecurity requirements for products incorporating digital elements, will facilitate conformity assessment by manufacturers. If the manufacturer chooses not to use these means for certain requirements, he must indicate in his technical documentation how conformity is achieved by other means. In addition, the application of harmonized standards, common specifications or European cybersecurity certification schemes adopted under Regulation (EU) 2019/881 would facilitate the verification of conformity of products with digital elements by market surveillance authorities by conferring a presumption of conformity on manufacturers. Therefore, manufacturers of products with digital elements are encouraged to apply these harmonized standards, common specifications or European cybersecurity certification schemes.
(88) Manufacturers should draw up an EU declaration of conformity to provide the information required under this Regulation on the compliance of the devices with digital elements with the essential cybersecurity requirements laid down in this Regulation and, where applicable, with other relevant Union harmonization legislation to which the device with digital elements is subject. Manufacturers may also be required by other Union acts to draw up an EU declaration of conformity. In order to ensure effective access to information for the purposes of market surveillance, a single EU declaration of conformity should be drawn up in relation to compliance with all relevant Union acts. In order to reduce the administrative burden on economic operators, it should be permissible for that single EU declaration of conformity to consist of a file composed of the relevant individual declarations of conformity.
(89) The CE marking expresses the conformity of a product and is the visible result of a whole process that includes conformity assessment in a broad sense. The general principles governing the CE marking are laid down in Regulation (EC) No 765/2008 of the European Parliament and of the Council (29). The rules for the affixing of the CE marking on products incorporating digital elements should be laid down in this Regulation. The CE marking should be the only marking which guarantees the conformity of products incorporating digital elements with the requirements laid down in this Regulation.
(90) In order to enable economic operators to demonstrate conformity with the essential cybersecurity requirements laid down in this Regulation and to enable market surveillance authorities to ensure that products with digital elements made available on the market comply with those requirements, it is necessary to provide for conformity assessment procedures. Decision No 768/2008/EC of the European Parliament and of the Council (30) lays down modules for conformity assessment procedures proportionate to the level of risk and the level of security required. In order to ensure cross-sectoral consistency and to avoid ad hoc variants, the conformity assessment procedures for checking the compliance of products incorporating digital elements with the essential cybersecurity requirements laid down in this Regulation should be based on those modules. The conformity assessment procedures should examine and verify both product- and process-related requirements covering the whole life cycle of devices incorporating digital elements, including planning, design, development or manufacture, testing and maintenance of the device incorporating digital elements.
(91) Conformity assessment of devices with digital elements that are not listed in this Regulation as essential or critical devices with digital elements may be carried out by the manufacturer under its own responsibility in accordance with the internal control procedure based on Module A of Decision No 768/2008/EC pursuant to this Regulation. This shall also apply in cases where a manufacturer decides not to apply all or part of an applicable harmonized standard, common specification or European cybersecurity certification scheme. The manufacturer remains free to choose a more stringent conformity assessment procedure involving a third party. As part of the conformity assessment carried out in accordance with the internal control procedure, the manufacturer shall ensure and declare, on its own responsibility, that the device with digital elements and the manufacturer’s processes comply with the applicable essential cybersecurity requirements set out in this Regulation. Where a critical device with digital elements falls within Class I, an additional assurance test is required to demonstrate conformity with the essential cybersecurity requirements laid down in this Regulation. The manufacturer should use harmonized standards, common specifications or European cybersecurity certification schemes adopted in accordance with Regulation (EU) 2019/881 and identified by the Commission in an implementing act if it wishes to carry out the conformity assessment under its own responsibility (Module A). If the manufacturer does not use such harmonized standards, common specifications or European schemes for cybersecurity certification, a conformity assessment should be carried out with the involvement of a third party (based on modules B and C or H). Taking into account the administrative burden for manufacturers and the fact that cybersecurity plays an important role in the design and development phase of tangible and intangible products with digital elements, conformity assessment procedures based on Modules B and C or Module H of Decision No 768/2008/EC have been selected as the most appropriate to assess the conformity of critical products with digital elements in a proportionate and effective way. The manufacturer who has the conformity assessment carried out by a third party can choose the procedure that best suits his design and manufacturing process. Given the even greater cybersecurity risk associated with the use of class II critical devices with digital elements, a third party should always be involved in their conformity assessment, even if the device fully or partially complies with harmonized standards, common specifications or European cybersecurity certification schemes. Manufacturers of critical devices with digital elements that are considered free and open source software should be able to apply the internal control procedure based on Module A, provided that they make the technical documentation available to the public.
(92) While the manufacture of physical products with digital elements generally requires a considerable amount of effort throughout the design, development and manufacturing phases, the manufacture of products with digital elements in the form of software focuses almost exclusively on the design and development, whereas the manufacturing phase plays a subordinate role. Nevertheless, software products often still have to be compiled and assembled into versions, packaged, made available for download or copied onto physical data carriers before they are placed on the market. When applying the relevant conformity assessment modules to verify the conformity of the product with the essential cybersecurity requirements laid down in this Regulation in the design, development and manufacturing phases, those activities should be considered as equivalent to the manufacturing process.
(93) With regard to micro and small enterprises, in order to ensure proportionality, it is appropriate to reduce administrative costs without compromising the level of cybersecurity of products with digital elements falling within the scope of this Regulation or the existence of a level playing field between manufacturers. Therefore, the Commission should establish a simplified technical documentation form tailored to the needs of micro and small enterprises. The simplified technical documentation form adopted by the Commission should cover all applicable elements related to technical documentation under this Regulation and indicate how a micro or small enterprise can provide the requested elements in a concise form, such as the description of the design, development and manufacturing of the product with digital elements. In this way, the form would help to reduce the administrative burden of compliance by providing legal certainty to the businesses concerned as to the scope and details of the information to be provided. Micro and small enterprises should have the option to provide the applicable elements related to the technical documentation in a comprehensive form and not to use the simplified technical form available to them.
(94) In order to promote and protect innovation, it is important that the interests of manufacturers that are micro, small or medium-sized enterprises, in particular micro and small enterprises, including start-ups, be given special consideration. To this end, Member States could develop initiatives aimed at manufacturers that are micro or small enterprises, including in the areas of training, awareness-raising, communication of information, testing, third-party conformity assessment and the establishment of living laboratories. Translation costs related to the mandatory documentation, such as technical documentation, and the information and instructions to users required under this Regulation, as well as communication with authorities, can entail significant expenditure for manufacturers, in particular for small manufacturers. Member States should therefore also be able to verify that one of the languages they determine and accept for the relevant documentation of manufacturers and for communication with manufacturers is a language that is widely understood by the largest possible number of users.
(95) In order to ensure the smooth application of this Regulation, Member States should ensure, as far as possible, that there are a sufficient number of notified bodies capable of carrying out third-party conformity assessments before the date of application of this Regulation. The Commission should assist Member States and other relevant parties in this endeavor as far as possible in order to avoid bottlenecks and barriers to market access for manufacturers. Targeted training activities led by the Member States, where appropriate with the support of the Commission, can contribute to the availability of qualified professionals and also support the activities of notified bodies under this Regulation. Furthermore, given the costs that third-party conformity assessment can entail, funding initiatives at Union and national level aimed at reducing those costs for micro and small enterprises should be considered.
(96) In order to ensure proportionality, conformity assessment bodies should take into account the specific interests and needs of micro, small and medium-sized enterprises, including start-ups, when setting the fees for conformity assessment procedures. In particular, conformity assessment bodies should apply the relevant verification procedures and tests provided for in this Regulation only where appropriate and following a risk-based approach.
(97) The objectives of real-world laboratories should be to foster innovation and competitiveness for businesses by creating controlled test environments before products with digital elements are placed on the market. Real-world laboratories should contribute to improving legal certainty for all actors falling within the scope of this Regulation and to facilitating and accelerating the access of products with digital elements to the Union market, in particular when they are provided by micro and small enterprises, including start-ups.
(98) In order to allow products incorporating digital elements to be subject to third-party conformity assessment, national notifying authorities should notify the Commission and the other Member States of conformity assessment bodies provided that they meet a number of requirements, in particular as regards independence, competence and absence of conflicts of interest.
(99) In order to ensure a consistent level of quality in the performance of conformity assessments of products incorporating digital elements, it is also necessary to lay down requirements for notifying authorities and other bodies involved in the assessment, notification and monitoring of notified bodies. The system provided for in this Regulation should be complemented by the accreditation system provided for in Regulation (EC) No 765/2008. Since accreditation is an important means of verifying the competence of conformity assessment bodies, it should also be used for notification purposes.
(100) Conformity assessment bodies accredited and notified under Union law setting out requirements similar to those laid down in this Regulation, such as a conformity assessment body notified for a European cybersecurity certification scheme adopted under Regulation (EU) 2019/881 or under Delegated Regulation (EU) 2022/30, should be reassessed and notified under this Regulation. However, the relevant authorities may define synergies in relation to overlapping requirements in order to avoid unnecessary financial and administrative burden and to ensure a smooth and timely notification process.
(101) Transparent accreditation in accordance with Regulation (EC) No 765/2008, which ensures the necessary level of confidence in certificates of conformity, should be regarded by national authorities throughout the Union as the preferred means of demonstrating the technical competence of conformity assessment bodies. However, national authorities may consider that they have the appropriate means to carry out this assessment themselves. In such cases, in order to ensure the credibility of assessments carried out by other national authorities, they should provide the Commission and the other Member States with all necessary documentary evidence demonstrating that the conformity assessment bodies assessed comply with the relevant legal requirements.
(102) Conformity assessment bodies often subcontract parts of their work related to conformity assessment or delegate it to subsidiaries. In order to maintain the level of protection required for the placing on the market of products with digital elements in the Union, it is essential that subcontractors and subsidiaries meet the same requirements as notified bodies when carrying out conformity assessment tasks.
(103) The notification of a conformity assessment body should be sent by the notifying authority to the Commission and the other Member States via the NANDO (New Approach Notified and Designated Organizations) Information System. The NANDO Information System is the electronic notification tool developed and managed by the Commission to maintain a list of all notified bodies.
(104) Since notified bodies may offer their services throughout the Union, the other Member States and the Commission should be given the opportunity to raise objections against a notified body. It is therefore important to provide for a period during which any doubts or concerns as to the competence of conformity assessment bodies can be clarified before they start operating as notified bodies.
(105) In the interests of competitiveness, it is essential that notified bodies apply the conformity assessment procedures without creating unnecessary burdens for economic operators. For the same reason, and in order to ensure equal treatment of economic operators, a uniform technical application of conformity assessment procedures should be ensured. This can best be achieved through appropriate coordination and cooperation between notified bodies.
(106) Market surveillance is an essential tool to ensure the correct and uniform application of Union law. A legal framework should therefore be established within which market surveillance can be carried out in an appropriate manner. The rules of Regulation (EU) 2019/1020 on Union market surveillance and control of products entering the Union market also apply to products with digital elements that fall within the scope of this Regulation.
(107) Under Regulation (EU) 2019/1020, a market surveillance authority carries out market surveillance on the territory of the Member State that designates it. This Regulation should not prevent Member States from deciding which authorities are competent to carry out market surveillance tasks. Each Member State should designate one or more market surveillance authorities on its territory. Member States should be able to decide to designate an existing or a new authority as market surveillance authority, including the competent authorities designated or designated pursuant to Article 8 of Directive (EU) 2022/2555, the national cybersecurity certification authorities designated pursuant to Article 58 of Regulation (EU) 2019/881 or the market surveillance authorities designated pursuant to Directive 2014/53/EU. Economic operators should cooperate fully with market surveillance authorities and other competent authorities. Each Member State should inform the Commission and the other Member States about its market surveillance authorities and their respective areas of competence and ensure that they have the necessary resources and capabilities to carry out the market surveillance tasks related to this Regulation. In accordance with Article 10(2) and (3) of Regulation (EU) 2019/1020, each Member State should designate a single liaison body which should be responsible, inter alia, for representing the coordinated position of market surveillance authorities and supporting cooperation between market surveillance authorities in different Member States.
(108) With a view to the uniform application of this Regulation, an ADCO on cyber resilience of products with digital elements should be established in accordance with Article 30(2) of Regulation (EU) 2019/1020. The ADCO should be composed of representatives of the designated market surveillance authorities and, where appropriate, representatives of the single liaison offices. The Commission should support and promote cooperation between market surveillance authorities through the Union network on product compliance established under Article 29 of Regulation (EU) 2019/1020, composed of representatives of each Member State, including a representative of each single liaison office referred to in Article 10 of that Regulation and an optional national expert, as well as the chairs of the ADCO and representatives of the Commission. The Commission should participate in the meetings of the Union Product Conformity Network, its sub-groups and the ADCO. It should support the ADCO through an executive secretariat providing technical and logistical support. The ADCO may also invite independent experts to participate and liaise with other ADCOs, such as the one established under Directive 2014/53/EU.
(109) Market surveillance authorities should cooperate closely through the ADCO established under this Regulation and be able to develop guidance documents to facilitate market surveillance activities at national level, for example by developing best practices and indicators to effectively verify the compliance of products incorporating digital elements with this Regulation.
(110) In order to enable timely, proportionate and effective action to be taken in relation to products with digital elements that pose a significant cybersecurity risk, a Union safeguard procedure should be made available to inform interested parties of planned measures in relation to such products. This would allow market surveillance authorities, in cooperation with the relevant economic operators, to intervene at an earlier stage if necessary. Where the Member States and the Commission agree that a measure taken by a Member State is justified, the Commission should only be required to take further action if the non-compliance is due to shortcomings in a harmonized standard.
(111) In certain cases, a product with digital elements that complies with this Regulation may nevertheless pose a significant cybersecurity risk or a risk to the health or safety of persons, to the fulfillment of obligations under Union or national law protecting fundamental rights, to the availability, authenticity, integrity or confidentiality of services provided through an electronic information system by essential entities within the meaning of Article 3(1) of Directive (EU) 2022/2555, or to other aspects of the protection of public interests. It is therefore necessary to lay down rules to ensure the mitigation of such risks. As a consequence, market surveillance authorities should take measures requiring the economic operator, depending on the risk, to ensure that the product no longer presents that risk, to recall it or to withdraw it from the market. As soon as a market surveillance authority restricts or prohibits the free movement of a product with digital elements in this way, the Member State should immediately inform the Commission and the other Member States, giving reasons and justification for the decision. Where a market surveillance authority takes such measures against products incorporating digital elements presenting a risk, the Commission should immediately enter into consultations with the Member States and the relevant economic operator(s) and evaluate the national measure. On the basis of the results of that assessment, the Commission should decide whether the national measure is justified or not. The Commission should address its decision to all Member States and communicate it without delay to them and the relevant economic operator(s). If the measure is considered justified, the Commission should also be able to consider proposals to revise the relevant Union law.
(112) for products with digital elements that pose a significant cybersecurity risk and where there is reason to believe that they do not comply with this Regulation, or for products that comply with this Regulation but pose other significant risks, such as risks to the health or safety of persons, to the fulfillment of obligations under Union or national law for the protection of fundamental rights, or to the availability, authenticity, integrity or confidentiality of services provided through an electronic information system by essential entities within the meaning of Article 3(1) of Directive (EU) 2022/2555, the Commission should be able to request ENISA to carry out an assessment. On the basis of that assessment, the Commission should be able to adopt, by means of implementing acts, corrective or restrictive measures at Union level, including ordering the withdrawal from the market or recall of the affected products with digital elements within a period proportionate to the nature of the risk. Such intervention by the Commission should only be possible in exceptional circumstances that justify immediate intervention to preserve the proper functioning of the internal market and only where the market surveillance authorities have not taken effective action to remedy the situation. Such exceptional circumstances may be emergencies where, for example, a non-compliant product with digital elements is made widely available on the market by the manufacturer in several Member States and is also used in key sectors of entities falling within the scope of Directive (EU) 2022/2555 and has known vulnerabilities that are exploited by malicious actors and for which the manufacturer does not provide available patches. The Commission should be able to intervene in such emergencies only for the duration of the exceptional circumstances and only for as long as the non-compliance with this Regulation or the high risks persist.
(113) Where there is evidence of non-compliance with this Regulation in several Member States, market surveillance authorities should be able to carry out joint activities with other authorities to verify compliance and identify cybersecurity risks of products with digital elements.
(114) Simultaneous coordinated controls (“sweeps”) are specific enforcement actions carried out by market surveillance authorities that can further improve product safety. Sweeps should be carried out in particular when market developments, consumer complaints or other indications suggest that certain categories of products with digital elements often present cybersecurity risks. In addition, market surveillance authorities should also take into account circumstances related to non-technical risk factors when determining the categories of products to be swept. To that end, market surveillance authorities should be able to take into account the results of the coordinated risk assessments carried out in accordance with Article 22 of Directive (EU) 2022/2555 in relation to the security of critical supply chains at Union level, including circumstances related to non-technical risk factors. ENISA should submit proposals to market surveillance authorities for categories of products with digital elements for which sweeps could be organized, including on the basis of vulnerability and security incident notifications received by ENISA.
(115) Given its expertise and mandate, ENISA should be able to support the process of implementation of this Regulation. In particular, ENISA should be able to propose joint activities to be carried out by market surveillance authorities on the basis of indications or information on possible non-compliance of products with digital elements with this Regulation in several Member States or to identify categories of products for which sweeps should be organized. In exceptional circumstances, ENISA should be able, at the request of the Commission, to carry out assessments in relation to specific products with digital elements that pose a significant cybersecurity risk, where immediate intervention is necessary to preserve the smooth functioning of the internal market.
(116) This Regulation entrusts ENISA with certain tasks that require adequate resources, both in terms of expertise and human resources, in order to enable ENISA to carry out those tasks effectively. When preparing the draft general budget of the Union, the Commission will propose the necessary budgetary resources for ENISA’s establishment plan in accordance with the procedure laid down in Article 29 of Regulation (EU) 2019/881. During that process, the Commission shall take into account the overall resources of ENISA to enable it to carry out its tasks, including those conferred on it under this Regulation.
(117) In order to adapt the regulatory framework where necessary, the power to adopt acts in accordance with Article 290 of the Treaty on the Functioning of the European Union (TFEU) should be delegated to the Commission in respect of updating the list of essential products with digital elements and their inclusion in the Annex to this Regulation. The power to adopt acts in accordance with that Article should be delegated to the Commission in respect of identifying products with digital elements covered by other Union legislation providing for the same level of protection as this Regulation, determining whether a restriction or exclusion from the scope of this Regulation would be necessary and, where appropriate, defining the scope of that restriction. The power to adopt acts in accordance with that Article should also be delegated to the Commission in respect of requiring, where appropriate, the certification of critical products with digital elements set out in an Annex to this Regulation under a European cybersecurity certification scheme, to update the list of critical products with digital elements on the basis of the criticality criteria set out in this Regulation and to specify the European cybersecurity certification schemes adopted pursuant to Regulation (EU) 2019/881 that may be used to demonstrate compliance with the essential cybersecurity requirements or parts thereof set out in an Annex to this Regulation. The power to adopt acts should also be delegated to the Commission in respect of determining the minimum period of support for certain categories of products where market surveillance data indicate insufficient support periods and in respect of determining the terms and conditions for the application of the grounds relating to cybersecurity risk where there is a delay in the disclosure of reports of actively exploited vulnerabilities. In addition, the power to adopt acts should be delegated to the Commission in respect of establishing voluntary security attestation schemes to assess the compliance of products containing digital items that qualify as free and open source software with all or certain essential cybersecurity requirements or other obligations set out in this Regulation, as well as to prescribe the minimum information to be included in the EU declaration of conformity and to supplement the elements to be included in the technical documentation. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making (31). In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts. The power to adopt delegated acts in accordance with this Regulation is conferred on the Commission for a period of five years from 10 December 2024. The Commission should draw up a report in respect of the delegation of power not later than nine months before the end of the five-year period. The delegation of power should be tacitly extended for periods of an identical duration, unless the European Parliament or the Council opposes such extension not later than three months before the end of each period.
(118) In order to ensure uniform conditions for the implementation of this Regulation, implementing powers should be conferred on the Commission in respect of the following: specifying the technical description of the categories of critical products with digital elements listed in an Annex to this Regulation, specifying the format and elements of the software BOM, specifying the format and procedure of notifications of actively exploited vulnerabilities and serious security incidents affecting the security of products with digital elements as submitted by manufacturers, specifying common specifications for technical requirements to meet the essential cybersecurity requirements set out in an Annex to this Regulation, specifying technical specifications for labels, pictograms or other markings relating to the security of products with digital elements and their support period and mechanisms to promote their use and to raise public awareness of the security of products with digital elements, establishing the simplified form for documentation tailored to the needs of micro and small enterprises, and deciding on corrective or restrictive measures at Union level in exceptional circumstances that justify immediate intervention in order to preserve the smooth functioning of the internal market. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and of the Council (32).
(119) In order to ensure trustful and constructive cooperation between market surveillance authorities at Union and Member State level, all parties involved in the application of this Regulation should respect the confidentiality of information and data obtained in the course of carrying out their activities.
(120) In order to ensure the effective enforcement of the obligations laid down in this Regulation, each market surveillance authority should have the power to impose or request the imposition of fines. It is therefore also appropriate to set upper limits for fines to be provided for in national law for infringements of the obligations laid down in this Regulation. When deciding on the amount of the fine, account should be taken in each individual case of all relevant circumstances of the specific situation and at least of the circumstances explicitly set out in this Regulation, including whether the manufacturer is a microenterprise or a small or medium-sized enterprise, including a start-up, and whether the same market surveillance authority or other market surveillance authorities have already imposed fines on the same economic operator for a similar infringement. Such circumstances could either be aggravating, if the infringement by the same economic operator continues on the territory of a Member State other than the one where a fine has already been imposed, or mitigating, by ensuring that sanctions imposed in other Member States and their amount, as well as other relevant concrete circumstances, are taken into account when another market surveillance authority is considering a further fine for the same economic operator or the same type of infringement. In any event, the total amount of fines that market surveillance authorities of several Member States could impose on the same economic operator for the same type of infringements should comply with the principle of proportionality. Since fines are not imposed on microenterprises or small enterprises for non-compliance with the 24-hour early notification period for actively exploited vulnerabilities or serious security incidents affecting the security of the product with digital elements, nor on administrators of open source software for infringements of this Regulation, and subject to the principle that penalties should be effective, proportionate and dissuasive, Member States should not impose any other financial penalties on those entities.
(121) Where fines are imposed on a person other than an undertaking, the competent authority should take into account the general level of income in the Member State concerned and the economic situation of the persons when setting the fine. Member States should be able to determine whether and to what extent fines can be imposed on public authorities.
(122) Member States should consider, taking into account national circumstances, whether the revenues from the penalties provided for in this Regulation or equivalent revenues can be used to support cybersecurity policies and improve the level of cybersecurity in the Union, including by increasing the number of qualified cybersecurity professionals, strengthening capacity building for micro, small and medium-sized enterprises and raising public awareness of cyber threats.
(123) In its relations with third countries, the Union aims to promote international trade in regulated products. A range of measures can be used to facilitate trade, including various legal instruments such as bilateral (intergovernmental) Mutual Recognition Agreements (MRAs) on conformity assessment and labeling of regulated products. Mutual Recognition Agreements are concluded between the Union and third countries that are at a comparable level of technical development and whose approach to conformity assessment is considered compatible. These agreements are based on the mutual recognition of certificates, marks of conformity and test reports issued by the conformity assessment bodies of the Parties in accordance with each other’s legislation. Such mutual recognition agreements currently exist with several third countries. These agreements are concluded for a number of specific sectors, which may differ from one third country to another. In order to further facilitate trade and recognizing that the supply chains for products with digital elements are global, the Union may conclude mutual recognition agreements on conformity assessment for products covered by this Regulation in accordance with Article 218 TFEU. It is also important to cooperate with partner countries to strengthen global resilience against cyber-attacks, as this will contribute to a stronger cybersecurity framework both inside and outside the Union in the long term.
(124) Consumers should be able to enforce their rights in relation to the obligations applicable to economic operators under this Regulation by means of representative actions in accordance with Directive (EU) 2020/1828 of the European Parliament and of the Council (33). To that end, this Regulation should provide that Directive (EU) 2020/1828 applies to representative actions for infringements of this Regulation that harm or are likely to harm the collective interests of consumers. Consequently, Annex I to that Directive should be amended accordingly. It is for Member States to ensure that those amendments are reflected in the transposition measures they adopt pursuant to that Directive, although the adoption of national transposition measures in this respect is not a precondition for the application of that Directive to such representative actions. That Directive should apply from 11 December 2027 to representative actions brought for infringements by economic operators of provisions of this Regulation that harm or are likely to harm the collective interests of consumers.
(125) The Commission should regularly assess and review this Regulation in consultation with relevant stakeholders, in particular to determine whether it needs to be adapted to changing social, political, technical or market conditions. This Regulation facilitates compliance with supply chain security obligations by entities falling within the scope of Regulation (EU) 2022/2554 and Directive (EU) 2022/2555 that use products with digital elements. The Commission should assess the combined impact of the Union cybersecurity framework as part of that periodic review.
(126) Economic operators should be given sufficient time to adapt to the requirements laid down in this Regulation. This Regulation should apply from 11 December 2027, with the exception of the notification requirements for actively exploited vulnerabilities and serious security incidents affecting the security of products with digital elements, which should apply from 11 September 2026, and the provisions on the notification of conformity assessment bodies, which should apply from 11 June 2026.
(127) It is important to support micro, small and medium-sized enterprises, including start-ups, in the implementation of this Regulation and to minimize the risks to implementation arising from a lack of knowledge and expertise in the market and to facilitate manufacturers’ compliance with their obligations under this Regulation. The Digital Europe Program and other relevant Union programs provide financial and technical support to enable those companies to contribute to the growth of the Union economy and to the strengthening of the common level of cybersecurity in the Union. The European Cybersecurity Research Competence Center and the National Coordination Centers as well as the European Digital Innovation Hubs established by the Commission and the Member States at Union or national level could also support businesses and public sector entities and contribute to the implementation of this Regulation. Within their respective roles and responsibilities, they could provide technical and scientific support to micro, small and medium-sized enterprises, for example in testing activities and third-party conformity assessments. They could also promote the use of tools to facilitate the implementation of this Regulation.
(128) Member States should also consider taking complementary measures aimed at providing guidance and support to micro, small and medium-sized enterprises, including through the establishment of living labs and targeted communication channels. In order to strengthen the level of cybersecurity in the Union, Member States may also consider supporting the development of capacities and competences related to the cybersecurity of products with digital elements, improving the resilience of economic operators against cyber-attacks, in particular when it comes to micro, small and medium-sized enterprises, and raising public awareness on the cybersecurity of products with digital elements.
(129) Since the objective of this Regulation cannot be sufficiently achieved by the Member States but can rather, by reason of the effects of the action, be better achieved at Union level, the Union may adopt measures, in accordance with the principle of subsidiarity as set out in Article 5 of the Treaty on European Union. In accordance with the principle of proportionality, as set out in that Article, this Regulation does not go beyond what is necessary in order to achieve that objective.
(130) The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 of the European Parliament and of the Council (34) and delivered an opinion on November 9, 2022 (35).
Chapter I General provisions
Article 1 Object
This Regulation lays down the following:
a) Regulations for the provision on the market of products with digital elements to ensure the cybersecurity of such products;
b) basic cybersecurity requirements for the design, development and manufacture of products with digital elements and the obligations of economic operators in relation to these products with regard to cybersecurity;
c) basic cybersecurity requirements for the vulnerability handling procedures established by manufacturers to ensure the cybersecurity of products with digital elements during the expected lifetime of the products, and obligations of economic operators in relation to those procedures;
d) rules for market surveillance, including monitoring, and enforcement of the rules and requirements referred to in this Article.
Article 2 Scope of application
(1) This Regulation applies to products made available on the market with digital elements whose intended purpose or reasonably foreseeable use involves a direct or indirect logical or physical data connection to a device or network.
(2) This Regulation shall not apply to products with digital elements to which the following Union acts apply:
a) Regulation (EU) 2017/745,
b) Regulation (EU) 2017/746,
c) Regulation (EU) 2019/2144.
(3) This Regulation shall not apply to products with digital elements that have been certified in accordance with Regulation (EU) 2018/1139.
(4) This Regulation shall not apply to devices falling within the scope of Directive 2014/90/EU of the European Parliament and of the Council (36).
(5) The application of this Regulation to devices with digital elements covered by other Union legislation with requirements for all or some of the risks covered by the essential cybersecurity requirements set out in Annex I may be limited or excluded where
a) such restriction or exclusion is compatible with the general legal framework applicable to these products, and
b) the sector-specific rules achieve the same level of protection as guaranteed by this Regulation or a higher level.
The Commission shall be empowered to adopt delegated acts in accordance with Article 61 to supplement this Regulation by determining the need for such restriction or exclusion and, where appropriate, by specifying the products and rules concerned and the scope of the restriction.
(6) This Regulation shall not apply to spare parts which are made available on the market to replace identical components in products with digital elements and which are manufactured to the same specifications as the components they are intended to replace.
(7) This Regulation shall not apply to products with digital elements designed or modified exclusively for national security or defense purposes, or to products specifically designed for the processing of classified information.
(8) The obligations laid down in this Regulation shall not include the provision of information the disclosure of which would be contrary to the essential interests of Member States in the area of national security, public security or defense.
Article 3 Definitions
For the purposes of this Regulation, the following definitions shall apply
1.‘product with digital elements’ means a software or hardware product and its remote computing solutions, including software or hardware components, which are placed on the market separately;
2.“Remote data processing” means remote data processing for which software is designed and developed by the manufacturer itself or under its responsibility and without which the product with digital elements could not fulfill one of its functions;
3.‘cybersecurity’ means cybersecurity as defined in Article 2(1) of Regulation (EU) 2019/881
4.“Software” means the part of an electronic information system that consists of computer code;
5.‘hardware’ means a physical electronic information system capable of processing, storing or transmitting digital data, or parts of such a system;
6.“Component” means software or hardware intended for integration into an electronic information system;
7.‘electronic information system’ means a system, including electrical or electronic equipment, capable of processing, storing or transmitting digital data
8.“logical connection” means a virtual representation of a data connection that is established via a software interface;
9.‘physical connection’ means a connection between electronic information systems or components established by physical means such as electrical, optical or mechanical interfaces, wires or radio waves;
10.“indirect connection” means a connection to a device or network that is not made directly, but as part of a larger system that can in turn be connected directly to that device or network;
11.“Endpoint” means a device that is connected to a network and serves as an access point to this network;
12.‘economic operator’ means the manufacturer, the authorized representative, the importer, the distributor or any other natural or legal person who is subject to obligations in relation to the manufacture of products incorporating digital elements or the making available on the market of products incorporating digital elements in accordance with this Regulation;
13.“Manufacturer” means a natural or legal person who develops or manufactures products with digital elements or who has products with digital elements designed, developed or manufactured and markets them under their name or brand, whether for payment, monetization or free of charge;
14.‘open source software manager’ means a legal entity, other than a manufacturer, which has the purpose or objective of systematically and sustainably supporting the development of specific products with digital elements that are considered free and open source software and are intended for commercial activities, and which ensures the usability of these products;
15.‘authorized representative’ means a natural or legal person resident or established in the Union who has received a written mandate from a manufacturer to act on his behalf in relation to specific tasks
16.‘importer’ means a natural or legal person resident or established in the Union who places a product incorporating digital elements on the market in the Union under the name or trademark of a natural or legal person resident or established outside the Union;
17.‘distributor’ means a natural or legal person in the supply chain, other than the manufacturer or the importer, who makes a product with digital elements available on the Union market without modifying its characteristics;
18.“Consumer” means a natural person who is acting for purposes which are outside his trade, business, craft or profession;
19.“microenterprises”, “small enterprises” and “medium-sized enterprises” microenterprises, small enterprises and medium-sized enterprises respectively as defined in the Annex to Recommendation 2003/361/EC;
20.’support period’ means the period during which the manufacturer shall ensure that the vulnerabilities of the product with digital elements are effectively addressed in accordance with the essential cybersecurity requirements set out in Part II of Annex I;
21.“Placing on the market” means the first making available of a product with digital elements on the Union market;
22.‘making available on the market’ means the supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge;
23.“Intended use” means the use for which a product with digital elements is intended according to the manufacturer, including the specific circumstances of use and conditions of use as specified by the manufacturer in the instructions for use, in advertising or sales material and in declarations as well as in the technical documentation;
24.“reasonably foreseeable use” means a use which does not necessarily correspond to the intended purpose stated by the manufacturer in the instructions for use, in advertising or sales material and in declarations and technical documentation, but which is likely to result from reasonably foreseeable human behavior or from technical processes or interactions;
25.“reasonably foreseeable misuse” means the use of a product with digital elements in a manner inconsistent with its intended purpose, but which may result from reasonably foreseeable human behavior or reasonably foreseeable interaction with other systems;
26.’notifying authority’ means the national authority responsible for setting up, carrying out and monitoring the necessary procedures for the assessment, designation and notification of conformity assessment bodies;
27.‘conformity assessment’ means the process of verifying compliance with the essential cybersecurity requirements set out in Annex I
28.‘conformity assessment body’ means a conformity assessment body as defined in point 13 of Article 2 of Regulation (EC) No 765/2008.
29.’notified body’ means a conformity assessment body designated in accordance with Article 43 of this Regulation and other relevant Union harmonization legislation;
30.’substantial change’ means a change to the product with digital elements after it has been placed on the market that affects the conformity of the product with the essential cybersecurity requirements set out in Part I of Annex I or leads to a change in the intended purpose for which the product has been tested;
31.‘CE marking’ means a marking by which a manufacturer declares that a device incorporating digital elements and the procedures specified by the manufacturer meet the essential cybersecurity requirements set out in Annex I and other applicable Union harmonization legislation providing for its affixing;
32.‘Union harmonization legislation’ means the Union legislation listed in Annex I to Regulation (EU) 2019/1020 and any other Union legislation harmonizing the conditions for the marketing of products to which that Regulation applies;
33.‘market surveillance authority’ means a market surveillance authority as defined in Article 3(4) of Regulation (EU) 2019/1020
34.‘international standard’ means an international standard as defined in Article 2(1)(a) of Regulation (EU) No 1025/2012
35.‘European standard’ means a European standard as defined in Article 2(1)(b) of Regulation (EU) No 1025/2012;
36.‘harmonized standard’ means a harmonized standard as defined in Article 2(1)(c) of Regulation (EU) No 1025/2012
37.“cybersecurity risk” means the potential for loss or disruption caused by a security incident, expressed as a combination of the magnitude of such loss or disruption and the likelihood of the security incident occurring;
38.“significant cybersecurity risk” means a cybersecurity risk that, due to its technical characteristics, is likely to lead to a security incident that could have a serious negative impact and cause significant material or immaterial loss or disruption;
39.’software bill of materials’ means a formal record of the details and supply chain relationships of the components contained in the software elements of a product with digital elements;
40.“Vulnerability” means a weakness, susceptibility or malfunction of a product with digital elements that can be exploited in the event of a cyber threat;
41.“exploitable vulnerability” means a vulnerability that can be effectively exploited by an unauthorized third party under practical operating conditions;
42.“actively exploited vulnerability” means a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without the consent of the system owner;
43.’security incident’ means a security incident as defined in Article 6(6) of Directive (EU) 2022/2555;
44.“security incident affecting the security of the product with digital elements” means a security incident that has or may have a negative impact on the ability of a product with digital elements to protect the availability, authenticity, integrity or confidentiality of data or functionality;
45.’near-miss incident’ means a near-miss incident as defined in Article 6(5) of Directive (EU) 2022/2555;
46.“cyber threat” means a cyber threat as defined in Article 2(8) of Regulation (EU) 2019/881
47.‘personal data’ means personal data as defined in Article 4(1) of Regulation (EU) 2016/679;
48.“free and open source software” means software whose source code is openly shared and which is made available under a free open source license that provides all rights to make it freely accessible, usable, modifiable and redistributable;
49.‘recall’ means a recall as defined in point 22 of Article 3 of Regulation (EU) 2019/1020
50.“withdrawal from the market” means withdrawal from the market as defined in Article 3(23) of Regulation (EU) 2019/1020;
51.‘CSIRT designated as coordinator’ means a CSIRT designated as coordinator in accordance with Article 12(1) of Directive (EU) 2022/2555
Article 4 Free movement
(1) Member States shall not impede the making available on the market of products with digital elements that comply with this Regulation in the respects covered by this Regulation.
(2) Member States shall not prevent the presentation or use of a product with digital elements that does not comply with this Regulation at trade fairs, exhibitions, demonstrations or similar events, including prototypes, provided that the product is visibly marked to indicate clearly that it does not comply with this Regulation and may not be made available on the market until it does so.
(3) Member States shall not prevent the making available on the market of unfinished software which does not comply with this Regulation, provided that the software is made available only for a limited period necessary for testing purposes and clearly indicates with a visible marking that it does not comply with this Regulation and will not be available on the market except for testing purposes.
(4) Paragraph 3 shall not apply to safety components covered by Union harmonization legislation other than this Regulation.
Article 5 Procurement or use of products with digital elements
(1) This Regulation shall not prevent Member States from imposing additional cybersecurity requirements on products incorporating digital elements when procuring or using those products for specific purposes, including where those products are procured or used for national security or defense purposes, provided that those requirements are consistent with Member States’ obligations under Union law and are necessary and proportionate to achieve those purposes.
(2) Without prejudice to Directives 2014/24/EU and 2014/25/EU, when procuring products with digital elements falling within the scope of this Regulation, Member States shall ensure that compliance with the essential cybersecurity requirements set out in Annex I to this Regulation, including the ability of manufacturers to effectively manage vulnerabilities, is taken into account in the procurement procedure.
Article 6 Requirements for products with digital elements
Products with digital elements are only made available on the market if
a) they meet the essential cybersecurity requirements set out in Part I of Annex I and on condition that they are properly installed, maintained and used as intended or under reasonably foreseeable circumstances and, where applicable, the necessary security updates have been installed; and
b) the procedures defined by the manufacturer comply with the essential cybersecurity requirements set out in Annex I, Part II.
Article 7 Important products with digital elements
(1) Devices incorporating digital elements that perform the core functions of a product category listed in Annex III shall be considered as essential devices incorporating digital elements and shall be subject to the conformity assessment procedures referred to in Article 32(2) and (3). The integration of a device incorporating digital elements that has the core functionality of a product category listed in Annex III shall not in itself make the product into which it is integrated subject to the conformity assessment procedures referred to in Article 32(2) and (3).
(2) The categories of devices with digital elements referred to in paragraph 1 of this Article, divided into classes I and II in accordance with Annex III, shall meet at least one of the following criteria:
a) The digital element product primarily performs functions that are critical to the cybersecurity of other products, networks or services, including securing authentication and access, intrusion prevention and detection, endpoint security or network protection;
b) the product with digital elements performs a function that presents a significant risk of adverse effects in terms of its intensity and ability to disrupt, control or harm a large number of other products or the health, safety or security of its users through direct manipulation, such as a key system function, including network management, configuration control, virtualization or personal data processing.
(3) The Commission shall be empowered to adopt delegated acts in accordance with Article 61 to amend Annex III in order to add a new category to the list within each class of categories of devices incorporating digital elements and to clarify its definition, to move a category of devices from one class to another or to remove an existing category from that list. When assessing the need to amend the list in Annex III, the Commission shall take into account the cybersecurity-related functions or the function and the level of cybersecurity risk posed by devices incorporating digital elements in accordance with the criteria set out in paragraph 2 of this Article.
The delegated acts referred to in the first subparagraph shall, where appropriate, provide for a transitional period of at least 12 months, in particular where a new category of class I or class II essential devices with digital elements referred to in Annex III is added or moved from class I to class II, before the relevant conformity assessment procedures referred to in Article 32(2) and (3) are applied, unless a shorter transitional period is justified on imperative grounds of urgency.
(4) By 11 December 2025, the Commission shall adopt an implementing act laying down the technical description of the categories of devices with digital elements falling within Classes I and II set out in Annex III and the technical description of the categories of devices with digital elements set out in Annex IV. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 62(2).
Article 8 Critical products with digital elements
(1) The Commission shall be empowered to adopt delegated acts in accordance with Article 61 supplementing this Regulation to specify which devices with digital elements that have the core functionality of a product category listed in Annex IV to this Regulation are to be granted a European cybersecurity certificate of at least assurance level ‘medium’ under a European cybersecurity certification scheme adopted pursuant to Regulation (EU) 2019/881, to demonstrate conformity with the essential cybersecurity requirements set out in Annex I to this Regulation or parts thereof, provided that a European cybersecurity certification scheme for those categories of products with digital elements has been adopted in accordance with Regulation (EU) 2019/881 and is available to manufacturers. Those delegated acts shall specify the required assurance level, which shall be proportionate to the level of cybersecurity risk associated with products with digital elements and shall take into account their intended purpose, including the critical dependency on them by essential entities as referred to in Article 3(1) of Directive (EU) 2022/2555.
Before adopting such delegated acts, the Commission shall carry out an assessment of the potential impact of the envisaged measures on the market and consult the relevant stakeholders, including the European Cybersecurity Certification Group established by Regulation (EU) 2019/881. The assessment shall take into account the readiness and capacity of Member States to implement the relevant European cybersecurity certification scheme. Where no delegated acts have been adopted pursuant to the first subparagraph, devices incorporating digital elements and having core functionality of a device category set out in Annex IV shall be subject to the conformity assessment procedures referred to in Article 32(3). The delegated acts referred to in the first subparagraph shall provide for a transitional period of at least six months, unless a shorter transitional period is justified on imperative grounds of urgency.
(2) The Commission shall be empowered to adopt delegated acts in accordance with Article 61 to amend Annex IV in order to add or remove categories of critical products incorporating digital elements. When determining such categories of critical products with digital elements and the required assurance level referred to in paragraph 1, the Commission shall take into account the criteria referred to in Article 7(2) and shall ensure that the category of products with digital elements complies with at least one of the following criteria:
a) There is a critical dependency of essential facilities according to Article 3 of Directive (EU) 2022/2555 on the category of products with digital elements;
b) Security incidents and exploited vulnerabilities relating to the category of products with digital elements could lead to serious disruptions to critical supply chains across the single market.
Before adopting such delegated acts, the Commission shall carry out an evaluation of the type referred to in paragraph 1. The delegated acts referred to in the first subparagraph shall provide for a transitional period of at least six months, unless a shorter transitional period is justified on imperative grounds of urgency.
Article 9 Consultation of stakeholders
(1) When preparing measures for the implementation of this Regulation, the Commission shall consult and take into account the views of relevant stakeholders, such as relevant Member State authorities, private sector entities, including micro, small and medium-sized enterprises, the open source software community, consumer associations, academia and relevant Union agencies and bodies, as well as expert groups established at Union level. In particular, the Commission shall, where appropriate, consult those stakeholders and seek their views in the following structured manner:
a) in drawing up the guidelines referred to in Article 26;
b) without prejudice to Article 61, when preparing the technical descriptions of the product categories listed in Annex III in accordance with Article 7(4), when assessing the need to update the list of product categories in accordance with Article 7(3) and Article 8(2), or when carrying out the assessment of the potential impact on the market in accordance with Article 8(1);
c) in carrying out preparatory work for the evaluation and review of this Regulation.
(2) The Commission shall organize regular consultation and information meetings, at least once a year, to obtain the views of the stakeholders referred to in paragraph 1 on the implementation of this Regulation.
Article 10 Enhancing skills in a digital environment with cyber defense capability
For the purposes of this Regulation and in order to meet the needs of professionals in supporting the implementation of this Regulation, Member States, with the support of the Commission, the European Cybersecurity Competence Center and ENISA, as appropriate, shall promote actions and policies aimed at the following, in full respect of the responsibilities of the Member States in the field of education:
a) Develop cybersecurity skills and create organizational and technological tools to ensure sufficient availability of qualified professionals to support the activities of market surveillance authorities and conformity assessment bodies;
b) Strengthen cooperation between the private sector and economic actors, including through retraining or upskilling of employees of manufacturers, consumers, training institutions and public administrations, in order to provide more opportunities for young people to access jobs in the cybersecurity sector.
Article 11 General product safety
By way of derogation from point (b) of the third subparagraph of Article 2(1) of Regulation (EU) 2023/988, Section 1 of Chapter III, Chapters V and VII and Chapters IX to XI of that Regulation shall apply to devices with digital elements relating to aspects and risks or risk categories not covered by this Regulation, provided that those devices are not subject to specific safety requirements laid down in other ‘Union harmonization legislation’ within the meaning of point (27) of Article 3 of Regulation (EU) 2023/988.
Article 12 High-risk AI systems
(1) Without prejudice to the accuracy and robustness requirements laid down in Article 15 of Regulation (EU) 2024/1689, products with digital elements that fall within the scope of this Regulation and that are classified as high-risk AI-systems in accordance with Article 6 of that Regulation shall be deemed to comply with the cybersecurity requirements laid down in Article 15 of that Regulation if
a) these products meet the essential cybersecurity requirements set out in Annex I, Part I;
b) the procedures defined by the manufacturer comply with the essential cybersecurity requirements set out in Part II of Annex I, and
c) the achievement of the cybersecurity level required under Article 15 of Regulation (EU) 2024/1689 is demonstrated in the EU declaration of conformity issued in accordance with this Regulation.
(2) The relevant conformity assessment procedure provided for in Article 43 of Regulation (EU) 2024/1689 shall apply to the devices with digital elements and cybersecurity requirements referred to in paragraph 1. For the purposes of this assessment, the notified bodies responsible for checking the conformity of high-risk AI-systems under Regulation (EU) 2024/1689 shall also be responsible for checking, under this Regulation, the conformity of high-risk AI-systems with the requirements set out in Annex I to this Regulation, provided that the notification procedure carried out under Regulation (EU) 2024/1689 has verified that those notified bodies meet the requirements set out in Article 39 of this Regulation.
(3) By way of derogation from paragraph 2 of this Article, critical devices with digital elements listed in Annex III to this Regulation that are subject to the conformity assessment procedures referred to in points (a) and (b) of Article 32(2) and Article 32(3) of this Regulation and critical devices with digital elements listed in Annex IV to this Regulation that are required to obtain a European cybersecurity certificate in accordance with Article 8(1) of this Regulation or, in the absence of such a certificate, that are subject to the conformity assessment procedures referred to in Article 32(3) of this Regulation shall be subject to the conformity assessment procedures referred to in Article 32(3) of this Regulation, and are also classified as high-risk AI-systems in accordance with Article 6 of Regulation (EU) 2024/1689 and to which the conformity assessment procedure based on internal control set out in Annex VI to Regulation (EU) 2024/1689 applies, are subject to the conformity assessment procedures provided for in this Regulation as far as the essential cybersecurity requirements laid down in this Regulation are concerned.
(4) Manufacturers of products with digital elements referred to in paragraph 1 may participate in the AI laboratories referred to in Article 57 of Regulation (EU) 2024/1689.
Chapter II Obligations of economic operators and provisions relating to free and open source software
Article 13 Obligations of producers
(1) When placing a device with digital elements on the market, manufacturers shall ensure that the device has been designed, developed and manufactured in accordance with the essential cybersecurity requirements set out in Part I of Annex I.
(2) For the purposes of complying with paragraph 1, manufacturers shall carry out an assessment of the cybersecurity risks posed by a device with digital elements and shall take the outcome of that assessment into account in the planning, design, development, manufacturing, supply and maintenance phases of the device with digital elements in order to minimize cybersecurity risks, prevent security incidents and minimize the impact of such incidents, including on the health and safety of users.
(3) The cybersecurity risk assessment shall be documented and, where appropriate, updated during a support period to be determined in accordance with paragraph 8. That cybersecurity risk assessment shall include at least a cybersecurity risk analysis based on the intended purpose and reasonably foreseeable use of the device with digital elements, such as the operating environment or the assets to be protected, taking into account the expected lifetime of the device. The cybersecurity risk assessment shall indicate whether and, if so, how the security requirements set out in point 2 of Part I of Annex I are applicable to the relevant device with digital elements and how those requirements are implemented on the basis of the cybersecurity risk assessment. It shall also indicate how the manufacturer shall apply point 1 of Part I of Annex I and the requirements for the management of vulnerabilities set out in Part II of Annex I.
(4) When placing a device with digital elements on the market, the manufacturer shall include the cybersecurity risk assessment referred to in paragraph 3 in the technical documentation required pursuant to Article 31 and Annex VII. For devices with digital elements referred to in Article 12 that are also subject to other Union legislation, the cybersecurity risk assessment may also be part of the risk assessments required by that Union legislation. Where certain essential cybersecurity requirements are not applicable to the device with digital elements, the manufacturer shall include a clear justification in that technical documentation.
(5) For the purposes of fulfilling the obligation laid down in paragraph 1, manufacturers shall exercise due care when integrating components obtained from third parties into their devices incorporating digital items, so that such components do not compromise the cybersecurity of the device incorporating digital items, including when integrating free and open source software that has not been made available on the market in the course of a commercial activity.
(6) As soon as the manufacturer identifies a vulnerability in a component, including an open source component, incorporated in the device with digital elements, it shall notify the vulnerability to the person or entity that manufactures or maintains that component and shall address and remediate the vulnerability in accordance with the vulnerability management requirements set out in Part II of Annex I. Where manufacturers have developed a software or hardware modification to address the vulnerability in that component, they shall communicate the relevant code or documentation to the person or entity that manufactures or maintains the component in a machine-readable format, as appropriate.
(7) The manufacturer shall systematically document, in a manner appropriate to the nature of the cybersecurity risks, all relevant cybersecurity aspects of the device with digital elements, including vulnerabilities of which it becomes aware and any relevant information provided by third parties, and update the cybersecurity risk assessment of the device as appropriate.
(8) When placing a device with digital elements on the market and during the expected lifetime of the device and the support period, manufacturers shall ensure that vulnerabilities of that device, including its components, are effectively addressed in accordance with the essential cybersecurity requirements set out in Part II of Annex I.
Manufacturers shall set the support period to reflect the expected duration of use of the device, taking into account, in particular, reasonable expectations of users, the nature of the device, including its intended purpose, and relevant Union legislation defining the lifetime of devices with digital elements. When determining the support period, manufacturers may also take into account the support periods for products with digital elements with a similar function placed on the market by other manufacturers, the availability of the operating environment, the support periods for integrated components providing core functionality and purchased from third parties, and the relevant guidance of the special administrative cooperation group (ADCO) established under Article 52(15) and of the Commission. The elements to be taken into account for determining the support period shall be taken into account in a manner that ensures proportionality. Without prejudice to the second subparagraph, the support period shall be at least five years. If the product with digital elements is expected to be in service for less than five years, the support period shall correspond to the expected useful life. Taking into account the ADCO recommendations referred to in Article 52(16), the Commission may adopt delegated acts in accordance with Article 61 to supplement this Regulation by specifying the minimum support period for certain categories of devices where market surveillance data indicate inadequate support periods. Manufacturers shall include the information taken into account when determining the support period of a device with digital elements in the technical documentation referred to in Annex VII. Manufacturers shall have in place appropriate policies and procedures, including a coordinated vulnerability disclosure policy in accordance with point 5 of Part II of Annex I, to address and correct potential vulnerabilities in the device with digital elements reported by internal or external sources.
(9) Manufacturers shall ensure that any security update referred to in point 8 of Part II of Annex I made available to users during the support period remains available for at least 10 years after its deployment or for the remainder of the support period, whichever is the longer.
(10) Where a manufacturer has placed subsequent substantially different versions of a software product on the market, it may limit the assurance of compliance with the essential cybersecurity requirement set out in point 2 of Part II of Annex I to the version last placed on the market by the manufacturer, provided that users of the previously placed version have access to the last version placed on the market free of charge and do not incur additional costs for adapting the hardware and software environment in which they use the original version of that product.
(11) Manufacturers may maintain public software archives that make it easier for users to access historical versions. In these cases, users are informed clearly and in an easily accessible form about the risks associated with the use of unsupported software.
(12) Before placing a device with digital elements on the market, manufacturers shall draw up the technical documentation referred to in Article 31.
They shall carry out the chosen conformity assessment procedures referred to in Article 32 or have them carried out. Where it has been demonstrated through that conformity assessment procedure that the device with digital elements satisfies the essential cybersecurity requirements set out in Part I of Annex I and the procedures adopted by the manufacturer satisfy the essential cybersecurity requirements set out in Part II of Annex I, manufacturers shall draw up the EU declaration of conformity referred to in Article 28 and affix the CE marking referred to in Article 30.
(13) Manufacturers shall keep the technical documentation and the EU declaration of conformity for the market surveillance authorities for at least 10 years after the product with digital elements has been placed on the market or for the duration of the support period, whichever is the longer.
(14) Manufacturers shall ensure that procedures are in place to ensure that devices incorporating digital elements remain in conformity with this Regulation when manufactured in series. Manufacturers shall take due account of any changes in the design and manufacturing process or in the design or characteristics of the device incorporating digital elements, as well as of changes in the harmonized standards, European cybersecurity certification schemes or common specifications referred to in Article 27 that were used as a basis for the declaration of conformity of the device incorporating digital elements or for the verification of its conformity.
(15) Manufacturers shall ensure that their devices incorporating digital elements bear a type, batch or serial number or other element allowing their identification, or, where that is not possible, that information is provided on the packaging or in a document accompanying the device incorporating digital elements.
(16) Manufacturers shall indicate the name, registered trade name or registered trade mark of the manufacturer, the postal address, e‑mail address or other digital contact details and, where available, the website where the manufacturer can be contacted, either on the device with digital elements itself or, where that is not possible, on its packaging or in a document accompanying the device with digital elements. This information shall also be included in the information and instructions for users set out in Annex II. The contact details shall be in a language which can be easily understood by users and market surveillance authorities.
(17) For the purposes of this Regulation, manufacturers shall designate a single point of contact that allows users to communicate directly and quickly with them, including to facilitate the reporting of vulnerabilities of the product with digital elements.
Manufacturers shall ensure that the single point of contact can be easily identified by users. They shall also include the one-stop shop in the information and instructions to users set out in Annex II. The one-stop shop shall allow users to choose their preferred means of communication, which shall not be limited to automated means.
(18) Manufacturers shall ensure that devices incorporating digital elements are accompanied by the information and instructions for users set out in Annex II in paper or electronic form. Such information and instructions shall be provided in a language which can be easily understood by users and market surveillance authorities. They must be clear, understandable, unambiguous and legible. They shall enable the safe installation, operation and use of products incorporating digital elements. Manufacturers shall make the information and instructions for users referred to in Annex II available to users for at least 10 years after the device with digital elements has been placed on the market or for the duration of the support period, whichever is the longer. Where such information and instructions are provided online, manufacturers shall ensure that they are accessible, user-friendly and available online for at least 10 years after the device with digital elements has been placed on the market or for the duration of the support period, whichever is the longer.
(19) Manufacturers shall ensure that the end date of the period of support referred to in paragraph 8 is clearly and comprehensibly indicated at the time of purchase in an easily accessible manner and, where applicable, on the device with digital elements, its packaging or by digital means, indicating at least the month and the year.
Where technically feasible given the nature of the product with digital elements, manufacturers shall display a message to users to inform them that the end of the support period of their product with digital elements has been reached.
(20) Manufacturers shall enclose with the product with digital elements either a copy of the EU declaration of conformity or a simplified EU declaration of conformity. Where only a simplified EU declaration of conformity is provided, it shall indicate the exact internet address where the full EU declaration of conformity can be found.
(21) From the placing on the market and during the support period, manufacturers who know or have reason to believe that the device with digital elements or the processes established by the manufacturer do not comply with the essential cybersecurity requirements set out in Annex I shall immediately take the necessary corrective action to bring that device with digital elements or the manufacturer’s processes into compliance or, if appropriate, to withdraw the device from the market or recall it.
(22) Manufacturers shall, further to a reasoned request from a market surveillance authority, provide it with all the information and documentation in paper or electronic form, in a language which can be easily understood by that authority, necessary to demonstrate the conformity of the device with digital elements and the procedures established by the manufacturer with the essential cybersecurity requirements set out in Annex I. Manufacturers shall cooperate with that authority, at its request, on any action taken to address the cybersecurity risks posed by the device with digital elements that they have placed on the market.
(23) A manufacturer who ceases to operate and, as a consequence, is unable to comply with this Regulation shall, before the cessation takes effect, inform the relevant market surveillance authorities and, by any available means and as far as possible, users of the relevant devices placed on the market through digital means, of the impending cessation.
(24) The Commission may, by means of implementing acts, specify the format and elements of the software BOM referred to in point 1 of Part II of Annex I, taking into account European or international standards and best practices. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 62(2).
(25) In order to assess the dependence of Member States and the Union as a whole on software components, and in particular on components considered as free and open source software, ADCO may decide to carry out a Union-wide dependence assessment for certain categories of devices with digital elements. For this purpose, market surveillance authorities may request manufacturers of such categories of products with digital elements to submit the relevant software BOMs in accordance with Annex I, Part II, point 1. On the basis of this information, market surveillance authorities may provide ADCO with anonymized and aggregated information on software dependencies. ADCO shall submit a report on the results of the dependency assessment to the Cooperation Group established under Article 14 of Directive (EU) 2022/2555.
Article 14 Reporting obligations of manufacturers
(1) A manufacturer shall report any actively exploited vulnerability contained in the device with digital elements of which it becomes aware simultaneously to the CSIRT designated as coordinator in accordance with paragraph 7 and to ENISA. The manufacturer shall report that actively exploited vulnerability through the single reporting platform established in accordance with Article 16.
(2) For the purposes of the notification referred to in paragraph 1, the manufacturer shall submit the following:
a) without undue delay and in any event within 24 hours after the manufacturer has become aware of it, an early warning of an actively exploited vulnerability, indicating the Member States in the territory of which the product containing digital elements of the manufacturer has been made available to its knowledge;
b) unless the relevant information has already been provided, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the actively exploited vulnerability, a vulnerability report containing general information, where available, on the digital item product concerned, on the general nature of the exploitation and of the vulnerability concerned, and on any corrective or mitigating action taken and any corrective or remedial action that users may take, including, where appropriate, an indication of how sensitive the manufacturer considers the reported information to be;
c) unless the relevant information has already been submitted, a final report containing at least the following no later than 14 days after a corrective or mitigating action is available:
i) a description of the vulnerability, including its severity and impact,
ii) if available, information about any malicious actor who has exploited or is exploiting the vulnerability,
iii) Information about the security update or other corrective measures provided to address the vulnerability.
(3) A manufacturer shall report any serious security incident affecting the security of the device with digital elements of which it becomes aware simultaneously to the CSIRT designated as coordinator in accordance with paragraph 7 and to ENISA. The manufacturer shall report that security incident through the single reporting platform established in accordance with Article 16.
(4) For the purposes of the notification referred to in paragraph 3, the manufacturer shall submit the following:
a) without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, an early warning of a serious security incident affecting the security of the product with digital elements, indicating at least whether the security incident is suspected to be the result of illegal or malicious acts and, where applicable, the Member States on whose territory the product with digital elements of the manufacturer is known to have been made available;
b) unless the relevant information has already been provided, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the security incident, a notification of the security incident containing general information, where available, on the nature of the security incident, an initial assessment of the security incident, corrective or mitigating actions taken and corrective or remedial actions that users may take, including, where appropriate, an indication of how sensitive the manufacturer considers the reported information to be;
c) unless the relevant information has already been provided, a final report containing at least the following within one month of the submission of the incident report referred to in point (b):
i) a detailed description of the security incident, including its severity and impact;
ii) Information on the type of threat or underlying cause that likely triggered the security incident;
iii) Details of remedial action taken and ongoing.
(5) For the purposes of paragraph 3, a security incident that has an impact on the security of the product with digital elements shall be considered serious if
a) it adversely affects or may adversely affect the ability of a product with digital elements to protect the availability, authenticity, integrity or confidentiality of sensitive or critical data or functions, or
b) it has led or may lead to the introduction or execution of malicious code in a product with digital elements or in the network and information system of a user of the product with digital elements.
(6) If necessary, the CSIRT designated as coordinator that initially receives the notification may request the manufacturers to provide an interim report on relevant status updates on the actively exploited vulnerability or serious security incident affecting the security of the product with digital elements.
(7) The notifications referred to in paragraphs 1 and 3 of this Article shall be submitted through the single reporting platform referred to in Article 16 using one of the electronic reporting endpoints referred to in Article 16(1). The notification shall be submitted via the electronic notification endpoint of the CSIRT designated as coordinator of the Member State where the manufacturers have their main establishment in the Union and shall be accessible to ENISA at the same time.
For the purposes of this Regulation, a manufacturer shall be deemed to have its main establishment in the Union in the Member State where the decisions relating to the cybersecurity of its products with digital elements are predominantly taken. Where such a Member State cannot be determined, the Member State of main establishment shall be deemed to be the Member State where the manufacturer concerned has the establishment with the highest number of employees in the Union. Where a manufacturer does not have a main establishment in the Union, it shall submit the notifications referred to in paragraphs 1 and 3 using the electronic notification endpoint of the CSIRT designated as coordinator in the Member State determined in accordance with the following order and on the basis of the information available to the manufacturer:
a) the Member State in which the authorized representative is established who acts on behalf of the manufacturer for most products with digital elements of the manufacturer;
b) the Member State in which the importer is established who places on the market most of the products containing digital elements from that manufacturer;
c) the Member State in which the distributor is established that makes most of the products with digital elements of that manufacturer available on the market;
d) the Member State in which most users of products with digital elements from this manufacturer are located.
With regard to point (d) of the third subparagraph, a manufacturer may submit notifications related to subsequent actively exploited vulnerabilities or serious security incidents affecting the security of the product with digital elements to the same CSIRT that has been designated as coordinator and to which it has first reported.
(8) After becoming aware of an actively exploited vulnerability or a serious security incident affecting the security of the device with digital elements, the manufacturer shall inform the affected users of the device with digital elements and, where applicable, all users of that vulnerability or serious security incident and, where necessary, of any risk mitigation measures and corrective actions that users can take to mitigate the impact of those vulnerabilities or security incidents, where appropriate in a structured, machine-readable format that can be easily processed automatically. Where the manufacturer fails to inform the users of the product with digital elements in a timely manner, the CSIRTs designated as coordinators may make this information available to the users if they consider it proportionate and necessary to prevent or mitigate the impact of these vulnerabilities or security incidents.
(9) By 11 December 2025, the Commission shall adopt a delegated act in accordance with Article 61 of this Regulation supplementing this Regulation by specifying the modalities and conditions for the application of the cybersecurity grounds related to the delay in dissemination of notifications referred to in Article 16(2) of this Regulation. The Commission shall cooperate with the CSIRTs network established under Article 15 of Directive (EU) 2022/2555 and ENISA in the preparation of the draft delegated act.
(10) The Commission may, by means of implementing acts, specify the format and procedures for the notifications referred to in this Article and in Articles 15 and 16. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 62(2). The Commission shall cooperate with the CSIRTs network and ENISA in the preparation of draft implementing acts.
Article 15 Voluntary declarations
(1) Manufacturers and other natural or legal persons may voluntarily report any vulnerability contained in a product with digital elements, as well as cyber threats that could impact the risk profile of a product with digital elements, to a CSIRT designated as coordinator or to ENISA.
(2) Manufacturers and other natural or legal persons may report, on a voluntary basis, any security incident affecting the security of the product with digital elements, as well as near-miss incidents that could have led to such a security incident, to a CSIRT designated as coordinator or to ENISA.
(3) The CSIRT designated as coordinator or ENISA shall process the notifications referred to in paragraphs 1 and 2 in accordance with the procedure laid down in Article 16.
The CSIRT appointed as coordinator can process mandatory notifications with priority over voluntary notifications.
(4) Where a natural or legal person other than the manufacturer referred to in paragraph 1 or 2 reports an actively exploited vulnerability or a serious security incident affecting the security of a product with digital elements, the CSIRT designated as coordinator shall inform the manufacturer without delay.
(5) The CSIRTs designated as coordinators and ENISA shall ensure the confidentiality and adequate protection of the information submitted by a reporting natural or legal person. Without prejudice to the prevention, investigation, detection and prosecution of criminal offenses, voluntary reporting shall not result in the imposition of additional obligations on the reporting natural or legal person that would not have applied to it if it had not submitted the report.
Article 16 Establishment of a single reporting platform
(1) For the purposes of the notifications referred to in Article 14(1) and (3) and Article 15(1) and (2) and in order to simplify the reporting obligations of manufacturers, ENISA shall set up a single reporting platform. The day-to-day operation of that single reporting platform shall be managed and maintained by ENISA. The architecture of the single reporting platform shall allow Member States and ENISA to set up their own endpoints for electronic reporting.
(2) Upon receipt of a notification, the CSIRT designated as coordinator that initially receives the notification shall immediately forward the notification via the single notification platform to the CSIRTs designated as coordinators in whose territory the product with digital items was made available according to the manufacturer’s specifications.
In exceptional circumstances, and in particular at the request of the manufacturer and given the level of sensitivity of the reported information indicated by the manufacturer in accordance with point (a) of Article 14(2) of this Regulation, the dissemination of the notification may be delayed for as long as strictly necessary for legitimate reasons related to cybersecurity, including where a vulnerability is subject to a coordinated vulnerability disclosure process in accordance with Article 12(1) of Directive (EU) 2022/2555. Where a CSIRT decides to withhold a notification, it shall inform ENISA of the decision without undue delay and provide both a justification for withholding the notification and an indication of when it will disseminate the notification in accordance with the procedure set out in this paragraph. ENISA may assist the CSIRT in the application of cybersecurity grounds related to the delay of the dissemination of the notification. In specific exceptional circumstances, where the manufacturer indicates the following in the notification referred to in point (b) of Article 14(2):
a) that the reported vulnerability was actively exploited by a malicious actor and, according to the available information, was not exploited in any Member State other than that of the CSIRT designated as coordinator to which the manufacturer reported the vulnerability;
b) that immediate further disclosure of the reported vulnerability would be likely to result in the provision of information the disclosure of which would be contrary to the essential interests of the Member State concerned; or
c) that the reported vulnerability poses an immediate high cybersecurity risk resulting from further propagation,
only the information that the manufacturer has made a notification, the general information on the product, the information on the general nature of the exploitation and the information that security reasons have been invoked shall be provided simultaneously to ENISA until the full notification is forwarded to the CSIRTs concerned and to ENISA. If, on the basis of this information, ENISA considers that there is a systemic risk to the security of the internal market, it shall recommend that the CSIRT that received the notification forwards the complete notification to the other CSIRTs designated as coordinators and to ENISA itself.
(3) Upon receipt of a notification of an actively exploited vulnerability in a product with digital elements or of a serious security incident affecting the security of a product with digital elements, the CSIRTs designated as coordinators shall provide the market surveillance authorities of their respective Member State with the notified information necessary to enable them to comply with their obligations under this Regulation.
(4) ENISA shall take appropriate and proportionate technical, operational and organizational measures to manage the risks to the security of the single reporting platform and the information transmitted or disseminated through the single reporting platform. It shall notify the CSIRTs network and the Commission without delay of any security incident affecting the single reporting platform.
(5) ENISA shall, in cooperation with the CSIRTs network, prepare and implement specifications for the technical, operational and organizational measures for the establishment, maintenance and secure operation of the single reporting platform referred to in paragraph 1, including at least the security measures related to the establishment operation and maintenance of the single reporting platform and the electronic reporting endpoints established by the CSIRTs designated as coordinators at national level and by ENISA at Union level, including procedural aspects to ensure that information on those vulnerabilities is shared in accordance with strict security protocols and on a need-to-know basis when corrective or mitigating measures are not available for a reported vulnerability.
(6) Where a CSIRT designated as coordinator has been made aware of an actively exploited vulnerability in the context of a coordinated vulnerability disclosure process in accordance with Article 12(1) of Directive (EU) 2022/2555, the CSIRT designated as coordinator that initially received the notification may, for legitimate reasons related to cybersecurity, postpone the dissemination of the notification concerned through the single notification platform for a period no longer than strictly necessary until the parties involved in the coordinated vulnerability disclosure have given their consent to the disclosure. This requirement shall not prevent manufacturers from voluntarily reporting such a vulnerability in accordance with the procedure set out in this Article.
Article 17 Other provisions relating to reporting
(1) ENISA may share with the European Cyber Crisis Liaison Organizations Network (EU-CyCLONe) established by Article 16 of Directive (EU) 2022/2555 the information reported in accordance with Article 14(1) and (3) and Article 15(1) and (2) of this Regulation, where such information is relevant for the coordinated management of massive cybersecurity incidents and crises at operational level. For the purposes of determining such relevance, ENISA may take into account technical analysis of the CSIRTs network, where appropriate.
(2) Where public awareness is necessary to prevent or mitigate a serious security incident affecting the security of the device with digital elements or to manage an ongoing security incident, or where disclosure of the security incident is otherwise in the public interest, the CSIRT designated as coordinator of the Member State concerned may, after consulting the manufacturer concerned and, where appropriate, in cooperation with ENISA, inform the public about the security incident or request the manufacturer to do so.
(3) ENISA shall, on the basis of the notifications received in accordance with Article 14(1) and (3) and Article 15(1) and (2) of this Regulation, prepare a technical report every 24 months on emerging trends in cybersecurity risks of products with digital elements and submit it to the Cooperation Group established in accordance with Article 14 of Directive (EU) 2022/2555. The first such report shall be submitted within 24 months of the date of application of the obligations laid down in Article 14(1) and (3). ENISA shall include relevant information from its technical reports in its report on the state of cybersecurity in the Union pursuant to Article 18 of Directive (EU) 2022/2555.
(4) The mere notification pursuant to Article 14(1) and (3) and Article 15(1) and (2) shall not increase the liability of the notifying natural or legal person.
(5) As soon as a security update or other form of corrective or mitigating action is available, ENISA shall, in agreement with the manufacturer of the digital device concerned, include the publicly known vulnerability reported in accordance with Article 14(1) or Article 15(1) of this Regulation in the European vulnerability database established in accordance with Article 12(2) of Directive (EU) 2022/2555.
(6) The CSIRTs designated as coordinators shall provide helpdesk support to manufacturers, and in particular manufacturers that are considered to be micro, small or medium-sized enterprises, in relation to the reporting obligations under Article 14.
Article 18 Authorized representatives
(1) A manufacturer may appoint an authorized representative in writing.
(2) The obligations laid down in Article 13(1) to (11), the first subparagraph of Article 13(12) and Article 13(14) shall not form part of the authorized representative’s mandate.
(3) An authorized representative shall perform the tasks specified in the mandate issued by the manufacturer. The authorized representative shall provide a copy of the mandate to the market surveillance authorities upon request. The mandate shall enable the authorized representative to perform at least the following tasks:
a) Keep the EU declaration of conformity referred to in Article 28 and the technical documentation referred to in Article 31 at the disposal of market surveillance authorities for at least 10 years from the date on which the product with digital elements is placed on the market or for the support period, whichever is the longer;
b) Transmission of all information and documents necessary to demonstrate the conformity of the product with digital elements to a market surveillance authority upon its reasoned request;
c) Cooperate with market surveillance authorities, at their request, on any action taken to eliminate the risks posed by a product with digital elements falling within the scope of the authorized representative’s tasks.
Article 19 Obligations of importers
(1) Importers shall only place on the market devices incorporating digital elements which meet the essential cybersecurity requirements set out in Part I of Annex I and for which the procedures defined by the manufacturer meet the essential cybersecurity requirements set out in Part II of Annex I.
(2) Before placing a product with digital elements on the market, importers shall ensure that
a) the manufacturer has carried out the appropriate conformity assessment procedures referred to in Article 32;
b) the manufacturer has prepared the technical documentation;
c) the product with digital elements bears the CE marking referred to in Article 30 and is accompanied by the EU declaration of conformity referred to in Article 13(20) and by the information and instructions for users set out in Annex II in a language which can be easily understood by users and market surveillance authorities;
d) the manufacturer complies with the requirements set out in Article 13(15), (16) and (19).
For the purposes of this paragraph, importers shall be able to provide the documentation necessary to demonstrate compliance with the requirements laid down in this Article.
(3) Where an importer considers or has reason to believe that a device incorporating digital elements or the procedures laid down by the manufacturer are not in conformity with this Regulation, he shall not place the device on the market until it and the procedures laid down by the manufacturer have been brought into conformity with this Regulation. Furthermore, where the device incorporating digital elements presents a significant cybersecurity risk, the importer shall inform the manufacturer and the market surveillance authorities to that effect.
Where an importer has reason to believe that a product with digital elements could pose a significant cybersecurity risk due to non-technical risk factors, he shall inform the market surveillance authorities. Upon receipt of this information, the market surveillance authorities shall follow the procedures referred to in Article 54(2).
(4) Importers shall indicate their name, registered trade name or registered trade mark, postal address, e‑mail address or other means of digital contact and, where applicable, the website where they can be contacted, either on the product with digital elements itself or on its packaging, or in a document accompanying the product with digital elements. The contact details shall be in a language that can be easily understood by users and market surveillance authorities.
(5) Importers who know or have reason to believe that a product with digital elements which they have placed on the market is not in conformity with this Regulation shall immediately take the necessary corrective action to bring that product with digital elements into conformity with this Regulation or, if appropriate, to withdraw the product from the market or recall it.
Importers shall, as soon as they become aware of a vulnerability in the product with digital elements, immediately inform the manufacturer of that vulnerability. Furthermore, where the product with digital elements presents a significant cybersecurity risk, importers shall immediately inform the market surveillance authorities of the Member States in which they made the product with digital elements available on the market, giving details, in particular, of the non-compliance and of any corrective action taken.
(6) Importers shall, for a period ending at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is the longer, keep a copy of the EU declaration of conformity at the disposal of the market surveillance authorities and ensure that they are able to present the technical documentation to those authorities, upon request.
(7) Importers shall, further to a reasoned request from a market surveillance authority, provide it with all the information and documentation in paper or electronic form in a language which can be easily understood by that authority, necessary to demonstrate the conformity of the product with digital elements with the essential cybersecurity requirements set out in Part I of Annex I and of the procedures set out by the manufacturer with the essential cybersecurity requirements set out in Part II of Annex I. They shall cooperate with that authority, at its request, on any action taken to address the cybersecurity risks posed by a device with digital elements that they have placed on the market.
(8) Where the importer of a device incorporating digital elements becomes aware that the manufacturer of that device has ceased its business activities and is consequently unable to fulfil the obligations laid down in this Regulation, he shall inform the relevant market surveillance authorities and, by any available means and as far as possible, the users of the devices incorporating digital elements placed on the market to that effect.
Article 20 Obligations of traders
(1) When making a product with digital elements available on the market, traders shall comply with the provisions of this Regulation with due care.
(2) Before making a product with digital elements available on the market, retailers check whether
a) the product is provided with digital elements with the CE marking;
b) the manufacturer and the importer have complied with the requirements of Article 13(15), (16), (18), (19) and (20) and Article 19(4) and have provided the distributor with all necessary documents.
(3) Where a distributor considers or has reason to believe, on the basis of the information available to it, that a device incorporating digital elements or the procedures established by the manufacturer do not comply with the essential cybersecurity requirements set out in Annex I, it shall not make the device incorporating digital elements available on the market until that device and the procedures established by the manufacturer have been brought into conformity with this Regulation. Furthermore, where the product with digital elements presents a significant cybersecurity risk, the distributor shall immediately inform the manufacturer and the market surveillance authorities thereof.
(4) Distributors who know or have reason to believe, on the basis of information available to them, that a product with digital elements which they have made available on the market or the procedures established by its manufacturer are not in conformity with this Regulation shall ensure that the necessary corrective action is taken to bring that product with digital elements into conformity with the procedures established by the manufacturer or, if appropriate, to withdraw the product from the market or recall it.
As soon as distributors become aware of a vulnerability in the product with digital elements, they shall immediately inform the manufacturer of that vulnerability. Where the product with digital elements presents a significant cybersecurity risk, distributors shall also immediately inform the market surveillance authorities of the Member States in which they made the product with digital elements available on the market, giving details, in particular, of the non-compliance and of any corrective action taken.
(5) Distributors shall, further to a reasoned request from a market surveillance authority, provide it with all the information and documentation necessary to demonstrate the conformity of the product with digital elements and with the procedures laid down in this Regulation by the manufacturer, in paper or electronic form in a language which can be easily understood by that authority. They shall cooperate with that authority, at its request, on any action taken to address the cybersecurity risks posed by a device with digital elements which they have made available on the market.
(6) Where the distributor of a device incorporating digital elements becomes aware, on the basis of the information available to him, that the manufacturer of that device has ceased its business activities and is consequently unable to fulfil the obligations laid down in this Regulation, he shall immediately inform the relevant market surveillance authorities and, by any available means and as far as possible, the users of the devices incorporating digital elements placed on the market to that effect.
Article 21 Cases where the obligations of producers also apply to importers and distributors
An importer or distributor shall be considered a manufacturer for the purposes of this Regulation and shall be subject to the obligations set out in Articles 13 and 14 where that importer or distributor places a product incorporating digital elements on the market under his own name or trademark or makes a substantial modification to a product incorporating digital elements that has already been placed on the market.
Article 22 Other cases where producers’ obligations apply
(1) A natural or legal person, other than the manufacturer, importer or distributor, who makes a substantial modification to the product incorporating digital elements and makes that product available on the market shall be considered a manufacturer for the purposes of this Regulation.
(2) The person referred to in paragraph 1 of this Article shall be subject to the obligations laid down in Articles 13 and 14 for the part of the product with digital elements affected by the substantial modification or, where the substantial modification affects the cybersecurity of the product with digital elements as a whole, for the entire product.
Article 23 Identification of economic operators
(1) Economic operators shall provide the market surveillance authorities with the following information on request:
a) Name and address of all economic operators from whom they have purchased products with digital elements,
b) where available, the name and address of all economic operators to whom they have supplied products with digital elements.
(2) Economic operators shall be able to provide the information referred to in paragraph 1 ten years after the purchase of the product with digital elements and ten years after the supply of the product with digital elements.
Article 24 Obligations of administrators of open source software
(1) Managers of open source software shall develop and document in a verifiable manner a cybersecurity policy to promote the development of a secure product with digital elements and the effective management of vulnerabilities by the developers of that product. That policy shall also encourage the voluntary reporting of vulnerabilities by the developers of that product in accordance with Article 15 and shall take into account the specificities of the manager of open source software and the legal and organizational arrangements to which it is subject. In particular, this policy shall cover aspects related to the documentation, remediation and elimination of vulnerabilities and shall encourage the sharing of information on vulnerabilities discovered within the open source community.
(2) Administrators of open source software will work with market surveillance authorities, at their request, to mitigate the cybersecurity risks posed by a product with digital elements that qualifies as free and open source software.
At the reasoned request of a market surveillance authority, administrators of open source software shall submit to that authority, in a language easily understood by that authority, the documentation referred to in paragraph 1 in paper or electronic form.
(3) The obligations set out in Article 14(1) shall apply to managers of open source software to the extent that they are involved in the development of the products incorporating digital items. The obligations laid down in Article 14(3) and (8) shall apply to managers of open source software to the extent that serious security incidents affecting the security of products incorporating digital items affect network and information systems provided by the managers of open source software for the development of such products.
Article 25 Security certification for free and open source software
In order to facilitate the due diligence obligation set out in Article 13(5), in particular with regard to manufacturers that incorporate free and open source software components into their digital-enabled products, the Commission shall be empowered to adopt delegated acts in accordance with Article 61 to supplement this Regulation by introducing voluntary security attestation schemes that allow developers or users of digital-enabled products that qualify as free and open source software, and other third parties, to assess the compliance of those products with all or certain essential cybersecurity requirements or other obligations laid down in this Regulation.
Article 26 Guidelines
(1) In order to facilitate implementation and ensure consistency, the Commission shall publish guidelines to assist economic operators in the application of this Regulation, with a particular focus on facilitating compliance by micro, small and medium-sized enterprises.
(2) Where the Commission intends to provide guidance in accordance with paragraph 1, it shall address at least the following aspects:
a) the scope of this Regulation, with a particular focus on remote computing solutions and free and open source software,
b) the application of support periods in relation to certain categories of products with digital elements;
c) Guidelines for manufacturers subject to this Regulation who are also subject to Union harmonization legislation other than this Regulation or other related Union acts;
d) the term “material change”.
The Commission shall also keep an easily accessible list of delegated and implementing acts adopted pursuant to this Regulation.
(3) The Commission shall consult the relevant stakeholders when drawing up the guidelines referred to in this Article.
Chapter III Conformity of the product with digital elements
Article 27 Presumption of conformity
(1) Devices incorporating digital elements and procedures defined by the manufacturer which are in conformity with harmonized standards or parts thereof the references of which have been published in the Official Journal of the European Union shall be presumed to be in conformity with the essential cybersecurity requirements set out in Annex I in so far as those requirements are covered by those standards or parts thereof.
The Commission shall, in accordance with Article 10(1) of Regulation (EU) No 1025/2012, request one or more European standardization organisations to develop harmonized standards for the essential cybersecurity requirements set out in Annex I to this Regulation. When preparing standardization requests for this Regulation, the Commission shall endeavour to take into account existing European and international cybersecurity standards that are in force or under development in order to facilitate the development of harmonized standards in accordance with Regulation (EU) No 1025/2012.
(2) The Commission may adopt implementing acts laying down common specifications of technical requirements, compliance with which shall enable the fulfilment of the essential cybersecurity requirements set out in Annex I for products with digital elements within the scope of this Regulation.
These implementing acts may only be adopted if the following conditions are met:
a) the Commission has requested, in accordance with Article 10(1) of Regulation (EU) No 1025/2012, one or more European standardization organizations to develop a harmonized standard for the essential cybersecurity requirements listed in Annex I; and:
i) the order was not accepted,
ii) the harmonized standards to which this request relates are not delivered within the time limit set in accordance with Article 10(1) of Regulation (EU) No 1025/2012, or
iii) the harmonized standards do not comply with the mandate, and
b) no reference has been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012 to harmonized standards that meet the relevant essential cybersecurity requirements set out in Annex I to this Regulation, and no such reference is expected to be published within a reasonable period of time.
Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 62(2).
(3) Before preparing a draft implementing act referred to in paragraph 2 of this Article, the Commission shall notify the Committee referred to in Article 22 of Regulation (EU) No 1025/2012 that it considers the conditions referred to in paragraph 2 of this Article to be met.
(4) When preparing a draft implementing act referred to in paragraph 2, the Commission shall take into account the views of the relevant bodies and duly consult all relevant stakeholders.
(5) Devices with digital elements and procedures defined by the manufacturer that comply with the common specifications established by the implementing act referred to in paragraph 2 of this Article shall be presumed to comply with the essential cybersecurity requirements set out in Annex I to the extent that the common specifications or parts thereof cover those requirements.
(6) Where a harmonized standard is adopted by a European standardization organisation and proposed to the Commission for publication of its reference in the Official Journal of the European Union, the Commission shall assess that harmonized standard in accordance with Regulation (EU) No 1025/2012. When a reference of a harmonized standard is published in the Official Journal of the European Union, the Commission shall repeal the implementing acts referred to in paragraph 2 of this Article, or parts thereof, which regulate the same essential cybersecurity requirements as the harmonized standard.
(7) Where a Member State considers that a common specification does not fully meet the essential cybersecurity requirements set out in Annex I, it shall inform the Commission thereof by means of a detailed explanation. The Commission shall assess the detailed explanation and may, where appropriate, amend the implementing act that established the common specification concerned.
(8) Devices with digital elements and procedures defined by the manufacturer for which an EU declaration of conformity or a cybersecurity certificate has been issued under a European cybersecurity certification scheme adopted in accordance with Regulation (EU) 2019/881 shall be presumed to be in conformity with the essential cybersecurity requirements set out in Annex I, provided that the EU declaration of conformity or the European cybersecurity certificate or parts thereof cover those requirements.
(9) The Commission shall be empowered to adopt delegated acts in accordance with Article 61 to supplement this Regulation by designating the European cybersecurity certification schemes adopted pursuant to Regulation (EU) 2019/881 that may be used to demonstrate the compliance of devices with digital elements with the essential cybersecurity requirements set out in Annex I or parts thereof. In addition, the issuance of a European cybersecurity certificate issued under such a scheme at a level of assurance of at least ‘medium’ shall remove the obligation for the manufacturer to have a third party conformity assessment carried out for the requirements concerned, as provided for in Article 32(2)(a) and (b) and Article 32(3)(a) and (b).
Article 28 EU Declaration of Conformity
(1) The EU declaration of conformity shall be drawn up by the manufacturer in accordance with Article 13(12) and shall state that compliance with the essential cybersecurity requirements set out in Annex I has been demonstrated.
(2) The EU declaration of conformity shall have the model structure set out in Annex V and shall contain the elements specified in the relevant conformity assessment procedures set out in Annex VIII. Such a declaration shall be updated as necessary. It shall be drawn up in the languages required by the Member State in which the product with digital elements is placed or made available on the market.
The simplified EU declaration of conformity referred to in Article 13(20) shall have the same structure as the model set out in Annex VI and shall be drawn up in the languages required by the Member State in which the device with digital elements is placed or made available on the market.
(3) Where a product with digital elements is subject to more than one Union act requiring an EU declaration of conformity, a single EU declaration of conformity shall be drawn up in respect of all such Union acts. This declaration shall indicate the relevant Union acts and their references in the Official Journal.
(4) By issuing the EU Declaration of Conformity, the manufacturer assumes responsibility for the conformity of the product with digital elements.
(5) The Commission shall be empowered to adopt delegated acts in accordance with Article 61 to supplement this Regulation in order to add new elements to the minimum content of the EU declaration of conformity set out in Annex V in the light of technical developments.
Article 29 General principles of the CE marking
The general principles set out in Article 30 of Regulation (EC) No 765/2008 apply to the CE marking.
Article 30 Rules and conditions for affixing the CE marking
(1) The CE marking shall be affixed visibly, legibly and indelibly to the device with digital elements. Where the nature of the device incorporating digital elements does not allow or does not justify it, the CE marking shall be affixed to the packaging and to the EU declaration of conformity referred to in Article 28 accompanying the device incorporating digital elements. For products with digital elements in the form of software, the CE marking shall be affixed either on the EU declaration of conformity referred to in Article 28 or on the website accompanying the software product. In the latter case, the relevant section of the website shall be easily and directly accessible to consumers.
(2) Due to the nature of the product with digital elements, the height of the CE marking affixed to it may be less than 5 mm, provided that it is still visible and legible.
(3) The CE marking shall be affixed with digital elements before the product is placed on the market. It may be followed by a pictogram or any other mark indicating a specific cybersecurity risk or use to be specified in the implementing acts referred to in paragraph 6.
(4) The CE marking shall be followed by the identification number of the notified body where the notified body is involved in the conformity assessment procedure based on full quality assurance (based on module H) in accordance with Article 32.
The identification number of the notified body shall be affixed either by the body itself or, under its instructions, by the manufacturer or his authorized representative.
(5) Member States shall build upon existing mechanisms to ensure proper implementation of the CE marking system and shall take appropriate action in the event of improper use of that marking. Where the product with digital elements is also covered by Union harmonization legislation other than this Regulation which also provides for the CE marking, the CE marking shall indicate that the product also complies with the requirements of such other Union harmonization legislation.
(6) The Commission may, by means of implementing acts, lay down technical specifications for labels, pictograms or other marks relating to the safety of products with digital elements, their support periods and mechanisms to promote their use and to raise public awareness of the safety of products with digital elements. When preparing the draft implementing acts, the Commission shall consult the relevant stakeholders and, where it has already been established in accordance with Article 52(15), ADCO. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 62(2).
Article 31 Technical documentation
(1) The technical documentation shall contain all relevant data or details on how the manufacturer ensures that the device with digital elements and the procedures defined by the manufacturer meet the essential cybersecurity requirements set out in Annex I. It shall contain at least the information set out in Annex VII.
(2) The technical documentation is created with digital elements before the product is placed on the market and, if necessary, updated continuously, at least during the support period.
(3) For devices with digital elements referred to in Article 12 which are also subject to other Union acts providing for technical documentation, a single technical documentation shall be drawn up containing the information referred to in Annex VII and the information required by the other Union acts.
(4) The technical documentation and correspondence relating to the conformity assessment procedures shall be drawn up in an official language of the Member State in which the notified body is established or in a language accepted by that body.
(5) The Commission shall be empowered to adopt delegated acts in accordance with Article 61 supplementing this Regulation by adding elements to be included in the technical documentation referred to in Annex VII in order to take account of technical developments and developments in the implementation of this Regulation. To that end, the Commission shall endeavor to ensure that the administrative burden on micro, small and medium-sized enterprises is proportionate.
Article 32 Conformity assessment procedures for devices incorporating digital elements
(1) The manufacturer shall carry out an assessment of conformity of the device with digital elements and the procedures specified by the manufacturer to determine whether the essential cybersecurity requirements set out in Annex I are met. The manufacturer shall demonstrate conformity with the essential cybersecurity requirements using one of the following procedures:
a) internal control procedure (based on Module A) in accordance with Annex VIII
b) EU-type examination procedure (based on module B) according to Annex VIII and then conformity to EU-type based on internal production control (based on module C) according to Annex VIII
c) Conformity assessment based on full quality assurance (based on Module H) in accordance with Annex VIII; or
d) where available and applicable, a European cybersecurity certification scheme in accordance with Article 27(9).
(2) Where the manufacturer has not applied or has only partially applied harmonized standards, common specifications or European cybersecurity certification schemes at least at assurance level ‘medium’ in accordance with Article 27 when assessing the conformity of a critical device with digital elements falling within class I as set out in Annex III and the procedures established by the manufacturer with the essential cybersecurity requirements set out in Annex I, or where such harmonized standards, common specifications or European cybersecurity certification schemes are not available, the devices with digital elements and the procedures established by the manufacturer shall be subject to one of the following procedures common specifications or European cybersecurity certification schemes do not exist, the devices with digital elements and the procedures defined by the manufacturer with regard to the essential cybersecurity requirements shall be subject to one of the following procedures:
a) EU-type examination procedure (based on module B) according to Annex VIII and then conformity to EU-type based on internal production control (based on module C) according to Annex VIII or
b) a conformity assessment based on full quality assurance (based on Module H) in accordance with Annex VIII.
(3) Where the device is a critical device with digital elements falling within Class II as set out in Annex III, the manufacturer shall demonstrate conformity with the essential cybersecurity requirements set out in Annex I using one of the following procedures:
a) EU-type examination procedure (based on module B) according to Annex VIII and subsequently conformity to EU-type based on internal production control (based on module C) according to Annex VIII;
b) a conformity assessment based on full quality assurance (based on Module H) in accordance with Annex VIII, or
c) where available and applicable, a European cybersecurity certification scheme in accordance with Article 27(9) of this Regulation at least at the assurance level ‘medium’ in accordance with Regulation (EU) 2019/881.
(4) For critical devices with digital elements listed in Annex IV, compliance with the essential cybersecurity requirements set out in Annex I shall be demonstrated by one of the following methods:
a) a European cybersecurity certification scheme in accordance with Article 8(1); or
b) if the conditions laid down in Article 8(1) are not met, one of the procedures referred to in paragraph 3.
(5) Manufacturers of devices incorporating digital items that are considered free and open source software and fall within the categories set out in Annex III may demonstrate compliance with the essential cybersecurity requirements set out in Annex I by means of one of the procedures referred to in paragraph 1 of this Article, provided that the technical documentation referred to in Article 31 is made available to the public at the time of placing those devices on the market.
(6) When setting the fees for conformity assessment, the specific interests and needs of micro, small and medium-sized enterprises, including start-ups, shall be taken into account and those fees shall be reduced in proportion to their specific interests and needs.
Article 33 Support measures for micro, small and medium-sized enterprises, including start-ups
(1) Member States shall, where appropriate, take the following measures tailored to the needs of micro and small enterprises:
a) Organization of specific awareness-raising and training measures for the application of this regulation,
b) Establish a dedicated communication channel for micro and small enterprises and, where appropriate, local authorities to provide advice on the implementation of this Regulation and to clarify queries,
c) Support of testing and conformity assessment activities, if required also with the support of the European Cybersecurity Competence Center.
(2) Member States may, where necessary, establish cyber resilience real-world laboratories. Such real-world laboratories shall provide for controlled test environments for innovative devices with digital elements to facilitate their development, design, validation and testing for the purpose of compliance with this Regulation for a limited period of time before they are placed on the market. The Commission and, where appropriate, ENISA may provide technical support, advice and tools for the establishment and operation of real-world laboratories. The real laboratories shall be set up under the direct supervision, guidance and support of the market surveillance authorities. Member States shall inform the Commission and the other market surveillance authorities of the establishment of a real-world laboratory through ADCO. The reallaboratories shall be without prejudice to the supervisory and corrective powers of the competent authorities. Member States shall ensure open, fair and transparent access to real laboratories and facilitate access in particular for micro and small enterprises, including start-ups.
(3) In accordance with Article 26, the Commission shall provide guidance to micro, small and medium-sized enterprises on the implementation of this Regulation.
(4) The Commission shall provide information on available financial support within the legal framework of existing Union programs, in particular to provide financial relief to micro and small enterprises.
(5) Micro and small enterprises may submit all elements of the technical documentation listed in Annex VII in a simplified format. To that end, the Commission shall, by means of implementing acts, establish the simplified technical documentation form tailored to the needs of micro and small enterprises, including the way in which the elements listed in Annex VII are to be provided. Where a microenterprise or a small enterprise chooses to provide the information required in Annex VII in a simplified manner, it shall use the form referred to in this paragraph. Notified bodies shall accept that form for the purposes of conformity assessment.
Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 62(2).
Article 34 Mutual recognition agreement
Taking into account the level of technical development and the approach to conformity assessment of a third country, the Union may conclude mutual recognition agreements with third countries in order to promote and facilitate international trade, in accordance with Article 218 TFEU.
Chapter IV Notification of conformity assessment bodies
Article 35 Notification
(1) Member States shall notify the Commission and the other Member States of the bodies authorized to carry out conformity assessments under this Regulation.
(2) By December 11, 2026, Member States shall ensure that there is a sufficient number of notified bodies in the Union that can carry out conformity assessments in order to prevent bottlenecks and barriers to market access.
Article 36 Notifying authorities
(1) Each Member State shall designate a notifying authority that shall be responsible for setting up, carrying out and monitoring the necessary procedures for the assessment, designation and notification of conformity assessment bodies, including compliance with Article 41.
(2) Member States may decide that the assessment and monitoring referred to in paragraph 1 of this Article shall be carried out by a national accreditation body within the meaning of and in accordance with Regulation (EC) No 765/2008.
(3) Where the notifying authority delegates or otherwise entrusts the assessment, notification or monitoring referred to in paragraph 1 of this Article to a non-governmental body, that body shall be a legal entity and shall comply with Article 37 accordingly. That body shall also make provisions to cover any liability arising from its activities.
(4) The notifying authority shall take full responsibility for the activities carried out by the body referred to in paragraph 3.
Article 37 Requirements for notifying authorities
(1) Notifying authorities are set up in such a way that there is no conflict of interest with the conformity assessment bodies.
(2) Notifying authorities shall ensure, through their organization and working methods, that objectivity and impartiality are maintained in the exercise of their activities.
(3) Notifying authorities shall be structured in such a way that each decision on the notification of a conformity assessment body is taken by competent persons who are not the same as the persons who carried out the assessment.
(4) Notifying authorities may not offer or provide activities carried out by conformity assessment bodies or consultancy services on a commercial or competitive basis.
(5) Notifying authorities guarantee the confidentiality of the information they obtain.
(6) A notifying authority has a sufficient number of competent employees at its disposal so that it can perform its tasks properly.
Article 38 Information obligations of notifying authorities
(1) Member States shall inform the Commission of their procedures for the assessment and notification of conformity assessment bodies and for the monitoring of notified bodies and of any changes thereto.
(2) The Commission shall make the information referred to in paragraph 1 available to the public.
Article 39 Requirements for notified bodies
(1) Conformity assessment bodies shall meet the requirements set out in paragraphs 2 to 12 for the purposes of notification.
(2) A conformity assessment body is established under national law and has legal personality.
(3) A conformity assessment body is an independent third party that is independent of the organization or the product with digital elements that is being assessed.
A body belonging to a trade association or professional organization that assesses products with digital elements whose design, development, manufacture, provision, assembly, use or maintenance involves companies represented by that association may be considered as such an independent third party, provided that its independence and the absence of any conflict of interest are demonstrated.
(4) A conformity assessment body, its top level management and the personnel responsible for carrying out the conformity assessment tasks shall not be the designer, developer, manufacturer, supplier, importer, distributor, installer, purchaser, owner, user or maintainer of the products incorporating digital elements which they assess, nor the authorized representative of any of those parties. This does not exclude the use of products that have already undergone conformity assessment and are required for the activities of the conformity assessment body or the use of such products for personal use.
A conformity assessment body, its top level management and the personnel responsible for carrying out the conformity assessment tasks shall not be directly involved in the design, development, manufacture, import, distribution, marketing, installation, use or maintenance of those products with digital elements which they assess, or represent the parties engaged in those activities. They shall not engage in any activity that may conflict with their independence of judgment or integrity in relation to the conformity assessment activities for which they are notified. This applies in particular to consultancy services. Conformity assessment bodies shall ensure that the activities of their subsidiaries or subcontractors do not affect the confidentiality, objectivity or impartiality of their conformity assessment activities.
(5) Conformity assessment bodies and their personnel shall carry out the conformity assessment activities with the highest degree of professional integrity and the requisite technical competence in the specific field and shall be free from all pressures and inducements, particularly financial, which might influence their judgment or the results of their conformity assessment activities, especially as regards persons or groups of persons with an interest in the results of those activities.
(6) A conformity assessment body shall be capable of carrying out all the conformity assessment tasks assigned to it by Annex VIII and in relation to which it has been notified, whether those tasks are carried out by the conformity assessment body itself or on its behalf and under its responsibility.
At all times and for each conformity assessment procedure and each kind and category of devices with digital elements for which it has been notified, a conformity assessment body shall have at its disposal
a) the necessary personnel with specialist knowledge and sufficient relevant experience to perform the tasks involved in conformity assessment;
b) descriptions of procedures according to which conformity assessment shall be carried out in order to ensure the transparency and repeatability of those procedures. It shall have appropriate policies and procedures in place that distinguish between the tasks it performs as a notified body and other activities;
c) Procedures for carrying out activities with due regard to the size of a company, the sector in which it operates, its structure, the degree of complexity of the product technology in question and the mass production or series nature of the manufacturing process.
A conformity assessment body shall have the means necessary to perform the technical and administrative tasks connected with the conformity assessment activities in an appropriate manner and shall have access to all necessary equipment or facilities.
(7) The staff responsible for carrying out the conformity assessment activities must have the following:
a) sound technical and vocational training covering all conformity assessment activities in the field for which the conformity assessment body has been notified;
b) sufficient knowledge of the requirements associated with the assessments to be carried out and the corresponding authorization to carry out such assessments;
c) appropriate knowledge and understanding of the essential cybersecurity requirements set out in Annex I, the applicable harmonized standards and common specifications and the relevant Union harmonization legislation and its implementing legislation;
d) the ability to draw up certificates, protocols and reports as proof of assessments carried out.
(8) The impartiality of the conformity assessment bodies, their top-level management and their assessing personnel must be guaranteed.
The remuneration of the top management level and the assessing personnel of the conformity assessment body must not be based on the number of assessments carried out or their results.
(9) Conformity assessment bodies shall take out liability insurance unless liability is assumed under the national law of their Member State or the Member State itself is directly responsible for the conformity assessment.
(10) Information obtained by the personnel of a conformity assessment body in carrying out their tasks under Annex VIII or any provision of national law giving effect to it shall be covered by the obligation of professional secrecy, except in relation to the market surveillance authorities of the Member State in which its activities are carried out. Proprietary rights shall be protected. The conformity assessment body shall have documented procedures in place to ensure compliance with this paragraph.
(11) Conformity assessment bodies shall participate in, or ensure that their assessment personnel are informed of, the relevant standardization activities and the activities of the notified body coordination group established under Article 51 and shall apply as general guidance the administrative decisions and documents produced by that group.
(12) Conformity assessment bodies shall carry out their activities in accordance with a set of consistent, fair, proportionate and reasonable commercial conditions, avoiding unnecessary burdens on economic operators and taking into account the interests of micro, small and medium-sized enterprises, in particular with regard to fees.
Article 40 Presumption of conformity of notified bodies
Where a conformity assessment body demonstrates its conformity with the criteria laid down in the relevant harmonized standards the references of which have been published in the Official Journal of the European Union, or parts thereof, it shall be presumed to comply with the requirements set out in Article 39 in so far as the applicable standards cover those requirements.
Article 41 Branches of notified bodies and subcontracting by notified bodies
(1) Where a notified body subcontracts specific tasks connected with conformity assessment or has recourse to a subsidiary, it shall ensure that the subcontractor or the subsidiary meets the requirements laid down in Article 39 and shall inform the notifying authority accordingly.
(2) Notified bodies bear full responsibility for the work carried out by subcontractors or subsidiaries, regardless of where they are established.
(3) Work may only be subcontracted or assigned to a branch office with the manufacturer’s consent.
(4) Notified bodies shall keep at the disposal of the notifying authority the relevant documents concerning the assessment of the qualifications of the subcontractor or the subsidiary and the work carried out by them under this Regulation.
Article 42 Application for notification
(1) A conformity assessment body shall submit an application for notification to the notifying authority of the Member State in which it is established.
(2) The application shall be accompanied by a description of the conformity assessment activities, the conformity assessment procedure or procedures and the product or products with digital elements for which that body claims to be competent, as well as by an accreditation certificate, where applicable, issued by a national accreditation body attesting that the conformity assessment body fulfills the requirements laid down in Article 39.
(3) Where the conformity assessment body concerned cannot provide an accreditation certificate, it shall provide the notifying authority with all the documentary evidence necessary for the verification, recognition and regular monitoring of its compliance with the requirements laid down in Article 39.
Article 43 Notification procedure
(1) Notifying authorities shall notify only conformity assessment bodies which have satisfied the requirements laid down in Article 39.
(2) The notifying authority shall inform the Commission and the other Member States by means of the information system for New Approach notified and designated organizations developed and managed by the Commission.
(3) The notification shall contain full details of the conformity assessment activities, the conformity assessment module or modules and products with digital elements concerned and the relevant attestation of competence.
(4) Where a notification is not based on an accreditation certificate as referred to in Article 42(2), the notifying authority shall provide the Commission and the other Member States with documentary evidence which attests to the conformity assessment body’s competence and the arrangements in place to ensure that the body will be monitored regularly and will continue to satisfy the requirements laid down in Article 39.
(5) The body concerned may perform the tasks of a notified body only if neither the Commission nor the other Member States have raised objections within two weeks of the notification, if an accreditation certificate is available, or within two months of the notification, if no accreditation is available.
Only such a body shall be considered a notified body for the purposes of this Regulation.
(6) The Commission and the other Member States shall be informed of any subsequent relevant changes to the notification.
Article 44 Identification numbers and lists of notified bodies
(1) The Commission shall assign an identification number to each notified body.
Even if a body is notified under several Union acts, it will only receive a single identification number.
(2) The Commission shall publish the list of bodies notified under this Regulation, together with the identification numbers assigned to them and the activities for which they have been notified.
The Commission shall ensure that this list is always kept up to date.
Article 45 Amendments to notifications
(1) Where a notifying authority has ascertained or has been informed that a notified body no longer meets the requirements laid down in Article 39, or that it is failing to fulfil its obligations, the notifying authority shall restrict, suspend or withdraw notification as appropriate, depending on the extent to which those requirements have not been met or those obligations have not been fulfilled. It shall immediately inform the Commission and the other Member States thereof.
(2) In the event of restriction, suspension or withdrawal of notification, or where the notified body has ceased its activity, the notifying Member State shall take appropriate steps to ensure that the files of that body are either processed by another notified body or kept available for the responsible notifying and market surveillance authorities at their request.
Article 46 Contestation of the competence of notified bodies
(1) The Commission shall investigate all cases where it doubts, or doubt is brought to its attention regarding, the competence of a notified body or the continued fulfillment by a notified body of the requirements and responsibilities to which it is subject.
(2) The notifying Member State shall provide the Commission, on request, with all information relating to the basis of the notification or the maintenance of the competence of the body concerned.
(3) The Commission ensures that all sensitive information obtained in the course of its investigations is treated confidentially.
(4) Where the Commission ascertains that a notified body does not meet or no longer meets the requirements for its notification, it shall inform the notifying Member State accordingly and request it to take the necessary corrective measures, including withdrawal of notification if necessary.
Article 47 Operational obligations of notified bodies
(1) Notified bodies shall carry out conformity assessments in accordance with the conformity assessment procedures set out in Article 32 and Annex VIII.
(2) Conformity assessments shall be carried out in a proportionate manner, avoiding unnecessary burdens on economic operators. Conformity assessment bodies shall perform their activities taking due account of the size of the undertakings, in particular as regards micro, small and medium-sized enterprises, the sector in which they operate, their structure, the degree of complexity and cybersecurity risk of the products incorporating digital elements and technologies concerned and the mass or serial nature of the manufacturing process.
(3) However, notified bodies shall be as stringent and maintain such a level of protection as is necessary for the compliance of products incorporating digital elements with this Regulation.
(4) Where a notified body finds that the requirements set out in Annex I or in the corresponding harmonized standards or common specifications referred to in Article 27 have not been met by a manufacturer, it shall require that manufacturer to take appropriate corrective measures and shall not issue a certificate of conformity.
(5) Where, in the course of the monitoring of conformity following the issue of a certificate, a notified body finds that a device with digital elements no longer complies with the requirements laid down in this Regulation, it shall require the manufacturer to take appropriate corrective measures and shall suspend or withdraw the certificate if necessary.
(6) If corrective actions are not taken or do not have the necessary effect, the notified body shall restrict, suspend or revoke the certificates, as appropriate.
Article 48 Appeal against decisions of notified bodies
Member States shall ensure that an appeal procedure against the decisions of the notified bodies is provided for.
Article 49 Notification obligations of notified bodies
(1) Notified bodies shall notify the notifying authority of
a) all refusals, restrictions, suspensions and revocations of a certificate,
b) any circumstances affecting the scope and conditions of the notification,
c) all requests for information on conformity assessment activities received from the market surveillance authorities,
d) on request, the conformity assessment activities they have carried out within the scope of their notification and other activities, including cross-border activities and subcontracting, which they have carried out.
(2) Notified bodies shall provide the other bodies notified under this Regulation carrying out similar conformity assessment activities for the same devices incorporating digital elements with relevant information on negative and, on request, positive conformity assessment results.
Article 50 Exchange of experience
The Commission shall organize the exchange of experience between the national authorities of the Member States responsible for notification policy.
Article 51 Coordination of notified bodies
(1) The Commission shall ensure that appropriate coordination and cooperation between notified bodies is established and properly maintained in the form of a cross-sectoral group of notified bodies.
(2) Member States shall ensure that the bodies notified by them participate in the work of this group directly or through designated representatives.
Chapter V Market surveillance and enforcement
Article 52 Market surveillance and control of products with digital elements on the Union market
(1) Regulation (EU) 2019/1020 applies to the products with digital elements that fall within the scope of this Regulation.
(2) Each Member State shall designate one or more market surveillance authorities for the purpose of ensuring the effective implementation of this Regulation. Member States may designate an existing or a new authority to act as market surveillance authority under this Regulation.
(3) The market surveillance authorities designated pursuant to paragraph 2 of this Article shall also be responsible for carrying out market surveillance activities in relation to the obligations for open source software managers set out in Article 24. Where a market surveillance authority finds that an open source software manager does not comply with the obligations laid down in that Article, it shall require the open source software manager to ensure that all appropriate corrective action is taken. Administrators of open source software shall, as part of their obligations under this Regulation, ensure that all appropriate corrective action is taken.
(4) Market surveillance authorities shall, where appropriate, cooperate and regularly exchange information with the national cybersecurity certification authorities designated in accordance with Article 58 of Regulation (EU) 2019/881. When overseeing the implementation of the reporting obligations under Article 14 of this Regulation, the designated market surveillance authorities shall cooperate and regularly exchange information with the CSIRTs designated as coordinators and ENISA.
(5) Market surveillance authorities may request technical advice from the CSIRT designated as coordinator or ENISA on the implementation and enforcement of this Regulation. When carrying out an investigation pursuant to Article 54, market surveillance authorities may request the CSIRT designated as coordinator or ENISA to carry out an analysis to substantiate the conformity assessment of products incorporating digital elements.
(6) Market surveillance authorities shall, where appropriate, cooperate and regularly exchange information with other market surveillance authorities designated on the basis of Union harmonization legislation other than this Regulation for other products.
(7) Market surveillance authorities shall, where appropriate, cooperate with the authorities supervising the application of Union data protection law. Such cooperation shall include informing those authorities of any findings relevant to the exercise of their responsibilities, including on the issuance of guidelines and advice referred to in paragraph 10, where such guidelines and advice concern the processing of personal data.
The authorities supervising the application of Union data protection law shall have the power to require and access all documents created or maintained under this Regulation to the extent that access to those documents is necessary for the performance of their tasks. They shall inform the designated market surveillance authorities of the Member State concerned of any such request.
(8) Member States shall ensure that designated market surveillance authorities are provided with adequate financial and technical resources, including process automation tools where appropriate, and human resources with the necessary cybersecurity skills to carry out their tasks under this Regulation.
(9) The Commission promotes and facilitates the exchange of experience between the designated market surveillance authorities.
(10) Market surveillance authorities, assisted by the Commission and, where appropriate, the CSIRTs and ENISA, may provide guidance and advice to economic operators on the implementation of this Regulation.
(11) Market surveillance authorities shall, in accordance with Article 11 of Regulation (EU) 2019/1020, inform consumers where to submit complaints that may indicate non-compliance with this Regulation and provide consumers with information on where and how to access mechanisms to facilitate the reporting of vulnerabilities, security incidents and cyber threats that may affect products with digital elements.
(12) Market surveillance authorities shall, where appropriate, facilitate cooperation with relevant stakeholders, including scientific, research and consumer organizations.
(13) Market surveillance authorities shall report annually to the Commission on the results of their respective market surveillance activities. Designated market surveillance authorities shall notify the Commission and the relevant national competition authorities without delay of any information obtained in the course of their market surveillance activities that may be of interest for the application of Union competition law.
(14) For devices with digital elements falling within the scope of this Regulation and classified as high-risk AI-systems in accordance with Article 6 of Regulation (EU) 2024/1689, the market surveillance authorities designated for the purposes of that Regulation shall also be responsible for the market surveillance activities required under this Regulation. The market surveillance authorities designated under Regulation (EU) 2024/1689 shall cooperate, as appropriate, with the market surveillance authorities designated under this Regulation and, with regard to the supervision of the implementation of the notification obligations under Article 14 of this Regulation, with the CSIRTs designated as coordinators and ENISA. In particular, the market surveillance authorities designated under Regulation (EU) 2024/1689 shall inform the market surveillance authorities designated under this Regulation of any findings relevant to the performance of their tasks in relation to the implementation of this Regulation.
(15) In order to ensure the uniform application of this Regulation, the ADCO shall be set up in accordance with Article 30(2) of Regulation (EU) 2019/1020. The ADCO shall be composed of representatives of the designated market surveillance authorities and, where appropriate, representatives of the single liaison offices. The ADCO shall also address specific questions on market surveillance activities related to the obligations for open source software administrators.
(16) Market surveillance authorities shall monitor how manufacturers have applied the criteria referred to in Article 13(8) when determining the period of support for their products with digital elements.
ADCO shall publish, in a publicly accessible and user-friendly form, relevant statistics on categories of products incorporating digital elements, including the average support periods established by the manufacturer in accordance with Article 13(8), and provide guidance containing indicative support periods for categories of products incorporating digital elements. Where the data indicate insufficient support periods for certain categories of devices incorporating digital elements, ADCO may recommend to market surveillance authorities to focus their activities on such categories of devices incorporating digital elements.
Article 53 Access to data and documentation
To the extent necessary to assess the compliance of products incorporating digital elements and the procedures established by their manufacturers with the essential cybersecurity requirements set out in Annex I, market surveillance authorities shall have access, on reasoned request and in a language which they easily understand, to the data necessary to assess the design, development, manufacturing and vulnerability treatment of such products, including the relevant internal documentation of the economic operator concerned.
Article 54 National procedures for products with digital elements that pose a significant cybersecurity risk
(1) Where the market surveillance authority of a Member State has sufficient reason to believe that a product incorporating digital elements, including vulnerability handling, presents a significant cybersecurity risk, it shall immediately carry out a conformity assessment of the product concerned against the requirements laid down in this Regulation, where appropriate in cooperation with the relevant CSIRT. The relevant economic operators shall cooperate as necessary with the market surveillance authority.
Where, in the course of that evaluation, the market surveillance authority finds that the device with digital elements does not comply with the requirements laid down in this Regulation, it shall without delay require the relevant economic operator to take all appropriate corrective actions to bring the device with digital elements into compliance with those requirements, to withdraw the device from the market or to recall it within a reasonable period, commensurate with the nature of the cybersecurity risk, as it may prescribe. The market surveillance authority shall inform the relevant notified body thereof. Article 18 of Regulation (EU) 2019/1020 shall apply to the corrective action.
(2) When determining the significance of a cybersecurity risk in accordance with paragraph 1, market surveillance authorities shall also take into account non-technical risk factors, in particular those identified as a result of coordinated supply chain security risk assessments at Union level in accordance with Article 22 of Directive (EU) 2022/2555. Where a market surveillance authority has reasonable grounds to believe that a product with digital elements poses a significant cybersecurity risk in light of non-technical risk factors, it shall inform the competent authorities designated or established in accordance with Article 8 of Directive (EU) 2022/2555 and cooperate with those authorities as necessary.
(3) Where the market surveillance authority considers that the non-compliance is not restricted to its national territory, it shall inform the Commission and the other Member States of the results of the investigation and of the actions it has required the economic operator to take.
(4) The economic operator shall ensure that all appropriate corrective action is taken in respect of all the products with digital elements concerned that it has made available on the market throughout the Union.
(5) Where the economic operator does not take adequate corrective action within the period referred to in the second subparagraph of paragraph 1, the market surveillance authorities shall take all appropriate provisional measures to prohibit or restrict the product with digital elements being made available on their national market, to withdraw the product from that market or to recall it.
That authority shall notify the Commission and the other Member States of those measures without delay.
(6) The information referred to in paragraph 5 shall include all available details, in particular the data necessary for the identification of the non-compliant product with digital elements, the origin of that product with digital elements, the nature of the non-compliance alleged and the risk involved, the nature and duration of the national measures taken and the arguments put forward by the relevant economic operator. The market surveillance authority shall indicate in particular whether the non-compliance is due to one or more of the following:
a) The device with digital elements or the procedures defined by the manufacturer do not meet the essential cybersecurity requirements set out in Annex I;
b) shortcomings in the harmonized standards, the European cybersecurity certification schemes or the common specifications referred to in Article 27.
(7) The market surveillance authorities of the Member States, other than the one that initiated the procedure, shall immediately inform the Commission and the other Member States of any measures taken and of any additional information at their disposal relating to the non-compliance of the product concerned with digital elements, as well as of their objections in the event of disagreement with the national measure notified to them.
(8) Where neither a Member State nor the Commission raises an objection to a provisional measure taken by a Member State within three months of receipt of the notification referred to in paragraph 5 of this Article, that measure shall be deemed justified. This shall be without prejudice to the procedural rights of the economic operator concerned under Article 18 of Regulation (EU) 2019/1020.
(9) The market surveillance authorities of all Member States shall ensure that appropriate restrictive measures are taken without delay in respect of the product with digital elements concerned, for example by withdrawing that product from their market.
Article 55 Union safeguard clause procedure
(1) Where, within three months of receipt of the notification referred to in Article 54(5), a Member State objects to a measure taken by another Member State or where the Commission considers a measure to be incompatible with Union law, the Commission shall enter into consultations with the Member State or economic operator concerned without delay and shall examine the national measure. On the basis of the results of that examination, the Commission shall, within nine months of receipt of the information referred to in Article 54(5), decide whether the national measure is justified or not and communicate that decision to the Member State concerned.
(2) If the national measure is considered justified, all Member States shall take the necessary measures to ensure that the non-compliant product with digital elements is withdrawn from their market and shall inform the Commission accordingly. If the national measure is considered unjustified, the Member State concerned shall withdraw it.
(3) If the national measure is considered justified and the non-compliance of the product with digital elements is attributed to shortcomings in the harmonized standards, the Commission shall initiate the procedure laid down in Article 11 of Regulation (EU) No 1025/2012.
(4) Where the national measure is considered justified and the non-compliance of the product with digital elements is attributed to shortcomings in a European cybersecurity certification scheme referred to in Article 27, the Commission shall examine whether a delegated act adopted pursuant to Article 27(9) conferring a presumption of conformity in relation to that certification scheme should be amended or repealed.
(5) Where the national measure is considered justified and the non-compliance of the product with digital elements is attributed to shortcomings in common specifications referred to in Article 27, the Commission shall examine whether an implementing act adopted pursuant to Article 27(2), in which the common specifications have been laid down, should be amended or repealed.
Article 56 Union-level procedures for products with digital elements posing a significant cybersecurity risk
(1) Where the Commission has sufficient reason to believe, including on the basis of information provided by ENISA, that a device with digital elements presenting a significant cybersecurity risk does not comply with the requirements of this Regulation, it shall inform the relevant market surveillance authorities. Where the market surveillance authorities carry out a conformity assessment of that device with digital elements which may present a significant cybersecurity risk as regards its compliance with the requirements of this Regulation, the procedures referred to in Articles 54 and 55 shall apply.
(2) Where the Commission has sufficient reason to believe that a product with digital elements poses a significant cybersecurity risk due to non-technical risk factors, it shall inform the relevant market surveillance authorities and, where appropriate, the competent authorities designated or established pursuant to Article 8 of Directive (EU) 2022/2555 and cooperate with those authorities as necessary. The Commission shall also assess the relevance of the identified risks for that product with digital elements with regard to its tasks related to the coordinated risk assessments on supply chain security at Union level pursuant to Article 22 of Directive (EU) 2022/2555 and, where necessary, consult the Cooperation Group established pursuant to Article 14 of Directive (EU) 2022/2555 and ENISA.
(3) In circumstances justifying immediate intervention in order to preserve the proper functioning of the internal market, and where the Commission has sufficient reason to believe that the product with digital elements referred to in paragraph 1 continues not to comply with the requirements of this Regulation and the relevant market surveillance authorities have not taken effective action, the Commission shall carry out a compliance assessment and may request ENISA to carry out an analysis to substantiate the assessment. The Commission shall inform the relevant market surveillance authorities thereof. The relevant economic operators shall cooperate with ENISA to the extent necessary.
(4) On the basis of the assessment referred to in paragraph 3, the Commission may determine that a corrective or restrictive measure at Union level is necessary. For that purpose, it shall immediately consult the Member States and the economic operator or operators concerned.
(5) On the basis of the consultation referred to in paragraph 4 of this Article, the Commission may adopt implementing acts concerning corrective or restrictive measures at Union level, including requiring the withdrawal from the market or recall of the digital items concerned within a period proportionate to the nature of the risk. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 62(2).
(6) The Commission shall inform the relevant economic operator or operators without delay of the implementing acts referred to in paragraph 5. Member States shall implement those implementing acts without delay and inform the Commission thereof.
(7) Paragraphs 3 to 6 shall apply for the duration of the exceptional circumstances that justified the Commission’s intervention, as long as the product concerned with digital elements has not been brought into conformity with this Regulation.
Article 57 Compliant products with digital elements that pose a significant cybersecurity risk
(1) The market surveillance authority of a Member State shall require an economic operator to take all appropriate measures where, having carried out an evaluation in accordance with Article 54, it finds that a device with digital elements and the procedures established by the manufacturer, although compliant with this Regulation, presents a significant cybersecurity risk and the following risks:
a) Risk to the health or safety of persons,
b) Risk to the fulfillment of obligations under Union or national law for the protection of fundamental rights,
c) risk to the availability, authenticity, integrity or confidentiality of services provided through an electronic information system by essential entities referred to in Article 3(1) of Directive (EU) 2022/2555; or
d) Risk to other aspects of the protection of public interests.
The measures referred to in the first subparagraph may include measures to ensure that the device with digital elements concerned and the procedures established by the manufacturer no longer present the relevant risks when the device with digital elements concerned is made available on the market, withdrawn from the market or recalled, and shall be proportionate to the nature of those risks.
(2) The manufacturer or other relevant economic operator shall ensure that corrective action is taken in respect of all the products with digital elements concerned that it has made available on the market throughout the Union within the time limit set by the market surveillance authority of the Member State referred to in paragraph 1.
(3) The Member State shall immediately inform the Commission and the other Member States of any measures taken pursuant to paragraph 1. That information shall include all available details, in particular the data identifying the product with digital elements concerned, its origin and supply chain, the nature of the risk involved and the nature and duration of the national measures taken.
(4) The Commission shall without delay enter into consultation with the Member States and the relevant economic operator and shall carry out an examination of the national measures taken. On the basis of the results of that examination, the Commission shall decide whether the measure is justified or not and, if necessary, propose appropriate measures.
(5) The Commission shall address the decision referred to in paragraph 4 to the Member States.
(6) Where the Commission has sufficient reason to believe, including on the basis of information from ENISA, that a device incorporating digital elements, although complying with this Regulation, presents the risks referred to in paragraph 1 of this Article, it shall inform the relevant market surveillance authority or authorities and may request them to carry out an evaluation and apply the procedures referred to in Article 54 and in paragraphs 1, 2 and 3 of this Article.
(7) In circumstances justifying immediate intervention in order to preserve the proper functioning of the internal market, and where the Commission has sufficient reason to believe that the product with digital elements referred to in paragraph 6 continues to present the risks referred to in paragraph 1 and the relevant market surveillance authorities have not taken effective action, the Commission shall carry out an assessment of the risks posed by that product with digital elements and may request ENISA to carry out an analysis to substantiate that assessment and shall inform the relevant market surveillance authorities thereof. The relevant economic operators shall cooperate with ENISA to the extent necessary.
(8) On the basis of the assessment referred to in paragraph 7, the Commission may determine that a corrective or restrictive measure at Union level is necessary. For that purpose, it shall immediately consult the Member States and the economic operator or operators concerned.
(9) On the basis of the consultation referred to in paragraph 8 of this Article, the Commission may adopt implementing acts concerning corrective or restrictive measures at Union level, including requiring the withdrawal from the market or recall of the digital items concerned within a period proportionate to the nature of the risk. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 62(2).
(10) The Commission shall inform the relevant economic operator or operators without delay of the implementing acts referred to in paragraph 9. Member States shall implement those implementing acts without delay and inform the Commission thereof.
(11) Paragraphs 6 to 10 shall apply for the duration of the exceptional circumstances that justified the Commission’s intervention and as long as the product concerned with digital elements continues to present the risks referred to in paragraph 1.
Article 58 Formal non-conformity
(1) Where the market surveillance authority of a Member State makes one of the following findings, it shall require the manufacturer concerned to remedy the non-compliance in question:
a) the CE marking has been affixed in non-compliance with Articles 29 and 30;
b) the CE marking has not been affixed;
c) the EU Declaration of Conformity has not been issued;
d) the EU Declaration of Conformity has not been properly issued;
e) the identification number of the notified body involved in the conformity assessment procedure, if applicable, has not been affixed;
f) the technical documentation is either not available or not complete.
(2) Where the non-compliance referred to in paragraph 1 persists, the Member State concerned shall take all appropriate measures to restrict or prohibit the product with digital elements being made available on the market or ensure that it is recalled or withdrawn from the market.
Article 59 Joint activities of market surveillance authorities
(1) Market surveillance authorities may agree with other relevant authorities to carry out joint activities to ensure cybersecurity and consumer protection in relation to specific products with digital elements placed or made available on the market, in particular in relation to products with digital elements where cybersecurity risks are frequently identified.
(2) The Commission or ENISA shall propose joint compliance verification activities to be carried out by market surveillance authorities on the basis of indications or information that products incorporating digital elements falling within the scope of this Regulation may not comply with the requirements of this Regulation in several Member States.
(3) Market surveillance authorities and, where appropriate, the Commission shall ensure that the joint activity agreement does not lead to unfair competition between economic operators and does not affect the objectivity, independence or impartiality of the parties to the agreement.
(4) A market surveillance authority may use any information it has obtained in the course of joint activities that were part of an investigation it carried out.
(5) The market surveillance authority concerned and, where appropriate, the Commission shall make the agreement on joint activities, including the names of the parties involved, available to the public.
Article 60 Coordinated checks (sweeps)
(1) Market surveillance authorities shall carry out simultaneous coordinated inspections (’sweeps’) of certain products incorporating digital elements to verify compliance with this Regulation or to detect infringements of this Regulation. These sweeps may also include the inspection of products with digital elements purchased under a false identity.
(2) Unless otherwise agreed by the market surveillance authorities concerned, such sweeps shall be coordinated by the Commission. The coordinator of the sweep shall publish the aggregated results as appropriate.
(3) Where ENISA, in the performance of its tasks, identifies categories of products with digital elements for which sweeps may be organized, including on the basis of notifications received pursuant to Article 14(1) and (3), it shall submit a proposal for sweeps to the coordinator referred to in paragraph 2 of this Article for consideration by the market surveillance authorities.
(4) When carrying out sweeps, the market surveillance authorities involved may use the investigatory powers laid down in Articles 52 to 58 and other powers conferred on them by national law.
(5) Market surveillance authorities may invite Commission officials and other accompanying persons authorized by the Commission to participate in sweeps.
Chapter VI Delegated powers and committee procedures
Article 61 Exercise of the delegation of power
(1) The power to adopt delegated acts is conferred on the Commission subject to the conditions laid down in this Article.
(2) The power to adopt delegated acts referred to in the second subparagraph of Article 2(5), Article 7(3), Article 8(1) and (2), the fourth subparagraph of Article 13(8), Article 14(9), Article 25, Article 27(9), Article 28(5) and Article 31(5) shall be conferred on the Commission for a period of five years from 10 December 2024. The Commission shall draw up a report in respect of the delegation of power not later than nine months before the end of the five-year period. The delegation of power shall be tacitly extended for periods of an identical duration, unless the European Parliament or the Council opposes such extension not later than three months before the end of each period.
(3) The delegation of power referred to in the second subparagraph of Article 2(5), Article 7(3), Article 8(1) and (2), the fourth subparagraph of Article 13(8), Article 14(9), Article 25, Article 27(9), Article 28(5) and Article 31(5) may be revoked at any time by the European Parliament or by the Council. A decision of revocation shall put an end to the delegation of the power specified in that decision. It shall take effect the day following the publication of the decision in the Official Journal of the European Union or at a later date specified therein. The decision of revocation shall not affect the validity of any delegated acts already in force.
(4) Before adopting a delegated act, the Commission shall consult experts designated by each Member State in accordance with the principles laid down in the Interinstitutional Agreement of April 13, 2016 on Better Law-Making.
(5) As soon as it adopts a delegated act, the Commission shall notify it simultaneously to the European Parliament and to the Council.
(6) A delegated act adopted pursuant to the second subparagraph of Article 2(5), Article 7(3), Article 8(1) or (2), the fourth subparagraph of Article 13(8), Article 14(9), Article 25, Article 27(9), Article 28(5) or Article 31(5) shall enter into force only if no objection has been expressed either by the European Parliament or the Council within a period of two months of notification of that act to the European Parliament and the Council or if, before the expiry of that period, the European Parliament and the Council have both informed the Commission that they will not object. That period shall be extended by two months at the initiative of the European Parliament or the Council.
Article 62 Committee procedure
(1) The Commission shall be assisted by a committee. This committee shall be a committee within the meaning of Regulation (EU) No 182/2011.
(2) Where reference is made to this paragraph, Article 5 of Regulation (EU) No 182/2011 shall apply.
(3) If the opinion of the Committee is obtained by written procedure, the procedure shall be terminated without result if the Chair of the Committee so decides within the time limit for delivery of the opinion or if a member of the Committee so requests.
Chapter VII Confidentiality and sanctions
Article 63 Confidentiality
(1) All parties involved in the application of this Regulation shall respect the confidentiality of the information and data of which they become aware in the course of their duties and activities, and shall in particular protect the following:
a) Intellectual property rights, confidential business information or trade secrets of natural or legal persons, including source code, with the exception of the cases referred to in Article 5 of Directive (EU) 2016/943 of the European Parliament and of the Council (37),
b) the effective implementation of this Regulation, in particular for the purposes of inspections, investigations or audits,
c) public and national security interests,
d) the integrity of criminal or administrative proceedings.
(2) Without prejudice to paragraph 1, information exchanged on a confidential basis between market surveillance authorities or with the Commission shall not be disclosed without the prior consent of the market surveillance authority from which the information originated.
(3) Paragraphs 1 and 2 shall not affect the rights and obligations of the Commission, Member States and notified bodies in relation to the exchange of information and the dissemination of alerts, nor the obligations of data subjects to provide information on the basis of the criminal law of the Member States.
(4) The Commission and the Member States may, where necessary, exchange sensitive information with relevant authorities of third countries with which they have concluded bilateral or multilateral confidentiality agreements and which ensure an adequate level of protection.
Article 64 Sanctions
(1) Member States shall lay down rules on penalties applicable to infringements of this Regulation and shall take all measures necessary to ensure that they are implemented. The penalties provided for must be effective, proportionate and dissuasive. The Member States shall notify those provisions and measures to the Commission without delay and shall notify it without delay of any subsequent amendment affecting them.
(2) Non-compliance with the essential cybersecurity requirements set out in Annex I or breaches of the obligations set out in Articles 13 and 14 shall be subject to fines of up to EUR 15 000 000 or, in the case of companies, up to 2.5 % of the total worldwide annual turnover of the preceding financial year, whichever is higher.
(3) Infringements of the obligations laid down in Articles 18 to 23, Article 28, Article 30(1) to (4), Article 31(1) to (4), Article 32(1), (2) and (3), Article 33(5) and Articles 39, 41, 47, 49 and 53 shall be subject to fines of up to EUR 10 000 000 or, in the case of undertakings, up to 2 % of the total worldwide annual turnover in the preceding business year, whichever is the higher.
(4) Where false, incomplete or misleading information is provided to notified bodies and market surveillance authorities in response to their requests for information, fines of up to EUR 5 000 000 or, in the case of companies, up to 1 % of the total annual worldwide turnover in the preceding business year, whichever is the higher, will be imposed.
(5) When setting the fine, all relevant circumstances of the specific situation and the following are duly taken into account in each individual case:
a) Type, severity and duration of the violation and its consequences,
b) whether the same or other market surveillance authorities have already imposed fines on the same economic operator for a similar infringement,
c) Size, in particular with regard to micro, small and medium-sized enterprises, including start-ups, and market share of the economic operator that committed the infringement.
(6) Market surveillance authorities that impose fines shall notify the imposition of a fine to the market surveillance authorities of the other Member States through the information and communication system referred to in Article 34 of Regulation (EU) 2019/1020.
(7) Each Member State shall lay down rules on whether and to what extent administrative fines may be imposed on public authorities and bodies established in that Member State.
(8) Depending on the legal system of the Member State concerned, the rules on fines may be applied in such a way that the fines are imposed by competent national courts or by other bodies in accordance with the allocation of jurisdiction established at national level in the Member States. The application of those rules in those Member States shall have equivalent effect.
(9) Fines may be imposed in addition to other corrective or restrictive measures imposed by market surveillance authorities for the same infringement, depending on the circumstances of the individual case.
(10) By way of derogation from paragraphs 3 to 9, the fines referred to in these paragraphs shall not apply to
a) producers that qualify as micro or small enterprises in relation to non-compliance with the time limit referred to in Article 14(2)(a) or Article 14(4)(a),
b) administrator of open source software for any violation of this regulation.
Article 65 Representative actions
Directive (EU) 2020/1828 shall apply to representative actions brought against infringements by economic operators of the provisions of this Regulation which harm or threaten to harm the collective interests of consumers.
Chapter VIII Transitional and final provisions
Article 66 Amendment to Regulation (EU) 2019/1020
In Annex I to Regulation (EU) 2019/1020, the following point is added: “72. Regulation (EU) 2024/2847 of the European Parliament and of the Council (*1).
Article 67 Amendment to Directive (EU) 2020/1828
In Annex I to Directive (EU) 2020/1828, the following point is added “(69) Regulation (EU) 2024/2847 of the European Parliament and of the Council (*2).
Article 68 Amendments to Regulation (EU) No 168/2013
In Part C1 of Annex II to Regulation (EU) No 168/2013 of the European Parliament and of the Council (38), the following entry is added to the table: “[…]”
Article 69 Transitional provisions
(1) EU-type examination certificates and approvals issued in relation to cybersecurity requirements for products with digital elements that are subject to Union harmonization legislation other than this Regulation shall remain valid until 11 June 2028, unless they expire before that date or unless otherwise provided for in other Union harmonization legislation, in which case they shall remain valid in accordance with the latter legislation.
(2) Products with digital elements placed on the market before December 11, 2027 shall be subject to the requirements laid down in this Regulation only if those products are subject to a substantial modification after that date.
(3) By way of derogation from paragraph 2 of this Article, the obligations laid down in Article 14 shall apply to all devices with digital elements that fall within the scope of this Regulation and were placed on the market before December 11, 2027.
Article 70 Assessment and verification
(1) By December 11, 2030, and every four years thereafter, the Commission shall submit a report to the European Parliament and the Council on the evaluation and review of this Regulation. The reports shall be published.
(2) By 11 September 2028, the Commission shall, after consulting ENISA and the CSIRTs network, submit a report to the European Parliament and to the Council assessing the effectiveness of the single notification platform referred to in Article 16 and the impact of the invocation of the cybersecurity grounds referred to in Article 16(2) by the CSIRTs designated as coordinators on the effectiveness of the single notification platform with regard to the timely transmission of notifications received to other relevant CSIRTs.
Article 71 Entry into force and date of application
(1) This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
(2) This Regulation shall apply from December 11, 2027, but Article 14 shall apply from September 11, 2026 and Chapter IV (Articles 35 to 51) shall apply from June 11, 2026. This Regulation shall be binding in its entirety and directly applicable in all Member States.
Attachments
Annex I Basic cybersecurity requirements
Part I Cybersecurity requirements relating to the characteristics of products with digital elements
(1) Products with digital elements are designed, developed and manufactured in such a way that they guarantee an appropriate level of cyber security in view of the risks.
(2) On the basis of the cybersecurity risk assessment referred to in Article 13(2), products with digital elements shall, where applicable
a) are made available on the market without known exploitable vulnerabilities,
b) be made available on the market with a secure default configuration, unless otherwise agreed between the manufacturer and the professional user in relation to a customized product with digital elements, and offer the possibility to restore the product to its original state,
c) ensure that vulnerabilities can be addressed through security updates, including, where appropriate, through automatic security updates that are installed by default within a reasonable timeframe and have a clear and user-friendly opt-out mechanism where users are notified of available updates and can temporarily postpone them;
d) provide protection against unauthorized access through appropriate control mechanisms, including at least authentication, identity or access management systems, and report any unauthorized access,
e) protect the confidentiality of stored, transmitted or otherwise processed personal or other data, e.g. by encrypting relevant data that is stored or in the process of being used or transmitted, through state-of-the-art mechanisms and by using other technical means,
f) protect the integrity of stored, transmitted or otherwise processed data, whether personal or other data, commands, programs and configurations from manipulation or modification not authorized by the user and report any damage,
g) limit the processing of personal or other data to that which is appropriate and relevant and to the extent necessary for the purpose of the product with digital elements (“data minimization”),
h) ensure the availability of essential and basic functions, even after a security incident, including via defense and containment measures against denial-of-service attacks,
i) minimize the negative impact of the products themselves or of networked devices on the availability of services provided by other devices or networks,
j) are designed, developed and manufactured in such a way that they offer as few attack surfaces as possible – even with external interfaces,
k) are designed, developed and manufactured in such a way that the impact of a security incident is reduced by appropriate mechanisms and techniques to mitigate the potential exploitation,
l) provide security-related information by recording and/or monitoring relevant internal processes such as access to and changes to data, services or functions and provide users with an opt-out mechanism,
m) Provide users with the ability to securely and easily delete all data and settings permanently and, if this data can be transferred to other products or systems, ensure that this is done in a secure manner.
Part II Requirements for the treatment of vulnerabilities
Manufacturers of products with digital elements must
(1) Identify and document weak points and components of the products with digital elements, e.g. by creating a software parts list in a common machine-readable format that shows at least the top-level dependencies of the products;
(2) with regard to the risks associated with the products with digital elements, promptly address and remedy vulnerabilities, including by providing security updates; where technically feasible, new security updates must be provided separately from functional updates;
(3) regularly and effectively test and check the safety of the product with digital elements;
(4) as soon as a security update has been made available, share and publish information about remediated vulnerabilities, including a description of the vulnerabilities with details that allow users to identify the affected product with digital elements, the impact of the vulnerabilities and their severity, and clear and understandable information to help users to address the vulnerabilities; in duly justified cases, where manufacturers consider that the risks of disclosure outweigh the benefits in terms of security, they may delay the disclosure of information on a fixed vulnerability until users have been given the opportunity to apply the relevant patch;
(5) Establish and implement a strategy for the coordinated disclosure of vulnerabilities;
(6) take measures to facilitate the exchange of information on possible vulnerabilities in their product with digital elements and third-party components contained therein, including by providing a contact address for reporting vulnerabilities discovered in the product with digital elements;
(7) Provide mechanisms for the secure distribution of updates for products with digital elements so that vulnerabilities are addressed or mitigated in a timely manner and, where appropriate, automatically in the case of security updates;
(8) ensure that security updates available to address identified security issues are disseminated promptly and, unless otherwise agreed between the manufacturer and the professional user in relation to a customized product with digital elements, free of charge, together with notices and relevant information, including on possible actions to be taken.
Appendix II Information and instructions for the user
The product with digital elements must be accompanied by at least the following:
1.Name, registered trade name or registered trade mark of the manufacturer, the postal address, e‑mail address or other digital contact option and, if available, website where the manufacturer can be contacted;
2.the central contact point where information about vulnerabilities of the product with digital elements can be reported and received and where the concept for the coordinated disclosure of vulnerabilities can be found;
3.Name and type as well as any additional information that allows the product to be uniquely identified with digital elements;
4.the intended purpose of the product with digital elements, including the security environment provided by the manufacturer, as well as the main functions of the product and information on the security features;
5.any known or foreseeable circumstances related to the intended use of the product with digital elements or its reasonably foreseeable misuse that could lead to significant cybersecurity risks;
6.where applicable, the Internet address at which the EU Declaration of Conformity is available;
7.the type of technical security support offered by the manufacturer and the end date of the support period during which users can expect to receive vulnerability fixes and security updates;
8.detailed instructions or an Internet address that refers to such detailed instructions and information,
a) the measures that must be taken when the product with digital elements is first put into operation and throughout its service life to ensure its safe use,
b) how changes to the product with digital elements can affect data security,
c) how security-relevant updates can be installed,
d) how to safely decommission the product with digital elements and how user data can be safely removed;
e) how to disable the default setting that enables the automatic installation of security updates in accordance with Annex I, Part I(c);
f) how the integrator can meet the essential cybersecurity requirements in Annex I and the technical documentation requirements in Annex VII when the product with digital elements is intended for integration with other products with digital elements;
9.in the event that the manufacturer makes the software parts list available to the user, where the software parts list can be accessed.
Appendix III Important products with digital elements
Class I
1.Identity management systems and software and hardware for managing privileged access, including readers for authentication and access control, including biometric readers
2.Standalone and embedded browsers
3.Password manager
4.Software for searching, removing and quarantining malware
5.Products with digital elements with the function of a virtual private network (VPN)
6.Network management systems
7.Systems for the management of security information and events (SIEM)
8.Boot manager
9.Public key infrastructures and software for issuing digital certificates
10.Physical and virtual network interfaces
11.Operating systems
12.Routers, modems for the Internet connection and switches
13.Microprocessors with safety-relevant functions
14.Microcontroller with safety-relevant functions
15.Application-specific integrated circuits (ASIC) and FPGA (Field Programmable Gate Array) with safety-relevant functions
16.Virtual assistants for the intelligent home environment with a general purpose
17.Products for the smart home environment with security functions, including smart door locks, security cameras, baby monitoring systems and alarm systems
18.Internet-connected toys covered by Directive 2009/48/EC of the European Parliament and of the Council (1) with social interaction functions (e.g. talking or filming) or positioning functions
19.wearable devices intended for the purpose of health monitoring (e.g. tracking) and not covered by Regulations (EU) 2017/745 or (EU) 2017/746, or wearable devices intended for use by and for children
Class II
1.Hypervisors and container runtime systems that support virtualized execution of operating systems and similar environments
2.Firewalls, intrusion detection systems and intrusion prevention systems
3.Tamper-proof microprocessors
4.Tamper-proof microcontroller
(1) Directive 2009/48/EC of the European Parliament and of the Council of June 18, 2009 on the safety of toys (OJ L 170, 30.6.2009, p. 1).
Annex IV Critical products with digital elements
1. hardware devices with security boxes 2. smart meter gateways in smart metering systems as defined in point (23) of Article 2 of Directive (EU) 2019/944 of the European Parliament and of the Council (1) and other devices for advanced security purposes, including secure crypto processing 3. smart cards or similar devices, including security elements
(1) Directive (EU) 2019/944 of the European Parliament and of the Council of June 5, 2019 concerning common rules for the internal market in electricity and amending Directive 2012/27/EU (OJ L 158, 14.6.2019, p. 125).
Annex V EU Declaration of Conformity
The EU declaration of conformity pursuant to Article 28 shall contain all of the following information:
1.the name and type and any additional information that allows the product to be uniquely identified with digital elements
2.the name and address of the manufacturer or his authorized representative
3.a declaration that the supplier bears sole responsibility for issuing the EU declaration of conformity
4.the object of the declaration (designation of the product with digital elements for traceability, with photo if necessary)
5.a declaration that the object of the declaration described above complies with the relevant Union harmonization legislation
6.references to the relevant harmonized standards or other common specifications used or the cybersecurity certification for which conformity is declared
7.where applicable, the name and identification number of the notified body, a description of the conformity assessment procedure carried out and the identification number of the certificate issued
8.Further information:
Signed for and on behalf of: (place and date of issue) (Name, function) (Signature):
Annex VI Simplified EU Declaration of Conformity
The simplified EU declaration of conformity referred to in Article 13(20) shall be worded as follows: ‘Hereby, … [name of the manufacturer] declares that the type of product with digital elements … [name of the type of product with digital elements] is in conformity with Regulation (EU) 2024/2847 (1). The full text of the EU declaration of conformity can be found at the following internet address …
(1) OJ L, 2024/2847, 20.11.2024, ELI: http://data.europa.eu/eli/reg/2024/2847/oj.
Annex VII Contents of the technical documentation
The technical documentation referred to in Article 31 shall contain at least the following information, insofar as it is relevant to the digital element product concerned:
1.a general description of the product with digital elements, including
a) its intended purpose,
b) Software versions that affect the fulfillment of basic cybersecurity requirements,
c) if the product with digital elements is a hardware product: Photographs or illustrations showing external features, markings and internal structure;
d) Information and instructions for users in accordance with Annex II;
2.a description of the design, development and manufacture of the product with digital elements and the vulnerability handling procedures, including
a) necessary information on the design and development of the product with digital elements, including drawings and schematics where appropriate and/or a description of the system architecture showing how software components build on each other, interact with each other and integrate into the overall processing;
b) required information and specifications regarding the vulnerability handling procedures established by the manufacturer, including the software bill of materials, the approach to coordinated vulnerability disclosure, evidence of the provision of a contact address for vulnerability reporting, and a description of the technical solutions chosen for the secure distribution of updates;
c) required information and specifications regarding the manufacturing and monitoring processes of the product with digital elements and the validation of these processes;
3.an assessment of the cybersecurity risks considered in the design, development, manufacture, supply and maintenance of the device with digital elements referred to in Article 13, including the extent to which the essential cybersecurity requirements set out in Part I of Annex I apply;
4.relevant information taken into account when determining the support period in accordance with Article 13(8) of the product with digital elements;
5.a list of the fully or partially applied harmonized standards, the references of which have been published in the Official Journal of the European Union, common specifications referred to in Article 27 of this Regulation or European cybersecurity certification schemes referred to in Article 27(8) of this Regulation, adopted in accordance with Regulation (EU) 2019/881 and, where no such harmonized standards, common specifications and European cybersecurity certification schemes are applied, descriptions of the solutions meeting the essential cybersecurity requirements set out in Parts I and II of Annex I, together with a list of other relevant technical specifications applied. In case of partial application of harmonized standards, common specifications or European cybersecurity certification schemes, the technical documentation shall indicate which parts have been applied;
6.Reports on the tests and examinations carried out to verify the conformity of the product with digital elements and vulnerability handling procedures with the applicable essential cybersecurity requirements set out in Parts I and II of Annex I;
7.a copy of the EU Declaration of Conformity;
8.where applicable, at the reasoned request of the market surveillance authority, the software BOM, where necessary to enable that authority to verify compliance with the essential cybersecurity requirements set out in Annex I.
Annex VIII Conformity assessment procedures
Part I Conformity assessment procedures based on internal control (based on Module A)
1.Internal control is the conformity assessment procedure whereby the manufacturer fulfills the obligations laid down in points 2, 3 and 4 of this Part, and ensures and declares on its sole responsibility that the devices incorporating digital elements satisfy all the essential cybersecurity requirements set out in Part I of Annex I and that the manufacturer satisfies the essential cybersecurity requirements set out in Part II of Annex I.
2.The manufacturer shall draw up the technical documentation in accordance with Annex VII.
3.Design, development, production and treatment of vulnerabilities in products with digital elements
The manufacturer shall take all measures necessary so that the design, development, manufacturing and vulnerability treatment processes and their monitoring ensure conformity of the manufactured or developed devices with digital elements and of the procedures defined by the manufacturer with the essential cybersecurity requirements set out in Parts I and II of Annex I.
4.Conformity marking and declaration of conformity
4.1.The manufacturer shall affix the CE marking to each individual device incorporating digital elements that satisfies the applicable requirements laid down in this Regulation.
4.2.The manufacturer shall draw up a written EU declaration of conformity in accordance with Article 28 for each device incorporating digital elements and keep it together with the technical documentation at the disposal of the national authorities for 10 years after the device incorporating digital elements has been placed on the market or for the duration of the support period, whichever is the longer. The EU declaration of conformity shall identify the product with digital elements for which it has been drawn up. A copy of the EU declaration of conformity shall be made available to the relevant authorities upon request.
5.Authorized representative
The manufacturer’s obligations set out in point 4 may be fulfilled by his authorized representative, on his behalf and under his responsibility, provided that the relevant obligations are specified in the mandate.
Part II EU type-examination (based on module B)
1.EU type-examination is the part of a conformity assessment procedure in which a notified body examines and verifies the technical design and development of a device incorporating digital elements and the procedures adopted by the manufacturer to address vulnerabilities, and then certifies that a device incorporating digital elements meets the essential cybersecurity requirements set out in Part I of Annex I and that the manufacturer complies with the essential cybersecurity requirements set out in Part II of Annex I.
2.The EU-type examination shall be carried out as an assessment of the adequacy of the technical design and development of the product with digital elements through examination of the technical documentation and supporting evidence referred to in point 3 and examination of specimens of one or more essential parts of the product (combination of production type and design type).
3.The application for EU type-examination is submitted by the manufacturer to a single notified body of his choice.
The application contains
3.1.the name and address of the manufacturer and, if the application is submitted by the authorized representative, the name and address of the authorized representative;
3.2.a written declaration that the same application has not been submitted to any other notified body;
3.3.the technical documentation that makes it possible to assess the conformity of the device with digital elements with the applicable essential cybersecurity requirements set out in Part I of Annex I and the manufacturer’s procedures for addressing vulnerabilities set out in Part II of Annex I; it shall also include an adequate risk analysis and assessment. The technical documentation shall specify the applicable requirements and cover the design, manufacture and operation of the device with digital elements, where relevant for the assessment. The technical documentation shall contain at least the elements listed in Annex VII, where applicable;
3.4.additional evidence of the adequacy of the technical design and development solutions and of the vulnerability management procedures. This supporting evidence shall mention any documents that have been used, in particular where the relevant harmonized standards or technical specifications have not been applied in full. The supporting evidence shall include, where necessary, the results of tests carried out by an appropriate laboratory of the manufacturer or by another testing laboratory on his behalf and under his responsibility.
4.The notified body
4.1.examine the technical documentation and supporting evidence to assess the compliance of the technical design and development of the device with digital elements with the essential cybersecurity requirements set out in Part I of Annex I and of the vulnerability handling procedures defined by the manufacturer with the essential cybersecurity requirements set out in Part II of Annex I;
4.2.verifies that the specimen(s) have been designed or manufactured in conformity with the technical documentation, which elements have been designed and developed in accordance with the applicable provisions of the relevant harmonized standards or technical specifications and which elements have been designed and developed without applying the relevant provisions of these standards;
4.3.carry out appropriate examinations and tests, or have them carried out, to check whether, where the manufacturer has chosen to apply the solutions in the relevant harmonized standards or technical specifications, these have been applied correctly in relation to the requirements set out in Annex I;
4.4.carry out appropriate examinations and tests, or have them carried out, to check whether, where the manufacturer has not applied the solutions set out in the relevant harmonized standards or technical specifications covering the requirements set out in Annex I, the solutions adopted by the manufacturer meet the corresponding essential cybersecurity requirements;
4.5.agrees with the manufacturer where the tests and inspections will be carried out.
5.The notified body shall draw up an assessment report on the activities carried out under point 4 and their results. Without prejudice to its obligations vis-à-vis the notifying authorities, the notified body shall release the content of that report, in full or in part, only with the agreement of the manufacturer.
6.Where the type and the vulnerability treatment procedures meet the essential cybersecurity requirements set out in Annex I, the notified body shall issue an EU-type examination certificate to the manufacturer. The certificate shall contain the name and address of the manufacturer, the conclusions of the examination, the conditions (if any) for its validity and the necessary data for identification of the approved type and vulnerability treatment process. The certificate may be accompanied by one or more annexes.
The certificate and its annexes shall contain all relevant information to allow the conformity of manufactured or designed products incorporating digital elements with the examined type and the conformity of the vulnerability management procedures to be evaluated and, where appropriate, to allow for in-service control. Where the type and the vulnerability management procedures do not satisfy the applicable essential cybersecurity requirements set out in Annex I, the notified body shall refuse to issue an EU-type examination certificate and shall inform the applicant accordingly, giving detailed reasons for its refusal.
7.The notified body shall keep itself apprised of any changes in the generally acknowledged state of the art which indicate that the approved type and vulnerability treatment procedures no longer meet the applicable essential cybersecurity requirements set out in Annex I, and shall determine whether such changes require further investigation. Where this is the case, the notified body shall inform the manufacturer accordingly.
The manufacturer shall inform the notified body that holds the technical documentation relating to the EU-type examination certificate of all modifications to the approved type and the procedure for addressing vulnerabilities that may affect the conformity with the essential cybersecurity requirements set out in Annex I or the conditions for validity of the certificate. Such changes shall require additional approval in the form of an addition to the original EU-type examination certificate.
8.The notified body shall periodically carry out audits to ensure that the vulnerability management procedures set out in Part II of Annex I are adequately implemented.
9.Each notified body shall inform its notifying authorities concerning the EU-type examination certificates and any additions thereto which it has issued or withdrawn, and shall, periodically or upon request, make available to its notifying authorities the list of certificates and any additions thereto refused, suspended or otherwise restricted.
Each notified body shall inform the other notified bodies concerning the EU-type examination certificates and any additions thereto which it has refused, withdrawn, suspended or otherwise restricted, and, upon request, concerning the certificates and additions thereto which it has issued. On request, the Commission, the Member States and the other notified bodies may obtain a copy of the EU-type examination certificates and any additions thereto. The Commission and the Member States may, on request, obtain a copy of the technical documentation and the results of the examinations carried out by the notified body. The notified body shall keep a copy of the EU-type examination certificate, its annexes and additions, as well as the technical file including the documentation submitted by the manufacturer, until the expiry of the validity of the certificate.
10.The manufacturer shall keep a copy of the EU-type examination certificate, its annexes and additions together with the technical documentation at the disposal of the national authorities for 10 years after the product with digital elements has been placed on the market or during the support period, whichever is the longer.
11.The manufacturer’s authorized representative may submit the application referred to in point 3 and fulfil the obligations set out in points 7 and 10, if the relevant obligations are specified in the mandate.
Part III Conformity to type based on internal production control (based on module C)
1.Conformity to type based on internal production control is the part of a conformity assessment procedure whereby the manufacturer fulfills the obligations laid down in points 2 and 3 of this Part, and ensures and declares that the products concerned with digital elements are in conformity with the type described in the EU-type examination certificate and satisfy the essential cybersecurity requirements set out in Part I of Annex I and meet the essential cybersecurity requirements set out in Part II of Annex I.
2.Manufacture
The manufacturer shall take all measures necessary so that the conformity of manufactured devices incorporating digital elements with the approved type described in the EU-type examination certificate and with the essential cybersecurity requirements set out in Part I of Annex I is ensured through manufacture and its monitoring, and shall ensure compliance with the essential cybersecurity requirements set out in Part II of Annex I.
3.Conformity marking and declaration of conformity
3.1.The manufacturer shall affix the CE marking to each individual device incorporating digital elements that is in conformity with the type described in the EU-type examination certificate and satisfies the applicable requirements set out in this Regulation.
3.2.The manufacturer shall draw up a written declaration of conformity for a product model and keep it at the disposal of the national authorities for 10 years after the product with digital elements has been placed on the market or during the support period, whichever is the longer. The declaration of conformity shall identify the product model for which it has been issued. A copy of the declaration of conformity shall be made available to the relevant authorities upon request.
4.Authorized representative
The manufacturer’s obligations set out in point 3 may be fulfilled by his authorized representative, on his behalf and under his responsibility, provided that the relevant obligations are specified in the mandate.
Part IV Conformity based on full quality assurance (based on Module H)
1.Conformity based on full quality assurance is the conformity assessment procedure whereby the manufacturer fulfills the obligations laid down in points 2 and 5, and ensures and declares on his sole responsibility that the devices incorporating digital elements or product categories concerned satisfy the essential cybersecurity requirements set out in Part I of Annex I and that the manufacturer’s vulnerability management procedures satisfy the essential requirements set out in Part II of Annex I.
2.Design, development, production and treatment of vulnerabilities in products with digital elements
The manufacturer shall operate and maintain an approved quality management system as specified in point 3 for the design, development and final product inspection and testing of the digital devices concerned and for the management of vulnerabilities throughout the period of support and shall be subject to surveillance as specified in point 4.
3.Quality assurance system
3.1.The manufacturer shall apply to a notified body of his choice for assessment of his quality system for the products concerned with digital elements.
The application contains
a) the name and address of the manufacturer and, if the application is submitted by the authorized representative, the name and address of the authorized representative;
b) the technical documentation for one model of each category of devices with digital elements to be manufactured or designed; the technical documentation shall include at least the elements listed in Annex VII, where applicable;
c) the documentation for the quality assurance system;
d) a written declaration that the same application has not been submitted to any other notified body.
3.2.The quality system shall ensure compliance of the device with digital elements with the essential cybersecurity requirements set out in Part I of Annex I and compliance of the manufacturer’s vulnerability management procedures with the essential requirements set out in Part II of Annex I.
All the elements, requirements and provisions adopted by the manufacturer shall be documented in a systematic and orderly manner in the form of written policies, procedures and instructions. This quality system documentation shall ensure a consistent interpretation of the quality programs, plans, manuals and quality records. In particular, they shall contain an adequate description of the following points:
a) Quality objectives and organizational structure, responsibilities and powers of management with regard to design, development, product quality and handling of weaknesses;
b) technical specifications for design and development, including the standards applied and, where the relevant harmonized standards or technical specifications are not applied in full, the means to ensure that the essential cybersecurity requirements set out in Part I of Annex I applicable to the devices incorporating digital elements are met;
c) procedural specifications, including the standards applied and, where the relevant harmonized standards or technical specifications are not applied in full, the means to ensure that the essential cybersecurity requirements set out in Part II of Annex I applicable to the manufacturer are met;
d) Design and development control techniques and design and development review techniques, processes and systematic actions used in the design and development of products with digital elements belonging to the relevant product category;
e) appropriate applied techniques, procedures and systematic measures for production, quality control and quality assurance;
f) Tests and trials carried out before, during and after manufacture and their frequency;
g) quality-related records such as inspection reports, test and calibration data and reports on the qualifications of employees working in this area;
h) Means by which the realization of the intended design and product quality and the effective operation of the quality assurance system can be monitored.
3.3.The notified body shall assess the quality system to determine whether it satisfies the requirements referred to in point 3.2.
It shall presume conformity with those requirements in respect of the elements of the quality management system that comply with the corresponding specifications of the national standard that implements the relevant harmonized standard or relevant technical specifications. In addition to experience in quality management systems, at least one member of the auditing team shall have experience of evaluation in the relevant field and technology of the product concerned and knowledge of the applicable requirements laid down in this Regulation. The audit shall include an inspection visit to the manufacturer’s premises, if any. The auditing team shall review the technical documentation referred to in point 3.1(b) in order to verify the manufacturer’s ability to identify the applicable requirements set out in this Regulation and to carry out the necessary examinations with a view to ensuring compliance of the device with digital elements with those requirements. The decision shall be notified to the manufacturer or his authorized representative. The notification shall contain the conclusions of the audit and the reasoned assessment decision.
3.4.The manufacturer undertakes to comply with the obligations arising out of the approved quality system and to ensure that it is applied correctly and efficiently at all times.
3.5.The manufacturer shall keep the notified body that has approved the quality system informed of any intended change to the quality system.
The notified body shall evaluate the modifications proposed and decide whether the amended quality system will still satisfy the requirements referred to in point 3.2 or whether a reassessment is required. It shall notify the manufacturer of its decision. The notification shall contain the conclusions of the examination and the reasoned assessment decision.
4.Surveillance under the responsibility of the notified body
4.1.The purpose of surveillance is to ensure that the manufacturer duly fulfills the obligations associated with the approved quality assurance system.
4.2.The manufacturer shall, for assessment purposes, allow the notified body access to the locations of design, manufacture, inspection, testing and storage and shall provide it with all necessary information, in particular
a) the documentation on the quality assurance system,
b) the quality reports as foreseen in the quality system for the design part, such as results of analyses, calculations and tests,
c) the quality records as foreseen by the manufacturing part quality system, such as inspection reports, test and calibration data and qualification reports of the personnel concerned.
4.3.The notified body shall periodically carry out audits to make sure that the manufacturer maintains and applies the quality system and shall provide the manufacturer with an audit report.
5.Conformity marking and declaration of conformity
5.1.The manufacturer shall affix the CE marking and, under the responsibility of the notified body referred to in paragraph 3.1, the latter’s identification number to each individual device incorporating digital elements that satisfies the requirements set out in Annex I, Part I.
5.2.The manufacturer shall draw up a written declaration of conformity for each product model and keep it at the disposal of the national authorities for 10 years after the product with digital elements has been placed on the market or during the support period, whichever is the longer. The declaration of conformity shall identify the product model for which it has been issued.
A copy of the declaration of conformity will be made available to the relevant authorities on request.
6.The manufacturer shall, for a period of at least 10 years after the device with digital elements has been placed on the market or during the support period, whichever is the longer, keep the following documentation at the disposal of the national authorities:
a) the technical documentation according to number 3.1,
b) the documentation on the quality assurance system in accordance with point 3.1,
c) the amendment according to number 3.5 in its approved form,
d) the decisions and reports from the notified body referred to in points 3.5 and 4.3.
7.Each notified body shall inform its notifying authorities concerning quality system approvals issued or withdrawn, and shall, periodically or upon request, make available to them the list of quality system approvals refused, suspended or otherwise restricted.
Each notified body shall inform the other notified bodies of quality system approvals which it has refused, suspended or withdrawn, and, upon request, of quality system approvals which it has issued.
8.Authorized representative
The manufacturer’s obligations set out in points 3.1, 3.5, 5 and 6 may be fulfilled by his authorized representative, on his behalf and under his responsibility, provided that the relevant obligations are specified in the mandate.