fold out | fold
Reci­tals
(1) Cyber­se­cu­ri­ty is one of the big­gest chal­lenges facing the Uni­on. The num­ber and varie­ty of con­nec­ted devices will increa­se expo­nen­ti­al­ly in the coming years. Cyber-attacks are an issue of public inte­rest, as they have a cri­ti­cal impact not only on the Union’s eco­no­my, but also on demo­cra­cy and the safe­ty and health of con­su­mers. It is the­r­e­fo­re neces­sa­ry to streng­then the Union’s approach to cyber­se­cu­ri­ty, to address cyber resi­li­ence at Uni­on level and to impro­ve the func­tio­ning of the inter­nal mar­ket by estab­li­shing a uni­form legal frame­work for essen­ti­al cyber­se­cu­ri­ty requi­re­ments for the pla­cing of pro­ducts with digi­tal ele­ments on the Uni­on mar­ket. This should address two major pro­blems that impo­se high costs on users and socie­ty: a low level of cyber­se­cu­ri­ty of pro­ducts with digi­tal ele­ments, which is reflec­ted in wide­spread vul­nerabi­li­ties and the insuf­fi­ci­ent and incon­si­stent pro­vi­si­on of secu­ri­ty updates to address them, and a lack of under­stan­ding and access to infor­ma­ti­on by users, which pre­vents them from choo­sing or safe­ly using pro­ducts with ade­qua­te cyber­se­cu­ri­ty features.
(2) This Regu­la­ti­on aims to crea­te the frame­work con­di­ti­ons for the deve­lo­p­ment of secu­re pro­ducts with digi­tal ele­ments, so that hard­ware and soft­ware pro­ducts with fewer vul­nerabi­li­ties are pla­ced on the mar­ket and so that manu­fac­tu­r­ers con­sist­ent­ly take care of secu­ri­ty throug­hout the enti­re life cycle of a pro­duct. It also aims to crea­te con­di­ti­ons that enable users to take cyber­se­cu­ri­ty into account when choo­sing and using pro­ducts with digi­tal ele­ments, for exam­p­le by incre­a­sing trans­pa­ren­cy regar­ding the sup­port peri­od for pro­ducts with digi­tal ele­ments made available on the market.
(3) Exi­sting rele­vant Uni­on law inclu­des seve­ral hori­zon­tal pro­vi­si­ons regu­la­ting cer­tain aspects of cyber­se­cu­ri­ty from dif­fe­rent angles, inclu­ding mea­su­res to enhan­ce the secu­ri­ty of the digi­tal sup­p­ly chain. Howe­ver, exi­sting Uni­on law on cyber­se­cu­ri­ty, inclu­ding Regu­la­ti­on (EU) 2019/881 of the Euro­pean Par­lia­ment and of the Coun­cil (3) and Direc­ti­ve (EU) 2022/2555 of the Euro­pean Par­lia­ment and of the Coun­cil (4), does not con­tain direct­ly bin­ding requi­re­ments on the secu­ri­ty of pro­ducts with digi­tal elements.
(4) While exi­sting Uni­on law applies to cer­tain pro­ducts with digi­tal ele­ments, the­re is no hori­zon­tal Uni­on legal frame­work that would estab­lish com­pre­hen­si­ve cyber­se­cu­ri­ty requi­re­ments for all pro­ducts with digi­tal ele­ments. The various rules adopted and initia­ti­ves taken so far at Uni­on and natio­nal level only par­ti­al­ly address the iden­ti­fi­ed pro­blems and risks rela­ted to cyber­se­cu­ri­ty, crea­ting a legis­la­ti­ve patch­work within the inter­nal mar­ket that leads to grea­ter legal uncer­tain­ty for both pro­du­cers and users of such pro­ducts and to a grea­ter unneces­sa­ry bur­den on busi­nesses and orga­nizati­ons that have to com­ply with a num­ber of dif­fe­rent requi­re­ments and obli­ga­ti­ons in rela­ti­on to simi­lar types of pro­ducts. The cyber­se­cu­ri­ty of the­se pro­ducts has a par­ti­cu­lar­ly strong cross-bor­der dimen­si­on becau­se pro­ducts with digi­tal ele­ments manu­fac­tu­red in a Mem­ber Sta­te or in a third coun­try are often used by orga­nizati­ons and con­su­mers throug­hout the inter­nal mar­ket. This makes it neces­sa­ry to regu­la­te the sec­tor at Uni­on level in order to ensu­re a har­mo­ni­zed legal frame­work and legal cer­tain­ty for users, orga­nizati­ons and busi­nesses, inclu­ding micro, small and medi­um-sized enter­pri­ses as defi­ned in the Annex to Com­mis­si­on Recom­men­da­ti­on 2003/361/EC (5). The Uni­on regu­la­to­ry envi­ron­ment should be har­mo­ni­zed through the intro­duc­tion of hori­zon­tal cyber­se­cu­ri­ty requi­re­ments for pro­ducts with digi­tal ele­ments. It is also neces­sa­ry to ensu­re legal cer­tain­ty for eco­no­mic ope­ra­tors and users across the Uni­on and bet­ter har­mo­nizati­on of the inter­nal mar­ket and pro­por­tio­na­li­ty for micro, small and medi­um-sized enter­pri­ses, which would also crea­te bet­ter con­di­ti­ons for eco­no­mic ope­ra­tors wis­hing to enter that market.
(5) As regards micro, small and medi­um-sized enter­pri­ses, the pro­vi­si­ons of the Annex to Recom­men­da­ti­on 2003/361/EC should be applied in full when deter­mi­ning the cate­go­ry into which an enter­pri­se falls. The­r­e­fo­re, the pro­vi­si­ons of Artic­le 6 of the Annex to Recom­men­da­ti­on 2003/361/EC on the com­pi­la­ti­on of the data of an enter­pri­se with regard to cer­tain types of enter­pri­ses, such as part­ner enter­pri­ses or lin­ked enter­pri­ses, should also be applied when cal­cu­la­ting the num­ber of employees and the finan­cial thres­holds for deter­mi­ning the types of enterprises.
(6) The Com­mis­si­on should pro­vi­de gui­dance to assist eco­no­mic ope­ra­tors, in par­ti­cu­lar micro, small and medi­um-sized enter­pri­ses, in the appli­ca­ti­on of this Regu­la­ti­on. Tho­se gui­de­lines should cover, inter alia, the scope of this Regu­la­ti­on, in par­ti­cu­lar remo­te data pro­ce­s­sing and its impact on deve­lo­pers of free and open source soft­ware, the appli­ca­ti­on of the cri­te­ria for estab­li­shing sup­port peri­ods for pro­ducts with digi­tal ele­ments, the inter­ac­tion bet­ween this Regu­la­ti­on and other Uni­on legis­la­ti­on, and what con­sti­tu­tes a sub­stan­ti­al modification.
(7) At Uni­on level, various pro­gram­ma­tic and poli­cy docu­ments, such as the joint com­mu­ni­ca­ti­on of the Com­mis­si­on and the High Repre­sen­ta­ti­ve of the Uni­on for For­eign Affairs and Secu­ri­ty Poli­cy of 16 Decem­ber 2020 entit­led “The EU Cyber­se­cu­ri­ty Stra­tegy for the Digi­tal Deca­de”, the Coun­cil con­clu­si­ons on the cyber­se­cu­ri­ty of con­nec­ted devices of 2 Decem­ber 2020 and the Coun­cil con­clu­si­ons on the deve­lo­p­ment of the Euro­pean Union’s cyber defen­se of 23 May 2022 and the Euro­pean Par­lia­ment reso­lu­ti­on of 10 June 2021 on the EU Cyber­se­cu­ri­ty Stra­tegy for the Digi­tal Deca­de (6 June 2021), have been published. The Coun­cil con­clu­si­ons of 23 Decem­ber 2020 and the Coun­cil con­clu­si­ons on the deve­lo­p­ment of the Euro­pean Union’s cyber defen­se of 23 May 2022 and the Euro­pean Par­lia­ment reso­lu­ti­on of 10 June 2021 on the EU Cyber­se­cu­ri­ty Stra­tegy for the Digi­tal Deca­de (6) cal­led for spe­ci­fic Uni­on cyber­se­cu­ri­ty requi­re­ments for digi­tal or con­nec­ted pro­ducts; at the same time, seve­ral third count­ries have taken mea­su­res to address this issue on their own initia­ti­ve. In the final report of the Con­fe­rence on the Future of Euro­pe, citi­zens cal­led for “a stron­ger role for the EU in coun­tering cyber­se­cu­ri­ty thre­ats”. In order for the Uni­on to play a lea­ding role inter­na­tio­nal­ly in the field of cyber­se­cu­ri­ty, it is important to crea­te an ambi­tious legal framework.
(8) In order to increa­se the over­all level of cyber­se­cu­ri­ty of all pro­ducts with digi­tal ele­ments pla­ced on the inter­nal mar­ket, objec­ti­ve and tech­no­lo­gy-neu­tral basic cyber­se­cu­ri­ty requi­re­ments must be intro­du­ced for the­se pro­ducts, which should then app­ly horizontally.
(9) All pro­ducts with digi­tal ele­ments that are inte­gra­ted into or con­nec­ted to a lar­ger elec­tro­nic infor­ma­ti­on system can, under cer­tain cir­cum­stances, ser­ve as an attack vec­tor for mali­cious actors. Con­se­quent­ly, even hard­ware and soft­ware that is con­side­red less cri­ti­cal can faci­li­ta­te an initi­al com­pro­mi­se of a device or net­work and allow mali­cious actors to gain pri­vi­le­ged access to a system or move across systems. Manu­fac­tu­r­ers should the­r­e­fo­re ensu­re that all pro­ducts with digi­tal ele­ments are desi­gned and deve­lo­ped in accordance with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in this Regu­la­ti­on. The obli­ga­ti­on applies both to pro­ducts that can be phy­si­cal­ly con­nec­ted via hard­ware inter­faces and to pro­ducts that are logi­cal­ly con­nec­ted, e.g. via net­work sockets, pipes, files, appli­ca­ti­on pro­gramming inter­faces or other types of soft­ware inter­faces. Sin­ce cyber thre­ats can spread through dif­fe­rent pro­ducts with digi­tal ele­ments befo­re rea­ching a spe­ci­fic tar­get, e.g. by chai­ning seve­ral explo­ita­ble vul­nerabi­li­ties, manu­fac­tu­r­ers should also ensu­re the cyber secu­ri­ty of tho­se pro­ducts with digi­tal ele­ments that are only indi­rect­ly con­nec­ted to other devices or networks.
(10) The estab­lish­ment of cyber­se­cu­ri­ty requi­re­ments for the pla­cing on the mar­ket of pro­ducts with digi­tal ele­ments is inten­ded to impro­ve the cyber­se­cu­ri­ty of the­se pro­ducts for both con­su­mers and busi­nesses. The­se requi­re­ments will also ensu­re that cyber­se­cu­ri­ty is taken into account throug­hout the sup­p­ly chain, making end pro­ducts with digi­tal ele­ments and their com­pon­ents more secu­re. This also con­cerns requi­re­ments for the pla­cing on the mar­ket of con­su­mer pro­ducts with digi­tal ele­ments inten­ded for vul­nerable con­su­mers, such as toys and baby moni­tor systems. The con­su­mer pro­ducts with digi­tal ele­ments that are clas­si­fi­ed as essen­ti­al pro­ducts with digi­tal ele­ments in this Regu­la­ti­on are sub­ject to a hig­her cyber­se­cu­ri­ty risk, as their func­tions pose a signi­fi­cant risk of adver­se effects in terms of their scope and their poten­ti­al harm to the health, safe­ty or inte­gri­ty of users of such pro­ducts, and should be sub­ject to a more strin­gent con­for­mi­ty assess­ment pro­ce­du­re. This applies to pro­ducts such as smart hou­se­hold appli­ances with secu­ri­ty func­tions, inclu­ding smart door locks, baby moni­tors and alarms, con­nec­ted toys and weara­ble medi­cal devices. In addi­ti­on, the more strin­gent con­for­mi­ty assess­ment pro­ce­du­res to which other pro­ducts with digi­tal ele­ments that are clas­si­fi­ed as essen­ti­al or cri­ti­cal pro­ducts with digi­tal ele­ments in this Regu­la­ti­on must be sub­ject will help to pre­vent any nega­ti­ve impact on con­su­mers that could result from the explo­ita­ti­on of vulnerabilities.
(11) This Regu­la­ti­on aims to ensu­re a high level of cyber­se­cu­ri­ty of pro­ducts with digi­tal ele­ments and their embedded remo­te com­pu­ting solu­ti­ons. Such remo­te com­pu­ting solu­ti­ons should be defi­ned as remo­te data pro­ce­s­sing for which soft­ware is desi­gned and deve­lo­ped by the manu­fac­tu­rer of the device with digi­tal ele­ments its­elf or under its respon­si­bi­li­ty and wit­hout which the device with digi­tal ele­ments could not per­form any of its func­tions. This ensu­res that such pro­ducts are ade­qua­te­ly secu­red in their enti­re­ty by their manu­fac­tu­r­ers, regard­less of whe­ther the data is pro­ce­s­sed or stored local­ly on the user’s device or remo­te­ly by the manu­fac­tu­rer. At the same time, remo­te pro­ce­s­sing or sto­rage falls within the scope of this Regu­la­ti­on only to the ext­ent that it is neces­sa­ry for a pro­duct with digi­tal ele­ments to per­form its func­tions. Such remo­te pro­ce­s­sing or sto­rage occurs when a mobi­le appli­ca­ti­on requi­res access to an appli­ca­ti­on pro­gramming inter­face or to a data­ba­se pro­vi­ded by a ser­vice deve­lo­ped by the manu­fac­tu­rer. In this case, the ser­vice falls within the scope of this Regu­la­ti­on as a remo­te data pro­ce­s­sing solu­ti­on. The requi­re­ments for remo­te com­pu­ting solu­ti­ons fal­ling within the scope of this Regu­la­ti­on shall the­r­e­fo­re not include tech­ni­cal, ope­ra­tio­nal or orga­nizatio­nal mea­su­res to mana­ge the risks to the secu­ri­ty of the manufacturer’s net­work and infor­ma­ti­on systems as a whole.
(12) Cloud solu­ti­ons shall only be con­side­red as remo­te data pro­ce­s­sing solu­ti­ons within the mea­ning of this Regu­la­ti­on if they com­ply with the defi­ni­ti­on laid down in this Regu­la­ti­on. For exam­p­le, cloud func­tion­a­li­ties offe­red by the manu­fac­tu­rer of smart hou­se­hold appli­ances that allow users to con­trol the appli­ance remo­te­ly fall within the scope of this Regu­la­ti­on. In con­trast, web­sites that do not sup­port the func­tion­a­li­ty of a pro­duct with digi­tal ele­ments or cloud ser­vices desi­gned and deve­lo­ped out­side the respon­si­bi­li­ty of a manu­fac­tu­rer of a pro­duct with digi­tal ele­ments do not fall within the scope of this Regu­la­ti­on. Direc­ti­ve (EU) 2022/2555 applies to cloud com­pu­ting ser­vices and cloud ser­vice models such as SaaS (Soft­ware as a Ser­vice), PaaS (Plat­form as a Ser­vice) or IaaS (Infras­truc­tu­re as a Ser­vice). The enti­ties pro­vi­ding cloud com­pu­ting ser­vices in the Uni­on that qua­li­fy as medi­um-sized enter­pri­ses in accordance with Artic­le 2 of the Annex to Recom­men­da­ti­on 2003/361/EC or that exce­ed the thres­holds for medi­um-sized enter­pri­ses set out in para­graph 1 of that Artic­le fall within the scope of that Directive.
(13) In line with the objec­ti­ve of this Regu­la­ti­on to remo­ve bar­riers to the free move­ment of pro­ducts incor­po­ra­ting digi­tal ele­ments, Mem­ber Sta­tes should not impe­de the making available on the mar­ket of pro­ducts incor­po­ra­ting digi­tal ele­ments that com­ply with this Regu­la­ti­on in the aspects cover­ed by this Regu­la­ti­on. In the are­as har­mo­ni­zed by this Regu­la­ti­on, Mem­ber Sta­tes may the­r­e­fo­re not impo­se addi­tio­nal cyber­se­cu­ri­ty requi­re­ments for the making available on the mar­ket of pro­ducts with digi­tal ele­ments. Howe­ver, any public or pri­va­te enti­ty may, in addi­ti­on to the requi­re­ments laid down in this Regu­la­ti­on, impo­se addi­tio­nal requi­re­ments for the pro­cu­re­ment or use of pro­ducts with digi­tal ele­ments for its spe­ci­fic pur­po­ses and may the­r­e­fo­re choo­se to use pro­ducts with digi­tal ele­ments that com­ply with more strin­gent or more spe­ci­fic cyber­se­cu­ri­ty requi­re­ments than tho­se appli­ca­ble to the making available on the mar­ket under this Regu­la­ti­on. Wit­hout pre­ju­di­ce to Direc­ti­ves 2014/24/EU (7) and 2014/25/EU (8) of the Euro­pean Par­lia­ment and of the Coun­cil, when pro­cu­ring pro­ducts with digi­tal ele­ments that are requi­red to com­ply with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in this Regu­la­ti­on, inclu­ding tho­se for mana­ging secu­ri­ty risks, Mem­ber Sta­tes should ensu­re that tho­se requi­re­ments are taken into account in the pro­cu­re­ment pro­cess and that the abili­ty of manu­fac­tu­r­ers to effec­tively app­ly cyber­se­cu­ri­ty mea­su­res and to mana­ge cyber thre­ats is also con­side­red. In addi­ti­on, Direc­ti­ve (EU) 2022/2555 sets out cyber­se­cu­ri­ty risk manage­ment mea­su­res for the essen­ti­al and important enti­ties refer­red to in Artic­le 3 of that Direc­ti­ve, which could include sup­p­ly chain secu­ri­ty mea­su­res that requi­re tho­se enti­ties to use pro­ducts with digi­tal ele­ments that meet more strin­gent cyber­se­cu­ri­ty requi­re­ments than tho­se set out in this Regu­la­ti­on. In accordance with Direc­ti­ve (EU) 2022/2555 and its prin­ci­ple of mini­mum har­mo­nizati­on, Mem­ber Sta­tes may the­r­e­fo­re lay down addi­tio­nal cyber­se­cu­ri­ty requi­re­ments for the use of infor­ma­ti­on and com­mu­ni­ca­ti­on tech­no­lo­gy (ICT) pro­ducts by essen­ti­al or cri­ti­cal enti­ties in accordance with that Direc­ti­ve in order to ensu­re a hig­her level of cyber­se­cu­ri­ty, pro­vi­ded that tho­se requi­re­ments are con­si­stent with the obli­ga­ti­ons of Mem­ber Sta­tes laid down in Uni­on law. Aspects not cover­ed by this Regu­la­ti­on may also include non-tech­ni­cal fac­tors rela­ted to pro­ducts with digi­tal ele­ments and their manu­fac­tu­r­ers. Mem­ber Sta­tes may the­r­e­fo­re lay down natio­nal mea­su­res, inclu­ding rest­ric­tions on pro­ducts with digi­tal ele­ments or on sup­pliers of such pro­ducts, which take into account non-tech­ni­cal fac­tors. Natio­nal mea­su­res rela­ting to such fac­tors shall be com­pa­ti­ble with Uni­on law.
(14) This Regu­la­ti­on should be wit­hout pre­ju­di­ce to the respon­si­bi­li­ty of Mem­ber Sta­tes to ensu­re natio­nal secu­ri­ty, in accordance with Uni­on law. Mem­ber Sta­tes should be able to impo­se addi­tio­nal requi­re­ments on pro­ducts con­tai­ning digi­tal ele­ments that are pro­cu­red or used for natio­nal secu­ri­ty or defen­se pur­po­ses, pro­vi­ded that tho­se requi­re­ments are con­si­stent with Mem­ber Sta­tes’ obli­ga­ti­ons under Uni­on law.
(15) This Regu­la­ti­on applies to eco­no­mic ope­ra­tors only in rela­ti­on to pro­ducts with digi­tal ele­ments that are made available on the mar­ket, i.e. sup­plied in the con­text of a com­mer­cial acti­vi­ty for dis­tri­bu­ti­on or use on the Uni­on mar­ket. A sup­p­ly in the con­text of a com­mer­cial acti­vi­ty may not only be cha­rac­te­ri­zed by the fact that a pri­ce is char­ged for a pro­duct with digi­tal ele­ments, but also by the fact that a fee is char­ged for tech­ni­cal sup­port ser­vices that are not only inten­ded to cover actu­al costs, for exam­p­le by pro­vi­ding a soft­ware plat­form, through which the manu­fac­tu­rer offers other ser­vices for pro­fit, or that the pro­ce­s­sing of per­so­nal data for pur­po­ses other than the sole impro­ve­ment of the secu­ri­ty, com­pa­ti­bi­li­ty or inter­ope­ra­bi­li­ty of the soft­ware is requi­red as a con­di­ti­on of use, or that dona­ti­ons are accept­ed that exce­ed the costs asso­cia­ted with the design, deve­lo­p­ment and pro­vi­si­on of a pro­duct with digi­tal ele­ments. The accep­tance of non-pro­fit dona­ti­ons should not be con­side­red a busi­ness activity.
(16) Pro­ducts with digi­tal ele­ments that are pro­vi­ded in the con­text of the pro­vi­si­on of a ser­vice for which a fee is char­ged exclu­si­ve­ly to cover the actu­al costs direct­ly rela­ted to the ope­ra­ti­on of that ser­vice, as may be the case for cer­tain pro­ducts with digi­tal ele­ments pro­vi­ded by public admi­ni­stra­ti­on bodies, should not be con­side­red to be part of a com­mer­cial acti­vi­ty within the mea­ning of this Regu­la­ti­on on tho­se grounds alo­ne. Fur­ther­mo­re, pro­ducts with digi­tal ele­ments that are deve­lo­ped or modi­fi­ed by a public admi­ni­stra­ti­on body exclu­si­ve­ly for its own use should not be con­side­red to be made available on the mar­ket within the mea­ning of this Regulation.
(17) Soft­ware and data that are open­ly shared and that users can free­ly access, use, modi­fy and redis­tri­bu­te, inclu­ding in modi­fi­ed form, can con­tri­bu­te to rese­arch and inno­va­ti­on on the mar­ket. In order to encou­ra­ge the deve­lo­p­ment and use of free and open source soft­ware, in par­ti­cu­lar by micro, small and medi­um-sized enter­pri­ses, inclu­ding start-ups, indi­vi­du­als, non-pro­fit orga­nizati­ons and aca­de­mic rese­arch insti­tu­ti­ons, the appli­ca­ti­on of this Regu­la­ti­on to pro­ducts with digi­tal ele­ments that are clas­si­fi­ed as free and open source soft­ware and made available for dis­tri­bu­ti­on or use in the cour­se of a com­mer­cial acti­vi­ty should take into account the types of dif­fe­rent deve­lo­p­ment models for soft­ware dis­tri­bu­ted and deve­lo­ped under free and open source soft­ware licences.
(18) Free and open source soft­ware is soft­ware who­se source code is open­ly shared and who­se licen­se inclu­des all the neces­sa­ry rights to make it free­ly acce­s­si­ble, usable, modi­fia­ble and redis­tri­bu­ta­ble. Free and open source soft­ware is deve­lo­ped, main­tai­ned and dis­tri­bu­ted open­ly, inclu­ding via online plat­forms. With regard to eco­no­mic ope­ra­tors fal­ling within the scope of this Regu­la­ti­on, only free and open source soft­ware that is made available on the mar­ket and thus made available for dis­tri­bu­ti­on or use in the cour­se of a com­mer­cial acti­vi­ty should fall within the scope of this Regu­la­ti­on. The mere cir­cum­stances in which the pro­duct con­tai­ning digi­tal ele­ments was deve­lo­ped or the way in which the deve­lo­p­ment was finan­ced should the­r­e­fo­re not be taken into account when deter­mi­ning the com­mer­cial or non-com­mer­cial natu­re of the rele­vant acti­vi­ty. In par­ti­cu­lar, for the pur­po­ses of this Regu­la­ti­on and in rela­ti­on to the eco­no­mic ope­ra­tors fal­ling within its scope, the sup­p­ly of pro­ducts incor­po­ra­ting digi­tal ele­ments that are clas­si­fi­ed as free and open source soft­ware and are not mone­ti­zed by their pro­du­cers should not be con­side­red a com­mer­cial acti­vi­ty, in order to ensu­re that a clear distinc­tion is made bet­ween the deve­lo­p­ment and sup­p­ly pha­ses. In addi­ti­on, the sup­p­ly of pro­ducts with digi­tal ele­ments that are clas­si­fi­ed as free and open source soft­ware com­pon­ents and are inten­ded for inte­gra­ti­on by other pro­du­cers into their own pro­ducts with digi­tal ele­ments should only be con­side­red as making available on the mar­ket if the com­po­nent is mone­ti­zed by its ori­gi­nal pro­du­cer. For exam­p­le, the mere fact that a pro­duct of open source soft­ware with digi­tal ele­ments is finan­ci­al­ly sup­port­ed by the pro­du­cers or that pro­du­cers con­tri­bu­te to the deve­lo­p­ment of such a pro­duct should not in its­elf be decisi­ve for estab­li­shing that the acti­vi­ty is of a com­mer­cial natu­re. Fur­ther­mo­re, the mere exi­stence of regu­lar releases of ver­si­ons should not in its­elf lead to the con­clu­si­on that a pro­duct with digi­tal ele­ments is sup­plied in the cour­se of a com­mer­cial acti­vi­ty. Final­ly, for the pur­po­ses of this Regu­la­ti­on, the deve­lo­p­ment by non-pro­fit orga­nizati­ons of pro­ducts with digi­tal ele­ments that qua­li­fy as free and open source soft­ware should not be con­side­red to be a com­mer­cial acti­vi­ty, pro­vi­ded that the orga­nizati­on is set up in such a way as to ensu­re that all reve­nues after deduc­tion of costs are used to achie­ve non-pro­fit objec­ti­ves. This Regu­la­ti­on shall not app­ly to natu­ral or legal per­sons who con­tri­bu­te with source code to pro­ducts with digi­tal ele­ments that are clas­si­fi­ed as free and open source soft­ware and are not under their responsibility.
(19) Given the importance for cyber­se­cu­ri­ty of many pro­ducts with digi­tal ele­ments that are clas­si­fi­ed as free and open source soft­ware and are published but not made available on the mar­ket within the mea­ning of this Regu­la­ti­on, legal enti­ties that sup­port the deve­lo­p­ment of such pro­ducts inten­ded for com­mer­cial acti­vi­ties on a per­ma­nent basis and play an important role in ensu­ring the usa­bi­li­ty of tho­se pro­ducts (open source soft­ware mana­gers) should be sub­ject to a sim­pli­fi­ed and tail­o­red regu­la­to­ry regime. Mana­gers of open source soft­ware include cer­tain foun­da­ti­ons and enti­ties that deve­lop and publish free and open source soft­ware in a com­mer­cial con­text, inclu­ding non-pro­fit enti­ties. Regu­la­ti­on should take into account their spe­ci­fi­ci­ties and com­pa­ti­bi­li­ty with the natu­re of the obli­ga­ti­ons impo­sed. Only pro­ducts with digi­tal ele­ments that qua­li­fy as free and open source soft­ware and are ulti­m­ate­ly inten­ded for com­mer­cial acti­vi­ties, such as inte­gra­ti­on into com­mer­cial ser­vices or paid pro­ducts with digi­tal ele­ments, should be cover­ed. For the pur­po­ses of this regu­la­to­ry regime, inten­ded inte­gra­ti­on into paid pro­ducts with digi­tal ele­ments inclu­des cases whe­re the manu­fac­tu­r­ers inte­gra­ting a com­po­nent into their own pro­ducts with digi­tal ele­ments eit­her regu­lar­ly con­tri­bu­te to the deve­lo­p­ment of that com­po­nent or pro­vi­de regu­lar finan­cial sup­port to ensu­re the con­ti­nui­ty of a soft­ware pro­duct. Ongo­ing sup­port for the deve­lo­p­ment of a pro­duct with digi­tal ele­ments inclu­des hosting and mana­ging soft­ware deve­lo­p­ment col­la­bo­ra­ti­on plat­forms, hosting source code or soft­ware, mana­ging or admi­ni­ste­ring pro­ducts with digi­tal ele­ments that are clas­si­fi­ed as free and open source soft­ware, and mana­ging the deve­lo­p­ment of such pro­ducts. Sin­ce the sim­pli­fi­ed and tail­or-made regu­la­to­ry regime does not pro­vi­de for the same obli­ga­ti­ons for mana­gers of open source soft­ware as for manu­fac­tu­r­ers under this Regu­la­ti­on, they should not be allo­wed to affix the CE mar­king on pro­ducts incor­po­ra­ting digi­tal ele­ments who­se deve­lo­p­ment they support.
(20) The mere pro­vi­si­on of pro­ducts with digi­tal ele­ments in open archi­ves, inclu­ding through packa­ge manage­ment or on col­la­bo­ra­ti­ve plat­forms, does not in its­elf con­sti­tu­te the pro­vi­si­on of a pro­duct with digi­tal ele­ments on the mar­ket. The pro­vi­ders of such ser­vices should only be con­side­red as dis­tri­bu­tors if they make such soft­ware available on the mar­ket and thus sup­p­ly it in the cour­se of a com­mer­cial acti­vi­ty for dis­tri­bu­ti­on or use on the Uni­on market.
(21) In order to sup­port and faci­li­ta­te the due dili­gence of manu­fac­tu­r­ers inte­gra­ting free and open source soft­ware com­pon­ents that are not sub­ject to the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on into their pro­ducts incor­po­ra­ting digi­tal items, the Com­mis­si­on should be able to estab­lish vol­un­t­a­ry secu­ri­ty cer­ti­fi­ca­ti­on sche­mes, eit­her by means of a dele­ga­ted act sup­ple­men­ting this Regu­la­ti­on or by requi­ring a Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­me in accordance with Artic­le 48 of Regu­la­ti­on (EU) 2019/881, which takes into account the spe­ci­fi­ci­ties of free and open source soft­ware deve­lo­p­ment models. The secu­ri­ty cer­ti­fi­ca­ti­on sche­mes should be desi­gned in such a way that not only natu­ral or legal per­sons deve­lo­ping or con­tri­bu­ting to a pro­duct with digi­tal ele­ments clas­si­fi­ed as free and open source soft­ware can initia­te or finan­ce a secu­ri­ty cer­ti­fi­ca­ti­on, but also third par­ties, such as manu­fac­tu­r­ers inte­gra­ting such pro­ducts with digi­tal ele­ments into their own pro­ducts with digi­tal ele­ments, as well as users or public admi­ni­stra­ti­ons of the Uni­on and of the Mem­ber States.
(22) In view of the objec­ti­ves of this Regu­la­ti­on in the field of public cyber­se­cu­ri­ty and in order to impro­ve Mem­ber Sta­tes’ awa­re­ness of the Union’s depen­den­cy on soft­ware com­pon­ents, and in par­ti­cu­lar on poten­ti­al­ly free and open source soft­ware com­pon­ents, a spe­cial admi­ni­stra­ti­ve coope­ra­ti­on group (ADCO) estab­lished by this Regu­la­ti­on should be able to deci­de to joint­ly car­ry out a Uni­on depen­den­cy assess­ment. Mar­ket sur­veil­lan­ce aut­ho­ri­ties should be able to request manu­fac­tu­r­ers of pro­ducts with digi­tal ele­ments fal­ling within the cate­go­ries estab­lished by ADCO to sub­mit the soft­ware BOMs that they have drawn up in accordance with this Regu­la­ti­on. In order to pro­tect the con­fi­den­tia­li­ty of the soft­ware BOMs, mar­ket sur­veil­lan­ce aut­ho­ri­ties should sub­mit rele­vant infor­ma­ti­on on depen­den­ci­es to ADCO in an anony­mi­zed and aggre­ga­ted form.
(23) The effec­ti­ve­ness of the imple­men­ta­ti­on of this Regu­la­ti­on will also depend on the avai­la­bi­li­ty of ade­qua­te cyber­se­cu­ri­ty skills. At Uni­on level, various pro­gram­ma­tic and poli­cy docu­ments, inclu­ding the Com­mis­si­on Com­mu­ni­ca­ti­on of 18 April 2023 entit­led “Clo­sing the cyber­se­cu­ri­ty skills gap to boost EU com­pe­ti­ti­ve­ness, growth and resi­li­ence” and the Coun­cil Con­clu­si­ons of 22 May 2023 on EU cyber defen­se poli­cy, have ack­now­led­ged that a cyber­se­cu­ri­ty skills gap exists in the Uni­on and needs to be addres­sed as a mat­ter of prio­ri­ty in both the public and pri­va­te sec­tors. In order to ensu­re the effec­ti­ve imple­men­ta­ti­on of this Regu­la­ti­on, Mem­ber Sta­tes should ensu­re that suf­fi­ci­ent resour­ces are available to ade­qua­te­ly staff mar­ket sur­veil­lan­ce aut­ho­ri­ties and con­for­mi­ty assess­ment bodies so that they can car­ry out their tasks set out in this Regu­la­ti­on. As part of tho­se mea­su­res, the mobi­li­ty of the cyber­se­cu­ri­ty work­force and rela­ted care­er paths should be impro­ved. The mea­su­res should also con­tri­bu­te to making the cyber­se­cu­ri­ty work­force more resi­li­ent and inclu­si­ve, inclu­ding in terms of gen­der equa­li­ty. Mem­ber Sta­tes should the­r­e­fo­re make pro­vi­si­ons to ensu­re that the rele­vant tasks are car­ri­ed out by appro­pria­te­ly trai­ned pro­fes­sio­nals with the neces­sa­ry cyber­se­cu­ri­ty skills. Simi­lar­ly, manu­fac­tu­r­ers should ensu­re that their per­son­nel have the neces­sa­ry skills to ful­fill their obli­ga­ti­ons under this Regu­la­ti­on. Mem­ber Sta­tes and the Com­mis­si­on should, in accordance with their pre­ro­ga­ti­ves and com­pe­ten­ces and the spe­ci­fic tasks con­fer­red on them by this Regu­la­ti­on, take mea­su­res to sup­port manu­fac­tu­r­ers, in par­ti­cu­lar micro, small and medi­um-sized enter­pri­ses, inclu­ding start-ups, inclu­ding in are­as such as capa­ci­ty buil­ding, in order to enable them to com­ply with their obli­ga­ti­ons under this Regu­la­ti­on. As Direc­ti­ve (EU) 2022/2555 requi­res Mem­ber Sta­tes to take mea­su­res to pro­mo­te and deve­lop cyber­se­cu­ri­ty trai­ning and cyber­se­cu­ri­ty skills as part of their natio­nal cyber­se­cu­ri­ty stra­te­gies, Mem­ber Sta­tes may, when adop­ting such stra­te­gies, also con­sider addres­sing cyber­se­cu­ri­ty skills needs ari­sing from this Regu­la­ti­on, inclu­ding retrai­ning and ups­kil­ling needs.
(24) A secu­re inter­net is essen­ti­al for the func­tio­ning of cri­ti­cal infras­truc­tures and for socie­ty as a who­le. Direc­ti­ve (EU) 2022/2555 aims to ensu­re a high level of cyber­se­cu­ri­ty of the ser­vices of the essen­ti­al and cri­ti­cal enti­ties refer­red to in Artic­le 3 of that Direc­ti­ve, inclu­ding digi­tal infras­truc­tu­re ope­ra­tors, sup­port­ing the core func­tions of the open inter­net and ensu­ring inter­net access and ser­vices. It is the­r­e­fo­re important that the pro­ducts con­tai­ning digi­tal ele­ments neces­sa­ry to enable digi­tal infras­truc­tu­re ope­ra­tors to ensu­re the func­tio­ning of the inter­net are deve­lo­ped in a secu­re man­ner and that they com­ply with estab­lished inter­net secu­ri­ty stan­dards. This Regu­la­ti­on, which applies to all con­nec­ta­ble hard­ware and soft­ware pro­ducts, also aims to make it easier for digi­tal infras­truc­tu­re ope­ra­tors to com­ply with the sup­p­ly chain requi­re­ments of Direc­ti­ve (EU) 2022/2555 by ensu­ring that the pro­ducts with digi­tal ele­ments that they use to pro­vi­de their ser­vices are deve­lo­ped in a secu­re man­ner and that they recei­ve time­ly secu­ri­ty updates for such products.
(25) Regu­la­ti­on (EU) 2017/745 of the Euro­pean Par­lia­ment and of the Coun­cil (9) con­ta­ins rules for medi­cal devices and Regu­la­ti­on (EU) 2017/746 of the Euro­pean Par­lia­ment and of the Coun­cil (10) con­ta­ins rules for in vitro dia­gno­stic medi­cal devices. The­se regu­la­ti­ons are desi­gned to address cyber­se­cu­ri­ty risks and fol­low spe­ci­fic approa­ches that also under­lie this Regu­la­ti­on. In par­ti­cu­lar, Regu­la­ti­ons (EU) 2017/745 and (EU) 2017/746 con­tain essen­ti­al requi­re­ments for medi­cal devices that func­tion by means of an elec­tro­nic system or that are them­sel­ves soft­ware. Cer­tain non-embedded soft­ware and the who­le life cycle approach are also cover­ed by the­se regu­la­ti­ons. Accor­ding to the­se requi­re­ments, manu­fac­tu­r­ers must app­ly risk manage­ment prin­ci­ples in the deve­lo­p­ment and design of their pro­ducts and defi­ne requi­re­ments for IT secu­ri­ty mea­su­res and cor­re­spon­ding con­for­mi­ty assess­ment pro­ce­du­res. In addi­ti­on, spe­ci­fic gui­dance on cyber­se­cu­ri­ty of medi­cal devices has been in place sin­ce Decem­ber 2019, pro­vi­ding gui­dance to manu­fac­tu­r­ers of medi­cal devices and in vitro dia­gno­stic medi­cal devices on how to com­ply with all rele­vant essen­ti­al requi­re­ments set out in Annex I of the­se regu­la­ti­ons in rela­ti­on to cyber­se­cu­ri­ty. Devices with digi­tal ele­ments cover­ed by one of tho­se Regu­la­ti­ons should the­r­e­fo­re not be cover­ed by this Regulation.
(26) Pro­ducts con­tai­ning digi­tal ele­ments deve­lo­ped or modi­fi­ed exclu­si­ve­ly for natio­nal secu­ri­ty or defen­se pur­po­ses or pro­ducts spe­ci­fi­cal­ly desi­gned for the pro­ce­s­sing of clas­si­fi­ed infor­ma­ti­on shall not fall within the scope of this Regu­la­ti­on. Mem­ber Sta­tes are requi­red to ensu­re the same or a hig­her level of pro­tec­tion for tho­se pro­ducts than for the pro­ducts fal­ling within the scope of this Regulation.
(27) Regu­la­ti­on (EU) 2019/2144 of the Euro­pean Par­lia­ment and of the Coun­cil (11) lays down requi­re­ments for the type-appr­oval of motor vehic­les and of systems and com­pon­ents for tho­se vehic­les and intro­du­ces cer­tain cyber­se­cu­ri­ty requi­re­ments, inclu­ding in rela­ti­on to the ope­ra­ti­on of a cer­ti­fi­ed cyber­se­cu­ri­ty manage­ment system, soft­ware updates that include the orga­nizati­ons’ poli­ci­es and pro­ce­du­res for mana­ging cyber­se­cu­ri­ty risks throug­hout the life cycle of vehic­les, equip­ment and ser­vices in accordance with the appli­ca­ble United Nati­ons regu­la­ti­ons on tech­ni­cal spe­ci­fi­ca­ti­ons and cyber­se­cu­ri­ty, in par­ti­cu­lar UN Regu­la­ti­on No 155 – Uni­form pro­vi­si­ons con­cer­ning the appr­oval of vehic­les with regard to cyber­se­cu­ri­ty and cyber­se­cu­ri­ty manage­ment systems (12), and pro­vi­des for spe­ci­fic con­for­mi­ty assess­ment pro­ce­du­res. 155 – Uni­form pro­vi­si­ons con­cer­ning the appr­oval of vehic­les with regard to cyber­se­cu­ri­ty and the cyber­se­cu­ri­ty manage­ment system (12), and pro­vi­de for spe­ci­fic con­for­mi­ty assess­ment pro­ce­du­res. In the field of avia­ti­on, the main objec­ti­ve of Regu­la­ti­on (EU) 2018/1139 of the Euro­pean Par­lia­ment and of the Coun­cil (13) is to estab­lish and main­tain a high uni­form level of avia­ti­on safe­ty in the Uni­on. The Regu­la­ti­on estab­lishes a frame­work for essen­ti­al requi­re­ments for the air­wort­hi­ness of aero­nau­ti­cal pro­ducts, parts and appli­ances, inclu­ding soft­ware, which inclu­des obli­ga­ti­ons to pro­tect against infor­ma­ti­on secu­ri­ty thre­ats. The cer­ti­fi­ca­ti­on pro­cess under Regu­la­ti­on (EU) 2018/1139 ensu­res the trust­wort­hi­ness sought by this Regu­la­ti­on. Pro­ducts with digi­tal ele­ments cover­ed by Regu­la­ti­on (EU) 2019/2144 and pro­ducts cer­ti­fi­ed under Regu­la­ti­on (EU) 2018/1139 should the­r­e­fo­re not be sub­ject to the essen­ti­al cyber­se­cu­ri­ty requi­re­ments and con­for­mi­ty assess­ment pro­ce­du­res laid down in this Regulation.
(28) This Regu­la­ti­on lays down hori­zon­tal cyber­se­cu­ri­ty rules that are not inten­ded to app­ly spe­ci­fi­cal­ly to cer­tain sec­tors or cer­tain pro­ducts with digi­tal ele­ments. Nevert­hel­ess, sec­tor- or pro­duct-spe­ci­fic Uni­on legis­la­ti­on could be intro­du­ced with requi­re­ments that address all or some of the risks cover­ed by the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on. The appli­ca­ti­on of this Regu­la­ti­on to pro­ducts with digi­tal ele­ments that are cover­ed by other Uni­on legis­la­ti­on impo­sing requi­re­ments rela­ting to all or some of the risks cover­ed by the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on may be rest­ric­ted or exclu­ded in such cases, pro­vi­ded that the rest­ric­tion or exclu­si­on is com­pa­ti­ble with the gene­ral legal frame­work appli­ca­ble to tho­se pro­ducts and that the sec­tor-spe­ci­fic rules achie­ve at least the same level of pro­tec­tion as is ensu­red by this Regu­la­ti­on. The Com­mis­si­on should be empowered to adopt dele­ga­ted acts sup­ple­men­ting this Regu­la­ti­on with regard to the estab­lish­ment of such pro­ducts and rules. With regard to exi­sting Uni­on law to which such rest­ric­tions or exclu­si­ons should app­ly, this Regu­la­ti­on con­ta­ins spe­ci­fic pro­vi­si­ons to cla­ri­fy its rela­ti­on­ship with that Uni­on law.
(29) In order to ensu­re that pro­ducts with digi­tal ele­ments made available on the mar­ket can be effec­tively repai­red and their life­time exten­ded, an exemp­ti­on should be pro­vi­ded for spa­re parts. That exemp­ti­on should app­ly both to spa­re parts used for the repair of exi­sting devices made available befo­re the date of appli­ca­ti­on of this Regu­la­ti­on and to spa­re parts that have alre­a­dy under­go­ne a con­for­mi­ty assess­ment pro­ce­du­re in accordance with this Regulation.
(30) Com­mis­si­on Dele­ga­ted Regu­la­ti­on (EU) 2022/30 (14) pro­vi­des that the essen­ti­al requi­re­ments refer­red to in Artic­le 3(3)(d), (e) and (f) of Direc­ti­ve 2014/53/EU of the Euro­pean Par­lia­ment and of the Coun­cil (15), which rela­te to harmful effects on the net­work and misu­se of net­work resour­ces, per­so­nal data and pri­va­cy and fraud, app­ly to cer­tain radio equip­ment. Com­mis­si­on Imple­men­ting Decis­i­on C(2022) 5637 of 5 August 2022 on a stan­dar­dizati­on request to the Euro­pean Com­mit­tee for Stan­dar­dizati­on and the Euro­pean Com­mit­tee for Elec­tro­tech­ni­cal Stan­dar­dizati­on con­ta­ins requi­re­ments for the deve­lo­p­ment of spe­ci­fic stan­dards spe­ci­fy­ing how the­se three essen­ti­al requi­re­ments are to be addres­sed. The essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on cover all ele­ments of the essen­ti­al requi­re­ments refer­red to in Artic­le 3(3)(d), (e) and (f) of Direc­ti­ve 2014/53/EU. In addi­ti­on, the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on are con­si­stent with the objec­ti­ves of the requi­re­ments for the spe­ci­fic stan­dards pro­vi­ded for in this stan­dar­dizati­on man­da­te. The­r­e­fo­re, when the Com­mis­si­on repeals or amends Dele­ga­ted Regu­la­ti­on (EU) 2022/30 so that it no lon­ger applies to cer­tain pro­ducts cover­ed by this Regu­la­ti­on, the Com­mis­si­on and the Euro­pean stan­dar­dizati­on orga­ni­sa­ti­ons should take into account the stan­dar­dizati­on work car­ri­ed out under Imple­men­ting Decis­i­on C(2022) 5637 when draf­ting and deve­lo­ping har­mo­ni­zed stan­dards in order to faci­li­ta­te the imple­men­ta­ti­on of this Regu­la­ti­on. During the tran­si­tio­nal peri­od for the appli­ca­ti­on of this Regu­la­ti­on, the Com­mis­si­on should pro­vi­de gui­dance to manu­fac­tu­r­ers sub­ject to this Regu­la­ti­on and also to Dele­ga­ted Regu­la­ti­on (EU) 2022/30 in order to faci­li­ta­te the demon­stra­ti­on of com­pli­ance with both Regulations.
(31) Direc­ti­ve (EU) 2024/2853 of the Euro­pean Par­lia­ment and of the Coun­cil (16) is com­ple­men­ta­ry to this Regu­la­ti­on. This Direc­ti­ve lays down rules on lia­bi­li­ty for defec­ti­ve pro­ducts in order to allow inju­red per­sons to cla­im com­pen­sa­ti­on for dama­ge cau­sed by a defec­ti­ve pro­duct. It lays down the prin­ci­ple that the manu­fac­tu­rer of a pro­duct is lia­ble, regard­less of fault, for dama­ge cau­sed by the lack of safe­ty of his pro­duct (“strict lia­bi­li­ty”). If such a lack of safe­ty con­sists of a lack of safe­ty updates after the pro­duct has been pla­ced on the mar­ket and this cau­ses dama­ge, this could result in the manufacturer’s lia­bi­li­ty. This Regu­la­ti­on should lay down obli­ga­ti­ons for manu­fac­tu­r­ers in rela­ti­on to the pro­vi­si­on of such safe­ty updates.
(32) This Regu­la­ti­on should app­ly wit­hout pre­ju­di­ce to Regu­la­ti­on (EU) 2016/679 of the Euro­pean Par­lia­ment and of the Coun­cil (17), which con­ta­ins pro­vi­si­ons rela­ting to the estab­lish­ment of data pro­tec­tion cer­ti­fi­ca­ti­on mecha­nisms and of data pro­tec­tion seals and marks to demon­stra­te that data con­trol­lers and pro­ces­sors com­ply with the pro­vi­si­ons of the lat­ter Regu­la­ti­on when pro­ce­s­sing data. Such pro­ce­s­ses could be embedded in a pro­duct with digi­tal ele­ments. The prin­ci­ples of data pro­tec­tion by design and by default and cyber­se­cu­ri­ty in gene­ral are key ele­ments of Regu­la­ti­on (EU) 2016/679. By pro­tec­ting con­su­mers and orga­nizati­ons from cyber­se­cu­ri­ty risks, the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on should also help to impro­ve the pro­tec­tion of per­so­nal data and the pri­va­cy of indi­vi­du­als. Syn­er­gies in the coope­ra­ti­on bet­ween the Com­mis­si­on, the Euro­pean stan­dar­dizati­on orga­ni­sa­ti­ons, the Euro­pean Uni­on Agen­cy for Cyber­se­cu­ri­ty (ENISA), the Euro­pean Data Pro­tec­tion Board estab­lished by Regu­la­ti­on (EU) 2016/679 and the natio­nal data pro­tec­tion super­vi­so­ry aut­ho­ri­ties should be taken into account for both stan­dar­dizati­on and cer­ti­fi­ca­ti­on of cyber­se­cu­ri­ty aspects. Syn­er­gies bet­ween this Regu­la­ti­on and Uni­on data pro­tec­tion law should also be sought in the area of mar­ket sur­veil­lan­ce and law enforce­ment. To this end, the natio­nal mar­ket sur­veil­lan­ce aut­ho­ri­ties desi­gna­ted under this Regu­la­ti­on should coope­ra­te with the aut­ho­ri­ties super­vi­sing the appli­ca­ti­on of Uni­on data pro­tec­tion law. The lat­ter aut­ho­ri­ties should also have access to infor­ma­ti­on rele­vant for the per­for­mance of their tasks.
(33) To the ext­ent that their pro­ducts fall within the scope of this Regu­la­ti­on, Euro­pean digi­tal iden­ti­ty wal­let pro­vi­ders (EUid wal­lets) should com­ply with both the hori­zon­tal essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on and the spe­ci­fic secu­ri­ty requi­re­ments laid down in Artic­le 5a of Regu­la­ti­on (EU) No 910/2014, in accordance with Artic­le 5a(2) of Regu­la­ti­on (EU) No 910/2014 of the Euro­pean Par­lia­ment and of the Coun­cil (18). In order to faci­li­ta­te com­pli­ance, pro­vi­ders of EUid wal­lets should be able to demon­stra­te the com­pli­ance of EUid wal­lets with the requi­re­ments laid down in this Regu­la­ti­on and in Regu­la­ti­on (EU) No 910/2014 by having their pro­ducts cer­ti­fi­ed under a Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­me under Regu­la­ti­on (EU) 2019/881 for which the Com­mis­si­on has estab­lished, by means of a dele­ga­ted act, a pre­sump­ti­on of con­for­mi­ty with the requi­re­ments of this Regu­la­ti­on to the ext­ent that the cer­ti­fi­ca­te or parts the­reof cover tho­se requirements.
(34) When inte­gra­ting com­pon­ents sourced from third par­ties into devices with digi­tal ele­ments at the design and deve­lo­p­ment stage, manu­fac­tu­r­ers should exer­cise due dili­gence on tho­se com­pon­ents, inclu­ding free and open source soft­ware com­pon­ents that have not been made available on the mar­ket, to ensu­re that the devices are desi­gned, deve­lo­ped and manu­fac­tu­red in com­pli­ance with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on. The appro­pria­te level of due dili­gence depends on the natu­re and ext­ent of the cyber­se­cu­ri­ty risk asso­cia­ted with a par­ti­cu­lar com­po­nent and should take into account one or more of the fol­lo­wing mea­su­res for this pur­po­se: checking, whe­re appro­pria­te, whe­ther the manu­fac­tu­rer of a com­po­nent has demon­stra­ted com­pli­ance with this Regu­la­ti­on, inclu­ding a check on whe­ther the com­po­nent alre­a­dy bears the CE mar­king; checking whe­ther a com­po­nent is sub­ject to regu­lar secu­ri­ty updates, such as by checking past secu­ri­ty updates; checking whe­ther a com­po­nent is free from the vul­nerabi­li­ties regi­stered in the Euro­pean vul­nerabi­li­ty data­ba­se estab­lished pur­su­ant to Artic­le 12(2) of Direc­ti­ve (EU) 2022/2555 or other publicly available vul­nerabi­li­ty data­ba­ses, or car­ry­ing out addi­tio­nal secu­ri­ty checks. The vul­nerabi­li­ty manage­ment obli­ga­ti­ons laid down in this Regu­la­ti­on, which manu­fac­tu­r­ers shall com­ply with when pla­cing a device with digi­tal ele­ments on the mar­ket and during the sup­port peri­od, shall app­ly to devices with digi­tal ele­ments in their enti­re­ty, inclu­ding all inte­gra­ted com­pon­ents. If the manu­fac­tu­rer of the pro­duct with digi­tal ele­ments iden­ti­fi­es a vul­nerabi­li­ty in a com­po­nent, inclu­ding in a free and open source com­po­nent, as part of its due dili­gence, it should inform the per­son or enti­ty that manu­fac­tu­red or main­ta­ins the com­po­nent, fix the vul­nerabi­li­ty and, whe­re appro­pria­te, pro­vi­de the per­son or enti­ty with the secu­ri­ty patch applied.
(35) Imme­dia­te­ly after the tran­si­tio­nal peri­od for the appli­ca­ti­on of this Regu­la­ti­on, a manu­fac­tu­rer of a device with digi­tal ele­ments that incor­po­ra­tes one or more com­pon­ents sourced from third par­ties that are also sub­ject to this Regu­la­ti­on may not be able to car­ry out due dili­gence to veri­fy that the manu­fac­tu­r­ers of tho­se com­pon­ents have demon­stra­ted con­for­mi­ty with this Regu­la­ti­on, for exam­p­le by checking whe­ther the com­pon­ents alre­a­dy bear the CE mar­king. This may be the case if the con­sti­tu­ents have been inte­gra­ted befo­re this Regu­la­ti­on beco­mes appli­ca­ble to the manu­fac­tu­r­ers of the­se con­sti­tu­ents. In such a case, a manu­fac­tu­rer inte­gra­ting such com­pon­ents should ful­fill his due dili­gence obli­ga­ti­on in ano­ther way.
(36) Pro­ducts incor­po­ra­ting digi­tal ele­ments should, as a gene­ral rule, bear the CE mar­king indi­ca­ting their con­for­mi­ty with this Regu­la­ti­on in a visi­ble, legi­ble and inde­li­ble man­ner so that they can move free­ly within the inter­nal mar­ket. Mem­ber Sta­tes should not crea­te unju­sti­fi­ed obs­ta­cles to the pla­cing on the mar­ket of pro­ducts incor­po­ra­ting digi­tal ele­ments which com­ply with the requi­re­ments laid down in this Regu­la­ti­on and bear the CE mar­king. Fur­ther­mo­re, Mem­ber Sta­tes should not pre­vent the pre­sen­ta­ti­on or use of a pro­duct incor­po­ra­ting digi­tal ele­ments that does not com­ply with this Regu­la­ti­on at trade fairs, exhi­bi­ti­ons, demon­stra­ti­ons or simi­lar events, inclu­ding pro­to­ty­pes, pro­vi­ded that the pro­duct bears a visi­ble mar­king cle­ar­ly indi­ca­ting that the pro­duct does not com­ply with this Regu­la­ti­on and may not be made available on the mar­ket until it does so.
(37) In order to allow manu­fac­tu­r­ers to release soft­ware for test­ing pur­po­ses befo­re sub­jec­ting their devices incor­po­ra­ting digi­tal ele­ments to con­for­mi­ty assess­ment, Mem­ber Sta­tes should not pre­vent unfi­nis­hed soft­ware from being made available, for exam­p­le as alpha, beta or pre-release ver­si­ons, pro­vi­ded that the unfi­nis­hed soft­ware is made available only for as long as is neces­sa­ry for test­ing and coll­ec­ting feed­back. Manu­fac­tu­r­ers should ensu­re that soft­ware made available under tho­se con­di­ti­ons is released only after a risk assess­ment and com­plies as far as pos­si­ble with the safe­ty requi­re­ments of this Regu­la­ti­on in rela­ti­on to the cha­rac­te­ri­stics of devices incor­po­ra­ting digi­tal ele­ments. Manu­fac­tu­r­ers should also imple­ment the vul­nerabi­li­ty hand­ling requi­re­ments as far as pos­si­ble. Manu­fac­tu­r­ers should not force users to update to ver­si­ons that have only been released for test­ing purposes.
(38) In order to ensu­re that pro­ducts with digi­tal ele­ments do not pose cyber­se­cu­ri­ty risks to per­sons and orga­nizati­ons when pla­ced on the mar­ket, essen­ti­al cyber­se­cu­ri­ty requi­re­ments should be estab­lished for such pro­ducts. The­se essen­ti­al cyber­se­cu­ri­ty requi­re­ments, inclu­ding vul­nerabi­li­ty manage­ment requi­re­ments, app­ly to each indi­vi­du­al pro­duct with digi­tal ele­ments when it is pla­ced on the mar­ket, regard­less of whe­ther the pro­duct with digi­tal ele­ments is manu­fac­tu­red as a sin­gle unit or in series. For exam­p­le, for a pro­duct type, each indi­vi­du­al pro­duct with digi­tal ele­ments should have recei­ved all available secu­ri­ty patches or updates to address rele­vant secu­ri­ty issues when it is pla­ced on the mar­ket. If such pro­ducts with digi­tal ele­ments are sub­se­quent­ly phy­si­cal­ly or digi­tal­ly modi­fi­ed in a way not fore­seen by the manu­fac­tu­rer in the ori­gi­nal risk assess­ment and which may result in them no lon­ger mee­ting the rele­vant essen­ti­al cyber­se­cu­ri­ty requi­re­ments, the modi­fi­ca­ti­on should be con­side­red sub­stan­ti­al. For exam­p­le, repairs could be trea­ted in the same way as main­ten­an­ce work, pro­vi­ded that they do not modi­fy a pro­duct with digi­tal ele­ments that has alre­a­dy been pla­ced on the mar­ket in such a way that con­for­mi­ty with the appli­ca­ble requi­re­ments may be affec­ted or the inten­ded pur­po­se for which the pro­duct was tested may be changed.
(39) As with phy­si­cal repairs or modi­fi­ca­ti­ons, a device with digi­tal ele­ments should be con­side­red to be sub­stan­ti­al­ly modi­fi­ed by a soft­ware update if the soft­ware update chan­ges the inten­ded pur­po­se of the device and the­se chan­ges were not fore­seen by the manu­fac­tu­rer in the ori­gi­nal risk assess­ment, or if the natu­re of the hazard has chan­ged or the cyber­se­cu­ri­ty risk has increa­sed due to the soft­ware update and the updated ver­si­on of the device is made available on the mar­ket. If a secu­ri­ty update inten­ded to redu­ce the cyber­se­cu­ri­ty risk of a pro­duct with digi­tal ele­ments does not chan­ge the inten­ded pur­po­se of a pro­duct with digi­tal ele­ments, it is not con­side­red a sub­stan­ti­al chan­ge. This gene­ral­ly inclu­des cases whe­re a secu­ri­ty update only invol­ves minor adjust­ments to the source code. This could be the case, for exam­p­le, whe­re a secu­ri­ty update addres­ses a known vul­nerabi­li­ty, inclu­ding by chan­ging the func­tion­a­li­ty or per­for­mance of a pro­duct with digi­tal ele­ments for the sole pur­po­se of redu­cing cyber­se­cu­ri­ty risk. Simi­lar­ly, a minor update to func­tion­a­li­ty, such as a visu­al impro­ve­ment or the addi­ti­on of new lan­guages or new icons to the user inter­face, should gene­ral­ly not be con­side­red a mate­ri­al chan­ge. Con­ver­se­ly, a func­tion­al update that chan­ges the ori­gi­nal­ly inten­ded func­tions or the natu­re or per­for­mance of a pro­duct with digi­tal ele­ments and meets the abo­ve cri­te­ria should be con­side­red a mate­ri­al chan­ge, as the addi­ti­on of new func­tions usual­ly leads to a lar­ger attack sur­face and thus increa­ses the cyber­se­cu­ri­ty risk. This could be the case, for exam­p­le, if a new input ele­ment is added to an appli­ca­ti­on, so that the manu­fac­tu­rer must ensu­re ade­qua­te input vali­da­ti­on. When asses­sing whe­ther a func­tion­al update is to be con­side­red a sub­stan­ti­al chan­ge, it does not mat­ter whe­ther it is pro­vi­ded as a sepa­ra­te update or in com­bi­na­ti­on with a secu­ri­ty update. The Com­mis­si­on should issue gui­dance on how to deter­mi­ne what con­sti­tu­tes a sub­stan­ti­al change.
(40) In view of the repe­ti­ti­ve natu­re of soft­ware deve­lo­p­ment, manu­fac­tu­r­ers who have pla­ced new ver­si­ons of a soft­ware pro­duct on the mar­ket due to a sub­se­quent sub­stan­ti­al chan­ge to the pro­duct should be able to offer secu­ri­ty updates during the sup­port peri­od only for the ver­si­on of the soft­ware pro­duct that they last pla­ced on the mar­ket. They should only be entit­led to do so if the users of the rele­vant ear­lier ver­si­ons of the pro­duct have access to the last ver­si­on of the pro­duct they pla­ced on the mar­ket and if they do not incur addi­tio­nal costs for adap­ting the hard­ware or soft­ware envi­ron­ment in which they ope­ra­te the pro­duct. This could be the case, for exam­p­le, if an upgrade of the desk­top ope­ra­ting system does not requi­re new hard­ware, e.g. a faster cen­tral pro­ce­s­sing unit or more memo­ry. Not­wi­th­stan­ding this, the manu­fac­tu­rer should con­ti­n­ue to com­ply with other vul­nerabi­li­ty hand­ling requi­re­ments during the sup­port peri­od, such as having a coor­di­na­ted vul­nerabi­li­ty dis­clo­sure poli­cy or having arran­ge­ments in place to faci­li­ta­te the sha­ring of infor­ma­ti­on about poten­ti­al vul­nerabi­li­ties for any sub­se­quent signi­fi­cant­ly modi­fi­ed ver­si­ons of the soft­ware pro­duct pla­ced on the mar­ket. Manu­fac­tu­r­ers should be able to pro­vi­de minor secu­ri­ty or func­tion­al updates that do not con­sti­tu­te a sub­stan­ti­al chan­ge only for the latest ver­si­on or sub-ver­si­on of a soft­ware pro­duct that has not been sub­stan­ti­al­ly chan­ged. At the same time, in cases whe­re a hard­ware pro­duct, such as a smart­phone, is not com­pa­ti­ble with the latest ver­si­on of the ope­ra­ting system with which it was ori­gi­nal­ly sup­plied, the manu­fac­tu­rer should con­ti­n­ue to pro­vi­de secu­ri­ty updates during the sup­port peri­od at least for the latest com­pa­ti­ble ver­si­on of the ope­ra­ting system.
(41) In accordance with the gene­ral­ly accept­ed con­cept of sub­stan­ti­al modi­fi­ca­ti­on of pro­ducts sub­ject to Uni­on har­mo­nizati­on legis­la­ti­on, whe­re a sub­stan­ti­al modi­fi­ca­ti­on occurs which could affect the con­for­mi­ty of a pro­duct with digi­tal ele­ments with this Regu­la­ti­on, or whe­re the inten­ded pur­po­se of that pro­duct chan­ges, it is appro­pria­te to review the con­for­mi­ty of the pro­duct with digi­tal ele­ments and, whe­re appro­pria­te, to sub­ject it to a new con­for­mi­ty assess­ment. Whe­re the manu­fac­tu­rer car­ri­es out a con­for­mi­ty assess­ment invol­ving a third par­ty, a chan­ge that could lead to a sub­stan­ti­al modi­fi­ca­ti­on should be noti­fi­ed to the third party.
(42) Sub­jec­ting a device with digi­tal ele­ments to ‘over­haul’, ‘main­ten­an­ce’ and ‘repair’ as defi­ned in points 18, 19 and 20 of Artic­le 2 of Regu­la­ti­on (EU) 2024/1781 of the Euro­pean Par­lia­ment and of the Coun­cil (19) does not neces­s­a­ri­ly result in a sub­stan­ti­al chan­ge to the device, for exam­p­le if the inten­ded pur­po­se and func­tions are not chan­ged and the level of risk remains the same. Howe­ver, the addi­ti­on of digi­tal ele­ments to a pro­duct by the manu­fac­tu­rer could lead to chan­ges in the design and deve­lo­p­ment of the pro­duct and the­r­e­fo­re have an impact on its inten­ded pur­po­se and con­for­mi­ty with the requi­re­ments laid down in this Regulation.
(43) Pro­ducts with digi­tal ele­ments should be con­side­red important whe­re the nega­ti­ve impact of exploi­ting poten­ti­al cyber­se­cu­ri­ty vul­nerabi­li­ties in the pro­duct may be seve­re, inclu­ding due to its cyber­se­cu­ri­ty func­tion or a func­tion that poses a signi­fi­cant risk of adver­se impact in terms of its scope and oppor­tu­ni­ty, dis­rupt, con­trol or harm a lar­ge num­ber of other pro­ducts with digi­tal ele­ments or affect the health, safe­ty or inte­gri­ty of their users by direct­ly mani­pu­la­ting it, such as a key system func­tion, inclu­ding net­work manage­ment, con­fi­gu­ra­ti­on con­trol, vir­tua­lizati­on or per­so­nal data pro­ce­s­sing. In par­ti­cu­lar, vul­nerabi­li­ties in pro­ducts with digi­tal ele­ments that have a cyber­se­cu­ri­ty func­tion, such as boot mana­gers, can lead to a pro­li­fe­ra­ti­on of secu­ri­ty issues throug­hout the sup­p­ly chain. The seve­ri­ty of the impact of a secu­ri­ty inci­dent may also increa­se if the pro­duct pri­ma­ri­ly per­forms a key system func­tion, inclu­ding net­work manage­ment, con­fi­gu­ra­ti­on con­trol, vir­tua­lizati­on or per­so­nal data processing.
(44) Cer­tain cate­go­ries of pro­ducts with digi­tal ele­ments should be sub­ject to stric­ter con­for­mi­ty assess­ment pro­ce­du­res, while main­tai­ning pro­por­tio­na­li­ty. To that end, cri­ti­cal devices with digi­tal ele­ments should be divi­ded into two clas­ses reflec­ting the cyber­se­cu­ri­ty risk asso­cia­ted with tho­se cate­go­ries of devices. A secu­ri­ty inci­dent invol­ving cri­ti­cal devices with digi­tal ele­ments fal­ling into class II could have a grea­ter nega­ti­ve impact than a secu­ri­ty inci­dent invol­ving cri­ti­cal devices with digi­tal ele­ments fal­ling into class I, for exam­p­le becau­se of the natu­re of their cyber­se­cu­ri­ty func­tion or the per­for­mance of ano­ther func­tion that car­ri­es a signi­fi­cant risk of adver­se effects. An indi­ca­ti­on of major adver­se effects could be that devices with digi­tal ele­ments fal­ling into class II per­form eit­her a cyber­se­cu­ri­ty func­tion or ano­ther func­tion asso­cia­ted with a hig­her risk of adver­se effects than devices in class I, or both. Essen­ti­al devices with digi­tal ele­ments fal­ling within Class II should the­r­e­fo­re be sub­ject to a more strin­gent con­for­mi­ty assess­ment procedure.
(45) Essen­ti­al devices with digi­tal ele­ments refer­red to in this Regu­la­ti­on should be under­s­tood as devices that have the core func­tion of a cate­go­ry of essen­ti­al devices with digi­tal ele­ments defi­ned in this Regu­la­ti­on. For exam­p­le, this Regu­la­ti­on estab­lishes cate­go­ries of cri­ti­cal devices with digi­tal ele­ments which are defi­ned by their core func­tion as fire­walls or intru­si­on detec­tion systems or intru­si­on pre­ven­ti­on systems of class II. Con­se­quent­ly, fire­walls and intru­si­on detec­tion and pre­ven­ti­on systems are sub­ject to man­da­to­ry third par­ty con­for­mi­ty assess­ment. This does not app­ly to other pro­ducts with digi­tal ele­ments which are not clas­si­fi­ed as cri­ti­cal pro­ducts with digi­tal ele­ments and which may con­tain fire­walls or intru­si­on detec­tion systems or intru­si­on pre­ven­ti­on systems. The Com­mis­si­on should adopt an imple­men­ting act to spe­ci­fy the tech­ni­cal descrip­ti­on of the cate­go­ries of cri­ti­cal devices with digi­tal ele­ments fal­ling within Clas­ses I and II under this Regulation.
(46) The cate­go­ries of cri­ti­cal devices with digi­tal ele­ments set out in this Regu­la­ti­on are asso­cia­ted with a cyber­se­cu­ri­ty func­tion and are used for a func­tion that poses a signi­fi­cant risk of adver­se effects in terms of its scope and its abili­ty to dis­rupt, con­trol or harm a lar­ge num­ber of other devices with digi­tal ele­ments by direct­ly mani­pu­la­ting them. In addi­ti­on, the­se cate­go­ries of pro­ducts with digi­tal ele­ments are con­side­red cri­ti­cal depen­den­ci­es for the essen­ti­al faci­li­ties refer­red to in Artic­le 3(1) of Direc­ti­ve (EU) 2022/2555. The cate­go­ries of cri­ti­cal pro­ducts with digi­tal ele­ments that are listed in an Annex to this Regu­la­ti­on due to their cri­ti­cal­i­ty often alre­a­dy use dif­fe­rent forms of cer­ti­fi­ca­ti­on and are also cover­ed by the Euro­pean Cyber­se­cu­ri­ty Cer­ti­fi­ca­ti­on (EUCC) sche­me based on com­mon cri­te­ria laid down in Imple­men­ting Regu­la­ti­on (EU) 2024/482 (20). In order to ensu­re a com­mon ade­qua­te level of cyber­se­cu­ri­ty pro­tec­tion of cri­ti­cal pro­ducts with digi­tal ele­ments in the Uni­on, it could the­r­e­fo­re be appro­pria­te and pro­por­tio­na­te to sub­ject such pro­duct cate­go­ries to man­da­to­ry Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on by means of a dele­ga­ted act, whe­re a rele­vant Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­me for tho­se pro­ducts alre­a­dy exists and the Com­mis­si­on has car­ri­ed out an assess­ment of the poten­ti­al impact of the envi­sa­ged man­da­to­ry cer­ti­fi­ca­ti­on on the mar­ket. This assess­ment should take into account both the sup­p­ly and the demand side, inclu­ding whe­ther the­re is suf­fi­ci­ent demand for the rele­vant pro­ducts with digi­tal ele­ments from both Mem­ber Sta­tes and users to requi­re Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on, as well as the pur­po­ses for which the pro­ducts with digi­tal ele­ments are inten­ded to be used, inclu­ding the cri­ti­cal depen­den­ci­es the­re­on by the essen­ti­al enti­ties refer­red to in Artic­le 3(1) of Direc­ti­ve (EU) 2022/2555. The assess­ment should also ana­ly­ze the poten­ti­al impact of man­da­to­ry cer­ti­fi­ca­ti­on on the avai­la­bi­li­ty of tho­se pro­ducts on the inter­nal mar­ket and the capa­bi­li­ties and rea­di­ness of Mem­ber Sta­tes to imple­ment the rele­vant Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on schemes.
(47) Dele­ga­ted acts impo­sing man­da­to­ry Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on should iden­ti­fy the pro­ducts with digi­tal ele­ments that have the core func­tions of a cate­go­ry of cri­ti­cal pro­ducts with digi­tal ele­ments defi­ned in this Regu­la­ti­on to be sub­ject to man­da­to­ry cer­ti­fi­ca­ti­on and the requi­red assu­rance level, which should be at least ‘medi­um’. The requi­red assu­rance level should be pro­por­tio­na­te to the level of cyber­se­cu­ri­ty risk asso­cia­ted with the pro­duct with digi­tal ele­ments. For exam­p­le, if the device with digi­tal ele­ments has the core func­tion of a cate­go­ry of cri­ti­cal devices with digi­tal ele­ments defi­ned in this Regu­la­ti­on and is inten­ded for use in a sen­si­ti­ve or cri­ti­cal envi­ron­ment, such as devices inten­ded for use by the essen­ti­al enti­ties refer­red to in Artic­le 3(1) of Direc­ti­ve (EU) 2022/2555, the hig­hest assu­rance level may be required.
(48) In order to ensu­re com­mon and ade­qua­te cyber­se­cu­ri­ty pro­tec­tion of pro­ducts with digi­tal ele­ments in the Uni­on that have the core func­tion of a cate­go­ry of cri­ti­cal pro­ducts with digi­tal ele­ments defi­ned in this Regu­la­ti­on, the power to adopt dele­ga­ted acts should also be dele­ga­ted to the Com­mis­si­on in respect of amen­ding this Regu­la­ti­on by adding or dele­ting cate­go­ries of cri­ti­cal devices with digi­tal ele­ments for which manu­fac­tu­r­ers could be requi­red to obtain a Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­te under a Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­me pur­su­ant to Regu­la­ti­on (EU) 2019/881 in order to demon­stra­te com­pli­ance with this Regu­la­ti­on. A new cate­go­ry of cri­ti­cal pro­ducts with digi­tal ele­ments may be added to the­se cate­go­ries if the­re is a cri­ti­cal depen­den­cy of the essen­ti­al faci­li­ties refer­red to in Artic­le 3(1) of Direc­ti­ve (EU) 2022/2555 on the­se pro­ducts or if they are affec­ted by secu­ri­ty inci­dents or con­tain exploi­ted vul­nerabi­li­ties and this could lead to dis­rup­ti­ons of cri­ti­cal sup­p­ly chains. When asses­sing whe­ther it is neces­sa­ry to add or remo­ve cate­go­ries of cri­ti­cal pro­ducts with digi­tal ele­ments by means of a dele­ga­ted act, the Com­mis­si­on should be able to take into account whe­ther Mem­ber Sta­tes have iden­ti­fi­ed at natio­nal level pro­ducts with digi­tal ele­ments that are cri­ti­cal to the resi­li­ence of essen­ti­al faci­li­ties within the mea­ning of Artic­le 3(1) of Direc­ti­ve (EU) 2022/2555 and that are incre­a­sing­ly sub­ject to cyber-attacks on the sup­p­ly chain, which could result in serious dis­rup­ti­ons. In addi­ti­on, the Com­mis­si­on should have the pos­si­bi­li­ty to take into account the out­co­me of the coor­di­na­ted risk assess­ments on the secu­ri­ty of cri­ti­cal sup­p­ly chains at Uni­on level car­ri­ed out in accordance with Artic­le 22 of Direc­ti­ve (EU) 2022/2555.
(49) The Com­mis­si­on should ensu­re that a broad ran­ge of rele­vant stake­hol­ders are con­sul­ted in a struc­tu­red and regu­lar man­ner when deve­lo­ping mea­su­res to imple­ment this Regu­la­ti­on. This should in par­ti­cu­lar be the case when the Com­mis­si­on con­siders the pos­si­ble need to update the lists of cate­go­ries of important or cri­ti­cal pro­ducts with digi­tal ele­ments, con­sul­ting rele­vant manu­fac­tu­r­ers and taking into account their views in order to ana­ly­ze the cyber­se­cu­ri­ty risks and the cost-bene­fit ratio asso­cia­ted with the clas­si­fi­ca­ti­on of such cate­go­ries of pro­ducts as important or critical.
(50) This regu­la­ti­on spe­ci­fi­cal­ly addres­ses cyber­se­cu­ri­ty risks. Howe­ver, pro­ducts with digi­tal ele­ments may pre­sent other secu­ri­ty risks that are not always rela­ted to cyber­se­cu­ri­ty but may result from a secu­ri­ty breach. Tho­se risks should con­ti­n­ue to be addres­sed by other rele­vant Uni­on har­mo­nizati­on legis­la­ti­on than this Regu­la­ti­on. Whe­re Uni­on har­mo­nizati­on legis­la­ti­on other than this Regu­la­ti­on is not appli­ca­ble, they should be sub­ject to Regu­la­ti­on (EU) 2023/988 of the Euro­pean Par­lia­ment and of the Coun­cil (21). The­r­e­fo­re, given the tar­ge­ted natu­re of this Regu­la­ti­on, by way of dero­ga­ti­on from point (b) of the third sub­pa­ra­graph of Artic­le 2(1) of Regu­la­ti­on (EU) 2023/988, in rela­ti­on to secu­ri­ty risks not cover­ed by this Regu­la­ti­on, Sec­tion 1 of Chap­ter III, Chap­ters V and VII and Chap­ters IX to XI of Regu­la­ti­on (EU) 2023/988 should also app­ly to pro­ducts incor­po­ra­ting digi­tal ele­ments whe­re tho­se pro­ducts are not sub­ject to spe­ci­fic requi­re­ments of Uni­on har­mo­nizati­on legis­la­ti­on other than this Regu­la­ti­on within the mea­ning of point (27) of Artic­le 3 of Regu­la­ti­on (EU) 2023/988.
(51) Pro­ducts with digi­tal ele­ments clas­si­fi­ed as high-risk AI-systems in accordance with Artic­le 6 of Regu­la­ti­on (EU) 2024/1689 of the Euro­pean Par­lia­ment and of the Coun­cil (22) and fal­ling within the scope of this Regu­la­ti­on should com­ply with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on. Whe­re tho­se high-risk AI-systems com­ply with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on, they should be dee­med to com­ply with the cyber­se­cu­ri­ty requi­re­ments set out in Artic­le 15 of Regu­la­ti­on (EU) 2024/1689 to the ext­ent that tho­se requi­re­ments are cover­ed by the EU decla­ra­ti­on of con­for­mi­ty or parts the­reof issued pur­su­ant to this Regu­la­ti­on. To that end, when asses­sing the cyber­se­cu­ri­ty risks asso­cia­ted with a pro­duct with digi­tal ele­ments that is clas­si­fi­ed as a high-risk AI-system in accordance with Regu­la­ti­on (EU) 2024/1689, to be taken into account during the plan­ning, design, deve­lo­p­ment, pro­duc­tion, deli­very and main­ten­an­ce pha­ses of such a pro­duct, as requi­red by this Regu­la­ti­on, the risks to the cyber resi­li­ence of an AI system are con­side­red in rela­ti­on to attempts by unaut­ho­ri­zed third par­ties to alter the use, beha­viour or per­for­mance of the system, inclu­ding AI-spe­ci­fic vul­nerabi­li­ties such as data poi­so­ning or adver­sa­ri­al attack, and, whe­re appli­ca­ble, risks to fun­da­men­tal rights, in accordance with Regu­la­ti­on (EU) 2024/1689. For the con­for­mi­ty assess­ment pro­ce­du­res con­cer­ning the essen­ti­al cyber­se­cu­ri­ty requi­re­ments for a device with digi­tal ele­ments that falls within the scope of this Regu­la­ti­on and is clas­si­fi­ed as a high-risk AI-system, Artic­le 43 of Regu­la­ti­on (EU) 2024/1689 should in prin­ci­ple app­ly instead of the rele­vant pro­vi­si­ons of this Regu­la­ti­on. Howe­ver, that rule should not have the effect of redu­cing the level of assu­rance requi­red for the important or cri­ti­cal pro­ducts with digi­tal ele­ments refer­red to in this Regu­la­ti­on. The­r­e­fo­re, by way of dero­ga­ti­on from that rule, high-risk AI-systems which fall within the scope of Regu­la­ti­on (EU) 2024/1689 and which are also important or cri­ti­cal devices with digi­tal ele­ments as refer­red to in this Regu­la­ti­on and to which the con­for­mi­ty assess­ment pro­ce­du­re based on inter­nal con­trol set out in Annex VI to Regu­la­ti­on (EU) 2024/1689 is applied should be sub­ject to the con­for­mi­ty assess­ment pro­ce­du­res of this Regu­la­ti­on as far as the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on are con­cer­ned. In that case, for all other aspects cover­ed by Regu­la­ti­on (EU) 2024/1689, the rele­vant pro­vi­si­ons on con­for­mi­ty assess­ment based on inter­nal con­trol set out in Annex VI to that Regu­la­ti­on should apply.
(52) In order to enhan­ce the secu­ri­ty of pro­ducts with digi­tal ele­ments pla­ced on the inter­nal mar­ket, it is neces­sa­ry to lay down essen­ti­al cyber­se­cu­ri­ty requi­re­ments appli­ca­ble to such pro­ducts. Tho­se essen­ti­al cyber­se­cu­ri­ty requi­re­ments should be wit­hout pre­ju­di­ce to the coor­di­na­ted risk assess­ments on the secu­ri­ty of cri­ti­cal sup­p­ly chains at Uni­on level pro­vi­ded for in Artic­le 22 of Direc­ti­ve (EU) 2022/2555, which take into account both tech­ni­cal and, whe­re appli­ca­ble, non-tech­ni­cal risk fac­tors, such as undue influence of a third coun­try on sup­pliers. Fur­ther­mo­re, they should be wit­hout pre­ju­di­ce to the pre­ro­ga­ti­ves of Mem­ber Sta­tes to lay down addi­tio­nal requi­re­ments that take into account non-tech­ni­cal fac­tors to ensu­re a high level of resi­li­ence, inclu­ding tho­se defi­ned in Com­mis­si­on Recom­men­da­ti­on (EU) 2019/534 (23), in the EU-wide coor­di­na­ted cyber­se­cu­ri­ty risk assess­ment of 5G net­works and in the EU 5G cyber­se­cu­ri­ty tool­box adopted by the NIS Coope­ra­ti­on Group estab­lished under Artic­le 14 of Direc­ti­ve (EU) 2022/2555.
(53) Manu­fac­tu­r­ers of devices that fall within the scope of Regu­la­ti­on (EU) 2023/1230 of the Euro­pean Par­lia­ment and of the Coun­cil (24) and who­se pro­ducts are also devices with digi­tal ele­ments within the mea­ning of this Regu­la­ti­on should com­ply with both the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on and the essen­ti­al health and safe­ty requi­re­ments laid down in Regu­la­ti­on (EU) 2023/1230. The essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on and cer­tain essen­ti­al requi­re­ments laid down in Regu­la­ti­on (EU) 2023/1230 may address simi­lar cyber­se­cu­ri­ty risks. The­r­e­fo­re, com­pli­ance with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on could faci­li­ta­te com­pli­ance with the essen­ti­al requi­re­ments that also cover cer­tain cyber­se­cu­ri­ty risks laid down in Regu­la­ti­on (EU) 2023/1230, in par­ti­cu­lar the requi­re­ments rela­ting to pro­tec­tion against tam­pe­ring and the safe­ty and relia­bi­li­ty of con­trol systems set out in Sec­tions 1.1.9 and 1.2.1 of Annex III to that Regu­la­ti­on. Such syn­er­gy must be demon­stra­ted by the manu­fac­tu­rer, for exam­p­le through the appli­ca­ti­on of har­mo­ni­zed stan­dards or other tech­ni­cal spe­ci­fi­ca­ti­ons cove­ring the rele­vant essen­ti­al cyber­se­cu­ri­ty requi­re­ments, after a risk assess­ment for the rele­vant cyber­se­cu­ri­ty risks has been car­ri­ed out. The manu­fac­tu­rer should also fol­low the appli­ca­ble con­for­mi­ty assess­ment pro­ce­du­res in accordance with this Regu­la­ti­on and Regu­la­ti­on (EU) 2023/1230. The Com­mis­si­on and the Euro­pean stan­dar­dizati­on orga­ni­sa­ti­ons should pro­mo­te con­si­sten­cy in the pre­pa­ra­to­ry work sup­port­ing the imple­men­ta­ti­on of this Regu­la­ti­on and Regu­la­ti­on (EU) 2023/1230 and the rela­ted stan­dar­dizati­on pro­ce­du­res as regards the assess­ment of cyber­se­cu­ri­ty risks and the way in which tho­se risks are to be cover­ed by har­mo­ni­zed stan­dards with regard to the rele­vant essen­ti­al requi­re­ments. In par­ti­cu­lar, the Com­mis­si­on and the Euro­pean stan­dar­dizati­on orga­ni­sa­ti­ons should take into account this Regu­la­ti­on when draf­ting and deve­lo­ping har­mo­ni­zed stan­dards in order to faci­li­ta­te the imple­men­ta­ti­on of Regu­la­ti­on (EU) 2023/1230, in par­ti­cu­lar with regard to the cyber­se­cu­ri­ty aspects rela­ted to pro­tec­tion against cor­rup­ti­on and the safe­ty and relia­bi­li­ty of con­trol systems listed in Sec­tions 1.1.9 and 1.2.1 of Annex III to that Regu­la­ti­on. The Com­mis­si­on should pro­vi­de gui­dance to assist manu­fac­tu­r­ers sub­ject to this Regu­la­ti­on and also to Regu­la­ti­on (EU) 2023/1230, in par­ti­cu­lar to faci­li­ta­te the demon­stra­ti­on of com­pli­ance with the rele­vant essen­ti­al requi­re­ments of this Regu­la­ti­on and of Regu­la­ti­on (EU) 2023/1230.
(54) In order to ensu­re that pro­ducts incor­po­ra­ting digi­tal ele­ments are secu­re both at the time of their pla­cing on the mar­ket and during the expec­ted life of the pro­duct incor­po­ra­ting digi­tal ele­ments, it is neces­sa­ry to estab­lish essen­ti­al cyber­se­cu­ri­ty requi­re­ments for the hand­ling of vul­nerabi­li­ties and essen­ti­al cyber­se­cu­ri­ty requi­re­ments rela­ting to the cha­rac­te­ri­stics of pro­ducts incor­po­ra­ting digi­tal ele­ments. Manu­fac­tu­r­ers should both com­ply with all essen­ti­al cyber­se­cu­ri­ty requi­re­ments rela­ted to vul­nerabi­li­ty hand­ling throug­hout the sup­port peri­od and deter­mi­ne which other essen­ti­al cyber­se­cu­ri­ty requi­re­ments rela­ted to pro­duct cha­rac­te­ri­stics are rele­vant for the type of devices with digi­tal ele­ments con­cer­ned. To that end, manu­fac­tu­r­ers should car­ry out an assess­ment of the cyber­se­cu­ri­ty risks asso­cia­ted with a pro­duct with digi­tal ele­ments in order to iden­ti­fy rele­vant risks and essen­ti­al cyber­se­cu­ri­ty requi­re­ments so that they pro­vi­de their pro­ducts with digi­tal ele­ments wit­hout known explo­ita­ble vul­nerabi­li­ties that could affect the secu­ri­ty of tho­se pro­ducts and to app­ly appro­pria­te har­mo­ni­zed stan­dards, com­mon spe­ci­fi­ca­ti­ons or Euro­pean or inter­na­tio­nal stan­dards as appropriate.
(55) Whe­re cer­tain essen­ti­al cyber­se­cu­ri­ty requi­re­ments are not appli­ca­ble to a device with digi­tal ele­ments, the manu­fac­tu­rer should cle­ar­ly justi­fy this in the cyber­se­cu­ri­ty risk assess­ment accom­pany­ing the tech­ni­cal docu­men­ta­ti­on. This could be the case if a basic cyber­se­cu­ri­ty requi­re­ment is incom­pa­ti­ble with the natu­re of a pro­duct with digi­tal ele­ments. For exam­p­le, the inten­ded pur­po­se of a pro­duct with digi­tal ele­ments may requi­re the manu­fac­tu­rer to com­ply with wide­ly reco­gnized inter­ope­ra­bi­li­ty stan­dards, even if its secu­ri­ty fea­tures are no lon­ger sta­te of the art. Other Uni­on legis­la­ti­on also requi­res manu­fac­tu­r­ers to com­ply with spe­ci­fic inter­ope­ra­bi­li­ty requi­re­ments. Whe­re a cyber­se­cu­ri­ty essen­ti­al requi­re­ment is not appli­ca­ble to a pro­duct with digi­tal ele­ments, but the manu­fac­tu­rer has iden­ti­fi­ed cyber­se­cu­ri­ty risks rela­ted to that cyber­se­cu­ri­ty essen­ti­al requi­re­ment, it should take mea­su­res to address tho­se risks by other means, for exam­p­le by limi­ting the inten­ded use of the pro­duct to tru­sted envi­ron­ments or by informing users of tho­se risks.
(56) One of the most important steps users need to take to pro­tect their pro­ducts with digi­tal ele­ments from cyber-attacks is to install the latest available secu­ri­ty updates as quick­ly as pos­si­ble. Manu­fac­tu­r­ers should the­r­e­fo­re design their pro­ducts and set up pro­ce­du­res so that pro­ducts with digi­tal ele­ments include auto­ma­tic fea­tures for the noti­fi­ca­ti­on, dis­tri­bu­ti­on, down­load and instal­la­ti­on of secu­ri­ty updates, espe­ci­al­ly in the case of con­su­mer pro­ducts. They should also offer the pos­si­bi­li­ty to aut­ho­ri­ze the down­load and instal­la­ti­on of secu­ri­ty updates as a final step. Users should con­ti­n­ue to have the pos­si­bi­li­ty to disable auto­ma­tic updates, with a clear and easy-to-use pro­cess com­ple­men­ted by clear expl­ana­ti­ons on how users can opt out of updates. The requi­re­ments on auto­ma­tic updates set out in an Annex to this Regu­la­ti­on shall not app­ly to devices with digi­tal ele­ments that are pri­ma­ri­ly inten­ded to be inte­gra­ted as com­pon­ents into other devices. They shall also not app­ly to devices incor­po­ra­ting digi­tal ele­ments whe­re users would not nor­mal­ly expect auto­ma­tic updates, inclu­ding devices incor­po­ra­ting digi­tal ele­ments inten­ded for use in pro­fes­sio­nal ICT net­works and in par­ti­cu­lar in cri­ti­cal and indu­stri­al envi­ron­ments whe­re auto­ma­tic updating could lead to dis­rup­ti­on of ope­ra­ti­ons. Regard­less of whe­ther a pro­duct with digi­tal ele­ments is desi­gned to recei­ve auto­ma­tic updates or not, its manu­fac­tu­rer should inform users of vul­nerabi­li­ties and pro­vi­de secu­ri­ty updates wit­hout delay. Whe­re a pro­duct with digi­tal fea­tures has a user inter­face or simi­lar tech­ni­cal means that allow direct inter­ac­tion with its users, the manu­fac­tu­rer should use the­se fea­tures to inform users that their pro­duct with digi­tal fea­tures has rea­ched the end of its sup­port peri­od. The noti­fi­ca­ti­ons should be limi­t­ed to what is neces­sa­ry to ensu­re the effec­ti­ve rece­ipt of that infor­ma­ti­on and should not have a nega­ti­ve impact on the user expe­ri­ence of the pro­duct with digi­tal elements.
(57) In order to make vul­nerabi­li­ty hand­ling pro­ce­du­res more trans­pa­rent and to ensu­re that users are not forced to install new fea­ture updates just to get the latest secu­ri­ty updates, manu­fac­tu­r­ers should ensu­re that new secu­ri­ty updates are pro­vi­ded sepa­ra­te­ly from fea­ture updates, whe­re tech­ni­cal­ly feasible.
(58) The Joint Com­mu­ni­ca­ti­on of the Com­mis­si­on and the High Repre­sen­ta­ti­ve of the Uni­on for For­eign Affairs and Secu­ri­ty Poli­cy of 20 June 2023 on a “Euro­pean Stra­tegy for Eco­no­mic Secu­ri­ty” sta­tes that the Uni­on needs to maxi­mi­ze the bene­fits of its eco­no­mic open­ness while mini­mi­zing the risks ari­sing from eco­no­mic depen­den­ci­es on high-risk sup­pliers through a com­mon stra­te­gic frame­work for the Union’s eco­no­mic secu­ri­ty. Depen­den­ci­es on high-risk pro­vi­ders of pro­ducts with digi­tal ele­ments may con­sti­tu­te a stra­te­gic risk that needs to be addres­sed at Uni­on level, in par­ti­cu­lar whe­re the pro­ducts with digi­tal ele­ments are inten­ded for use by the essen­ti­al enti­ties refer­red to in Artic­le 3(1) of Direc­ti­ve (EU) 2022/2555. The­se risks may be rela­ted, inter alia, to the juris­dic­tion appli­ca­ble to the manu­fac­tu­rer, the cha­rac­te­ri­stics of its cor­po­ra­te owner­ship and the con­trol­ling rela­ti­on­ship with the govern­ment of a third coun­try in which it is estab­lished, in par­ti­cu­lar whe­re the third coun­try enga­ges in indu­stri­al espio­na­ge or irre­spon­si­ble sta­te beha­vi­or in cyber­space and its laws allow arbi­tra­ry access to busi­ness tran­sac­tions or cor­po­ra­te data of any kind, inclu­ding com­mer­ci­al­ly sen­si­ti­ve data, inclu­ding com­mer­ci­al­ly sen­si­ti­ve data, and may impo­se intel­li­gence obli­ga­ti­ons wit­hout demo­cra­tic safe­guards, over­sight mecha­nisms, due pro­cess or the right to appeal to an inde­pen­dent tri­bu­nal. When deter­mi­ning the mate­ria­li­ty of a cyber­se­cu­ri­ty risk for the pur­po­ses of this Regu­la­ti­on, the Com­mis­si­on and the mar­ket sur­veil­lan­ce aut­ho­ri­ties should also take into account non-tech­ni­cal risk fac­tors, in par­ti­cu­lar tho­se iden­ti­fi­ed as a result of coor­di­na­ted sup­p­ly chain secu­ri­ty risk assess­ments at Uni­on level car­ri­ed out in accordance with Artic­le 22 of Direc­ti­ve (EU) 2022/2555, within the scope of their respon­si­bi­li­ties set out in this Regulation.
(59) In order to ensu­re the safe­ty of pro­ducts incor­po­ra­ting digi­tal ele­ments after they have been pla­ced on the mar­ket, manu­fac­tu­r­ers should deter­mi­ne the sup­port peri­od, which should take into account the expec­ted life­time of the pro­duct incor­po­ra­ting digi­tal ele­ments. When set­ting a sup­port peri­od, a manu­fac­tu­rer should take into account, in par­ti­cu­lar, the legi­ti­ma­te expec­ta­ti­ons of users, the natu­re of the pro­duct and the rele­vant Uni­on law defi­ning the life­time of pro­ducts incor­po­ra­ting digi­tal ele­ments. Manu­fac­tu­r­ers should also be able to take into account other rele­vant fac­tors. The cri­te­ria should be applied in such a way as to ensu­re pro­por­tio­na­li­ty when deter­mi­ning the sup­port peri­ods. Upon request, a manu­fac­tu­rer should make available to the mar­ket sur­veil­lan­ce aut­ho­ri­ties the infor­ma­ti­on taken into account when deter­mi­ning the sup­port peri­od of a pro­duct with digi­tal elements.
(60) The sup­port peri­od for which the manu­fac­tu­rer ensu­res the effec­ti­ve tre­at­ment of vul­nerabi­li­ties should be at least five years, unless the life­time of the pro­duct with digi­tal ele­ments is less than five years, in which case the manu­fac­tu­rer should ensu­re the tre­at­ment of vul­nerabi­li­ties for the cor­re­spon­ding life­time. Whe­re it can rea­son­ab­ly be expec­ted that the pro­duct with digi­tal ele­ments will be used for more than five years, as is often the case for hard­ware com­pon­ents such as mother­boards or micro­pro­ces­sors, for net­work devices such as rou­ters, modems or swit­ches, and for soft­ware such as ope­ra­ting systems or video editing tools, manu­fac­tu­r­ers should ensu­re cor­re­spon­din­gly lon­ger sup­port peri­ods. In par­ti­cu­lar, pro­ducts with digi­tal ele­ments inten­ded for use in indu­stri­al envi­ron­ments, such as indu­stri­al con­trol systems, are often used for much lon­ger peri­ods of time. A manu­fac­tu­rer should only be able to set a sup­port peri­od of less than five years if this is justi­fi­ed by the natu­re of the digi­tal ele­ment pro­duct con­cer­ned and the pro­duct is expec­ted to be in use for less than five years, in which case the sup­port peri­od should cor­re­spond to the expec­ted life­time. For exam­p­le, the life­time of a cont­act tra­cing app inten­ded for use during a pan­de­mic could be limi­t­ed to the dura­ti­on of the pan­de­mic. In addi­ti­on, some soft­ware appli­ca­ti­ons can, by their natu­re, only be pro­vi­ded on a sub­scrip­ti­on basis, espe­ci­al­ly if the appli­ca­ti­on is no lon­ger available to the user after the sub­scrip­ti­on expi­res and is the­r­e­fo­re no lon­ger used.
(61) For pro­ducts with digi­tal ele­ments, when the end of the rele­vant sup­port peri­od is rea­ched, manu­fac­tu­r­ers should con­sider releasing the source code of tho­se pro­ducts with digi­tal ele­ments eit­her to other com­pa­nies that com­mit to an exten­ded pro­vi­si­on of vul­nerabi­li­ty hand­ling ser­vices or to the public so that vul­nerabi­li­ties can be hand­led even after the end of the sup­port peri­od. If manu­fac­tu­r­ers share the source code with other com­pa­nies, they should be able to pro­tect the owner­ship of the pro­duct with digi­tal ele­ments and pre­vent the dis­clo­sure of the source code to the public, for exam­p­le through con­trac­tu­al agreements.
(62) In order to ensu­re that manu­fac­tu­r­ers across the Uni­on set com­pa­ra­ble sup­port peri­ods for com­pa­ra­ble pro­ducts with digi­tal ele­ments, ADCO should publish sta­tis­tics on the avera­ge sup­port peri­ods set by manu­fac­tu­r­ers for cate­go­ries of pro­ducts with digi­tal ele­ments and issue gui­de­lines spe­ci­fy­ing appro­pria­te sup­port peri­ods for tho­se cate­go­ries. In addi­ti­on, in order to ensu­re a har­mo­ni­zed approach across the inter­nal mar­ket, the Com­mis­si­on should be able to adopt dele­ga­ted acts to set mini­mum sup­port peri­ods for cer­tain cate­go­ries of devices whe­re data pro­vi­ded by mar­ket sur­veil­lan­ce aut­ho­ri­ties indi­ca­te eit­her that the sup­port peri­ods set by manu­fac­tu­r­ers syste­ma­ti­cal­ly do not com­ply with the cri­te­ria for set­ting sup­port peri­ods laid down in this Regu­la­ti­on or indi­ca­te that manu­fac­tu­r­ers from dif­fe­rent Mem­ber Sta­tes set unju­sti­fi­a­bly dif­fe­rent sup­port periods.
(63) Manu­fac­tu­r­ers should set up a sin­gle point of cont­act that allo­ws users to easi­ly com­mu­ni­ca­te with them, for exam­p­le to report vul­nerabi­li­ties of the pro­duct with digi­tal ele­ments and to obtain infor­ma­ti­on on the­se vul­nerabi­li­ties. They should make the sin­gle point of cont­act easi­ly acce­s­si­ble to users, pro­vi­de clear infor­ma­ti­on on how to reach them and keep this infor­ma­ti­on up to date. If manu­fac­tu­r­ers choo­se to offer auto­ma­ted tools such as chat boxes, they should also pro­vi­de a pho­ne num­ber or other digi­tal cont­act opti­ons such as an email address or cont­act form. The sin­gle point of cont­act should not rely sole­ly on auto­ma­ted tools.
(64) Manu­fac­tu­r­ers should make their pro­ducts with digi­tal ele­ments available on the mar­ket with a secu­re default con­fi­gu­ra­ti­on and pro­vi­de users with secu­ri­ty updates free of char­ge. Manu­fac­tu­r­ers should only be able to dero­ga­te from the basic cyber­se­cu­ri­ty requi­re­ments in the case of bespo­ke pro­ducts tail­o­red for a spe­ci­fic busi­ness user for a spe­ci­fic pur­po­se and whe­re both the manu­fac­tu­rer and the user have expli­ci­t­ly agreed to dif­fe­rent con­trac­tu­al terms.
(65) Manu­fac­tu­r­ers should report actively exploi­ted vul­nerabi­li­ties in pro­ducts with digi­tal ele­ments and serious secu­ri­ty inci­dents affec­ting the secu­ri­ty of tho­se pro­ducts simul­ta­neous­ly to both the desi­gna­ted coor­di­na­tor Com­pu­ter Secu­ri­ty Inci­dent Respon­se Team (CSIRT) and ENISA via the sin­gle report­ing plat­form. The reports should be sub­mit­ted via the elec­tro­nic report­ing end­point of a CSIRT desi­gna­ted as coor­di­na­tor and should be acce­s­si­ble to ENISA at the same time.
(66) Manu­fac­tu­r­ers should actively report exploi­ted vul­nerabi­li­ties in order to ensu­re that the CSIRTs desi­gna­ted as coor­di­na­tors and ENISA have an ade­qua­te over­view of tho­se vul­nerabi­li­ties and recei­ve the infor­ma­ti­on they need to car­ry out their tasks under Direc­ti­ve (EU) 2022/2555 and to enhan­ce the over­all level of cyber­se­cu­ri­ty of essen­ti­al and cri­ti­cal enti­ties in accordance with Artic­le 3 of that Direc­ti­ve, and to ensu­re the effec­ti­ve func­tio­ning of mar­ket sur­veil­lan­ce aut­ho­ri­ties. As most pro­ducts with digi­tal ele­ments are mar­ke­ted throug­hout the inter­nal mar­ket, any exploi­ted vul­nerabi­li­ty in a pro­duct with digi­tal ele­ments should be con­side­red a thre­at to the func­tio­ning of the inter­nal mar­ket. In agree­ment with the manu­fac­tu­rer, ENISA should dis­c­lo­se reme­di­ed vul­nerabi­li­ties in the Euro­pean vul­nerabi­li­ty data­ba­se estab­lished under Artic­le 12(2) of Direc­ti­ve (EU) 2022/2555. The Euro­pean vul­nerabi­li­ty data­ba­se will assist manu­fac­tu­r­ers in iden­ti­fy­ing known explo­ita­ble vul­nerabi­li­ties in their pro­ducts to ensu­re that secu­re pro­ducts are made available on the market.
(67) Manu­fac­tu­r­ers should also noti­fy the CSIRT desi­gna­ted as coor­di­na­tor and ENISA of any serious secu­ri­ty inci­dent affec­ting the secu­ri­ty of a pro­duct with digi­tal ele­ments. In order to enable users to react quick­ly to serious secu­ri­ty inci­dents affec­ting the secu­ri­ty of their pro­ducts with digi­tal ele­ments, manu­fac­tu­r­ers should also inform their users of such inci­dents and, whe­re appro­pria­te, of cor­rec­ti­ve actions that users can take to miti­ga­te the impact of the inci­dent, for exam­p­le by publi­shing rele­vant infor­ma­ti­on on their web­sites or, if the manu­fac­tu­rer can cont­act the users and the cyber­se­cu­ri­ty risks justi­fy it, by cont­ac­ting the users directly.
(68) Actively exploi­ted vul­nerabi­li­ties are cases whe­re a manu­fac­tu­rer dis­co­vers that a secu­ri­ty breach affec­ting its users or other natu­ral or legal per­sons is due to a mali­cious actor taking advan­ta­ge of a flaw in one of the pro­ducts with digi­tal ele­ments pro­vi­ded by the manu­fac­tu­rer on the mar­ket. Such vul­nerabi­li­ties may, for exam­p­le, be weak­ne­s­ses in the iden­ti­fi­ca­ti­on and authen­ti­ca­ti­on func­tions of a pro­duct. Vul­nerabi­li­ties iden­ti­fi­ed wit­hout mali­cious intent during good faith test­ing, inve­sti­ga­ti­on, reme­dia­ti­on or dis­clo­sure aimed at the secu­ri­ty and pro­tec­tion of the system owner and its users should not be repor­ta­ble. Serious secu­ri­ty inci­dents affec­ting the secu­ri­ty of the pro­duct with digi­tal ele­ments, on the other hand, refer to situa­tions whe­re a cyber­se­cu­ri­ty inci­dent affects the manufacturer’s deve­lo­p­ment, manu­fac­tu­ring or main­ten­an­ce pro­ce­s­ses in such a way that it could lead to an increa­sed cyber­se­cu­ri­ty risk to users or others. The­se serious secu­ri­ty inci­dents include, for exam­p­le, the case whe­re an attacker has suc­cessful­ly infil­tra­ted a mali­cious pro­gram into the release chan­nel through which the manu­fac­tu­rer releases secu­ri­ty updates to users.
(69) In order to ensu­re that noti­fi­ca­ti­ons can be quick­ly for­ward­ed to all rele­vant CSIRTs desi­gna­ted as coor­di­na­tors and that manu­fac­tu­r­ers have the pos­si­bi­li­ty of indi­vi­du­al noti­fi­ca­ti­on at each stage of the noti­fi­ca­ti­on pro­cess, ENISA should estab­lish a sin­gle noti­fi­ca­ti­on plat­form with natio­nal end­points for elec­tro­nic noti­fi­ca­ti­on. The ongo­ing ope­ra­ti­on of the sin­gle report­ing plat­form should be mana­ged and main­tai­ned by ENISA. The CSIRTs desi­gna­ted as coor­di­na­tors should inform their respec­ti­ve mar­ket sur­veil­lan­ce aut­ho­ri­ties of repor­ted vul­nerabi­li­ties or secu­ri­ty inci­dents. The sin­gle report­ing plat­form should be desi­gned in such a way that the con­fi­den­tia­li­ty of reports is main­tai­ned, in par­ti­cu­lar for vul­nerabi­li­ties for which a secu­ri­ty update is not yet available. In addi­ti­on, ENISA should estab­lish pro­ce­du­res for the secu­re and con­fi­den­ti­al hand­ling of infor­ma­ti­on. On the basis of the infor­ma­ti­on it coll­ects, ENISA should pro­du­ce a tech­ni­cal report every two years on emer­ging trends in cyber­se­cu­ri­ty risks for pro­ducts with digi­tal ele­ments and sub­mit it to the Coope­ra­ti­on Group estab­lished under Artic­le 14 of Direc­ti­ve (EU) 2022/2555.
(70) In excep­tio­nal cir­cum­stances, and in par­ti­cu­lar at the request of the manu­fac­tu­rer, the CSIRT desi­gna­ted as coor­di­na­tor that initi­al­ly recei­ves the noti­fi­ca­ti­on should be able to deci­de to defer the trans­mis­si­on through the sin­gle noti­fi­ca­ti­on plat­form to the other rele­vant CSIRTs desi­gna­ted as coor­di­na­tors, whe­re this can be justi­fi­ed for cyber­se­cu­ri­ty rea­sons and for a strict­ly neces­sa­ry peri­od of time. The CSIRT desi­gna­ted as coor­di­na­tor should inform ENISA wit­hout delay of the decis­i­on to defer and the rea­sons for it, as well as when it intends to re-deploy. The Com­mis­si­on should, by means of a dele­ga­ted act, deve­lop tech­ni­cal details on the con­di­ti­ons under which cyber­se­cu­ri­ty grounds could be invo­ked and coope­ra­te with the CSIRTs net­work estab­lished under Artic­le 15 of Direc­ti­ve (EU) 2022/2555 and ENISA in the pre­pa­ra­ti­on of the draft dele­ga­ted act. Cyber­se­cu­ri­ty rea­sons may include an ongo­ing coor­di­na­ted vul­nerabi­li­ty dis­clo­sure pro­cess or situa­tions whe­re a manu­fac­tu­rer is expec­ted to take a miti­ga­ti­on action in the near future and the cyber­se­cu­ri­ty risks asso­cia­ted with an imme­dia­te refer­ral through the sin­gle noti­fi­ca­ti­on plat­form out­weigh the bene­fits of such refer­ral. At the request of the CSIRT desi­gna­ted as coor­di­na­tor, ENISA should be able to assist the CSIRT in invo­king cyber­se­cu­ri­ty rea­sons rela­ted to the defer­ral of the for­war­ding of the noti­fi­ca­ti­on on the basis of the infor­ma­ti­on recei­ved by ENISA from that CSIRT regar­ding the decis­i­on to defer a noti­fi­ca­ti­on for tho­se cyber­se­cu­ri­ty-rela­ted rea­sons. In addi­ti­on, in par­ti­cu­lar­ly excep­tio­nal cir­cum­stances, ENISA should not recei­ve all the details of a noti­fi­ca­ti­on of an actively exploi­ted vul­nerabi­li­ty at the same time. This would be the case if the manu­fac­tu­rer indi­ca­tes in its noti­fi­ca­ti­on that the repor­ted vul­nerabi­li­ty has been actively exploi­ted by a mali­cious actor and that, accor­ding to the available infor­ma­ti­on, it has not been exploi­ted in any Mem­ber Sta­te other than that of the CSIRT desi­gna­ted as coor­di­na­tor to which the manu­fac­tu­rer has noti­fi­ed the vul­nerabi­li­ty, if imme­dia­te dis­se­mi­na­ti­on of the vul­nerabi­li­ty report would be likely to lead to a leak of infor­ma­ti­on the dis­clo­sure of which would be con­tra­ry to the essen­ti­al inte­rests of that Mem­ber Sta­te, or if the repor­ted vul­nerabi­li­ty would pose an imme­dia­te high cyber­se­cu­ri­ty risk due to the dis­se­mi­na­ti­on. In such cases, ENISA shall only have simul­ta­neous access to the infor­ma­ti­on that the manu­fac­tu­rer has made a noti­fi­ca­ti­on, to gene­ral infor­ma­ti­on on the pro­duct with digi­tal ele­ments con­cer­ned, to the infor­ma­ti­on on the gene­ral natu­re of the explo­ita­ti­on and to infor­ma­ti­on that the­se secu­ri­ty rea­sons have been invo­ked by the manu­fac­tu­rer and that the full con­tent of the noti­fi­ca­ti­on is the­r­e­fo­re with­held. The full noti­fi­ca­ti­on should be made available to ENISA and other rele­vant CSIRTs desi­gna­ted as coor­di­na­tors if the CSIRT desi­gna­ted as coor­di­na­tor initi­al­ly recei­ving the noti­fi­ca­ti­on deter­mi­nes that tho­se safe­ty grounds reflec­ting par­ti­cu­lar­ly excep­tio­nal cir­cum­stances within the mea­ning of this Regu­la­ti­on no lon­ger exist. Whe­re ENISA con­siders, on the basis of the available infor­ma­ti­on, that the­re is a syste­mic risk to the secu­ri­ty of the inter­nal mar­ket, it should recom­mend to the CSIRT that recei­ved the noti­fi­ca­ti­on to for­ward the com­ple­te noti­fi­ca­ti­on to the other CSIRTs desi­gna­ted as coor­di­na­tors and to ENISA itself.
(71) When manu­fac­tu­r­ers report an actively exploi­ted vul­nerabi­li­ty or a serious secu­ri­ty inci­dent affec­ting the secu­ri­ty of the pro­duct with digi­tal ele­ments, they should indi­ca­te how sen­si­ti­ve they con­sider the repor­ted infor­ma­ti­on to be. The CSIRT desi­gna­ted as coor­di­na­tor that initi­al­ly recei­ves the noti­fi­ca­ti­on should take this infor­ma­ti­on into account when asses­sing whe­ther the noti­fi­ca­ti­on sug­gests excep­tio­nal cir­cum­stances that justi­fy defer­ring the for­war­ding of the noti­fi­ca­ti­on to the other rele­vant CSIRTs desi­gna­ted as coor­di­na­tors for legi­ti­ma­te cyber­se­cu­ri­ty rea­sons. It should also take this infor­ma­ti­on into account when asses­sing whe­ther the noti­fi­ca­ti­on of an actively exploi­ted vul­nerabi­li­ty sug­gests par­ti­cu­lar­ly excep­tio­nal cir­cum­stances justi­fy­ing that the full noti­fi­ca­ti­on is not made available to ENISA at the same time. In addi­ti­on, the CSIRTs desi­gna­ted as coor­di­na­tors should be able to take this infor­ma­ti­on into account when deter­mi­ning appro­pria­te mea­su­res to miti­ga­te the risks ari­sing from the rele­vant vul­nerabi­li­ties and incidents.
(72) In order to sim­pli­fy the report­ing of infor­ma­ti­on requi­red under this Regu­la­ti­on, taking into account other com­ple­men­ta­ry report­ing obli­ga­ti­ons laid down in Uni­on law, such as Regu­la­ti­on (EU) 2016/679, Regu­la­ti­on (EU) 2022/2554 of the Euro­pean Par­lia­ment and of the Coun­cil (25), Direc­ti­ve 2002/58/EC of the Euro­pean Par­lia­ment and of the Coun­cil (26) and Direc­ti­ve (EU) 2022/2555, and to redu­ce the admi­ni­stra­ti­ve bur­den on insti­tu­ti­ons, Mem­ber Sta­tes are encou­ra­ged to con­sider estab­li­shing natio­nal one-stop-shops for such report­ing obli­ga­ti­ons. The use of such natio­nal sin­gle points of cont­act for inci­dent report­ing under Regu­la­ti­on (EU) 2016/679 and Direc­ti­ve 2002/58/EC should be wit­hout pre­ju­di­ce to the appli­ca­ti­on of the pro­vi­si­ons of Regu­la­ti­on (EU) 2016/679 and Direc­ti­ve 2002/58/EC, in par­ti­cu­lar the pro­vi­si­ons on the inde­pen­dence of the aut­ho­ri­ties refer­red to the­r­ein. When estab­li­shing the sin­gle report­ing plat­form refer­red to in this Regu­la­ti­on, ENISA should take into account the pos­si­bi­li­ty that the natio­nal elec­tro­nic report­ing end­points refer­red to in this Regu­la­ti­on may be inte­gra­ted into natio­nal one-stop-shops, which may also include other report­ing requi­red under Uni­on law.
(73) In order to bene­fit from past expe­ri­ence, ENISA should con­sult other Uni­on insti­tu­ti­ons or agen­ci­es mana­ging plat­forms or data­ba­ses sub­ject to strict secu­ri­ty requi­re­ments, such as the Euro­pean Uni­on Agen­cy for the Ope­ra­tio­nal Manage­ment of Lar­ge-Sca­le IT Systems in the Area of Free­dom, Secu­ri­ty and Justi­ce (eu-LISA), when estab­li­shing the sin­gle report­ing plat­form refer­red to in this Regu­la­ti­on. ENISA should also assess pos­si­ble com­ple­men­ta­ri­ties with the Euro­pean vul­nerabi­li­ty data­ba­se estab­lished under Artic­le 12(2) of Direc­ti­ve (EU) 2022/2555.
(74) Manu­fac­tu­r­ers and other natu­ral and legal per­sons should be able to report on a vol­un­t­a­ry basis to a CSIRT desi­gna­ted as coor­di­na­tor or to ENISA any vul­nerabi­li­ty con­tai­ned in a pro­duct with digi­tal ele­ments, cyber thre­ats that could affect the risk pro­fi­le of a pro­duct with digi­tal ele­ments, any secu­ri­ty inci­dent affec­ting the secu­ri­ty of the pro­duct with digi­tal ele­ments and near mis­ses that could have led to such a secu­ri­ty incident.
(75) Mem­ber Sta­tes should address as far as pos­si­ble the chal­lenges faced by vul­nerabi­li­ty rese­ar­chers, inclu­ding their poten­ti­al cri­mi­nal lia­bi­li­ty, in accordance with natio­nal legis­la­ti­on. As natu­ral and legal per­sons rese­ar­ching vul­nerabi­li­ties could be sub­ject to cri­mi­nal and civil lia­bi­li­ty in some Mem­ber Sta­tes, Mem­ber Sta­tes are encou­ra­ged to adopt gui­de­lines on the non-pro­se­cu­ti­on of infor­ma­ti­on secu­ri­ty rese­ar­chers and to adopt an exemp­ti­on from civil lia­bi­li­ty for their activities.
(76) Manu­fac­tu­r­ers of pro­ducts with digi­tal ele­ments should imple­ment coor­di­na­ted vul­nerabi­li­ty dis­clo­sure sche­mes to faci­li­ta­te the report­ing of vul­nerabi­li­ties by natu­ral or legal per­sons eit­her direct­ly to the manu­fac­tu­rer or indi­rect­ly and anony­mously, if reque­sted, through the CSIRTs desi­gna­ted as coor­di­na­tors for the pur­po­ses of coor­di­na­ted vul­nerabi­li­ty dis­clo­sure in accordance with Artic­le 12(1) of Direc­ti­ve (EU) 2022/2555. The manu­fac­tu­r­ers’ approach to coor­di­na­ted vul­nerabi­li­ty dis­clo­sure should pro­vi­de for a struc­tu­red pro­cess in which vul­nerabi­li­ties are repor­ted to the manu­fac­tu­rer in a way that allo­ws the manu­fac­tu­rer to dia­gno­se and address such vul­nerabi­li­ties befo­re detail­ed infor­ma­ti­on about the vul­nerabi­li­ty is dis­c­lo­sed to third par­ties or the public. In addi­ti­on, manu­fac­tu­r­ers should also con­sider publi­shing their secu­ri­ty poli­ci­es in machi­ne-rea­da­ble for­mat. Given that infor­ma­ti­on about explo­ita­ble vul­nerabi­li­ties in wide­ly used pro­ducts with digi­tal ele­ments can fetch high pri­ces on the black mar­ket, manu­fac­tu­r­ers of such pro­ducts should be able to imple­ment pro­grams as part of their coor­di­na­ted vul­nerabi­li­ty dis­clo­sure poli­ci­es to incen­ti­vi­ze vul­nerabi­li­ty report­ing by ensu­ring that indi­vi­du­als or enti­ties recei­ve reco­gni­ti­on and rewards for their efforts. The­se are so-cal­led “bug boun­ty programs”.
(77) To faci­li­ta­te vul­nerabi­li­ty ana­ly­sis, manu­fac­tu­r­ers should iden­ti­fy and docu­ment which com­pon­ents are inclu­ded in pro­ducts with digi­tal ele­ments and, whe­re appro­pria­te, draw up a soft­ware bill of mate­ri­als. A soft­ware bill of mate­ri­als can pro­vi­de tho­se who manu­fac­tu­re, purcha­se and ope­ra­te soft­ware with infor­ma­ti­on that helps them bet­ter under­stand the sup­p­ly chain, which has num­e­rous bene­fits, par­ti­cu­lar­ly hel­ping manu­fac­tu­r­ers and users to track known emer­ging vul­nerabi­li­ties and cyber­se­cu­ri­ty risks. It is par­ti­cu­lar­ly important that manu­fac­tu­r­ers ensu­re that their pro­ducts with digi­tal ele­ments do not con­tain vul­nerable com­pon­ents deve­lo­ped by third par­ties. Manu­fac­tu­r­ers should not be requi­red to publish the soft­ware bill of materials.
(78) In the con­text of the new com­plex busi­ness models rela­ted to online sales, a com­pa­ny ope­ra­ting online can offer a varie­ty of ser­vices. Depen­ding on the natu­re of the ser­vices pro­vi­ded in rela­ti­on to a spe­ci­fic pro­duct with digi­tal ele­ments, the same under­ta­king may fall into dif­fe­rent cate­go­ries of busi­ness models or eco­no­mic ope­ra­tors. Whe­re an under­ta­king only pro­vi­des online inter­me­dia­ti­on ser­vices for a spe­ci­fic pro­duct with digi­tal ele­ments and that under­ta­king is only an online mar­ket­place pro­vi­der within the mea­ning of Artic­le 3(14) of Regu­la­ti­on (EU) 2023/988, it shall not fall within any of the cate­go­ries of eco­no­mic ope­ra­tors within the mea­ning of this Regu­la­ti­on. Whe­re an under­ta­king is an online mar­ket­place pro­vi­der that also acts as an eco­no­mic ope­ra­tor within the mea­ning of this Regu­la­ti­on when sel­ling cer­tain pro­ducts with digi­tal ele­ments, it should be sub­ject to the obli­ga­ti­ons laid down for that type of eco­no­mic ope­ra­tor in this Regu­la­ti­on. For exam­p­le, if the pro­vi­der of an online mar­ket­place also sells a pro­duct with digi­tal ele­ments, it is con­side­red to be a trader in rela­ti­on to the sale of that pro­duct. Simi­lar­ly, if the com­pa­ny in que­sti­on sells its own bran­ded pro­ducts with digi­tal ele­ments, it would be con­side­red a manu­fac­tu­rer and would the­r­e­fo­re have to com­ply with the requi­re­ments appli­ca­ble to manu­fac­tu­r­ers. In addi­ti­on, some com­pa­nies may be con­side­red ful­fill­ment ser­vice pro­vi­ders within the mea­ning of Artic­le 3(11) of Regu­la­ti­on (EU) 2019/1020 of the Euro­pean Par­lia­ment and of the Coun­cil (27) if they offer the rele­vant ser­vices. The cases in que­sti­on would have to be asses­sed on a case-by-case basis. Given the pro­mi­nent role that online mar­ket­places play in enab­ling e‑commerce, they should endea­vor to coope­ra­te with the mar­ket sur­veil­lan­ce aut­ho­ri­ties of the Mem­ber Sta­tes to help ensu­re that pro­ducts with digi­tal ele­ments purcha­sed through online mar­ket­places com­ply with the cyber­se­cu­ri­ty requi­re­ments laid down in this Regulation.
(79) In order to faci­li­ta­te the assess­ment of con­for­mi­ty with the requi­re­ments laid down in this Regu­la­ti­on, a pre­sump­ti­on of con­for­mi­ty should app­ly to pro­ducts incor­po­ra­ting digi­tal ele­ments which are in con­for­mi­ty with har­mo­ni­zed stan­dards trans­po­sing the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on into detail­ed tech­ni­cal spe­ci­fi­ca­ti­ons adopted in accordance with Regu­la­ti­on (EU) No 1025/2012 of the Euro­pean Par­lia­ment and of the Coun­cil (28). That Regu­la­ti­on lays down a pro­ce­du­re for objec­tions to har­mo­ni­zed stan­dards whe­re tho­se stan­dards do not ful­ly meet the requi­re­ments laid down in this Regu­la­ti­on. The stan­dar­dizati­on pro­cess should ensu­re a balan­ced repre­sen­ta­ti­on of inte­rests and effec­ti­ve invol­vement of civil socie­ty stake­hol­ders, inclu­ding con­su­mer orga­nizati­ons. Inter­na­tio­nal stan­dards that are con­si­stent with the level of cyber­se­cu­ri­ty pro­tec­tion sought by the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on should also be taken into account in order to sup­port the deve­lo­p­ment of har­mo­ni­zed stan­dards and the imple­men­ta­ti­on of this Regu­la­ti­on and to faci­li­ta­te com­pli­ance by busi­nesses, in par­ti­cu­lar micro, small and medi­um-sized enter­pri­ses and glo­bal­ly acti­ve enterprises.
(80) The time­ly deve­lo­p­ment of har­mo­ni­zed stan­dards during the tran­si­tio­nal peri­od for the appli­ca­ti­on of this Regu­la­ti­on and their avai­la­bi­li­ty befo­re the date of appli­ca­ti­on of this Regu­la­ti­on will be par­ti­cu­lar­ly important for its effec­ti­ve imple­men­ta­ti­on. This is par­ti­cu­lar­ly the case for important pro­ducts with Class I digi­tal ele­ments. The avai­la­bi­li­ty of har­mo­ni­zed stan­dards will allow manu­fac­tu­r­ers of the pro­ducts con­cer­ned to car­ry out con­for­mi­ty assess­ments through the inter­nal con­trol pro­ce­du­re and may thus help to avo­id bot­t­len­ecks and delays in the acti­vi­ties of con­for­mi­ty assess­ment bodies.
(81) Regu­la­ti­on (EU) 2019/881 estab­lishes a vol­un­t­a­ry Euro­pean frame­work for the cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on of ICT pro­ducts, pro­ce­s­ses and ser­vices. The Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­mes pro­vi­de a com­mon frame­work for user con­fi­dence in the use of pro­ducts with digi­tal ele­ments that fall within the scope of this Regu­la­ti­on. This Regu­la­ti­on should the­r­e­fo­re crea­te syn­er­gies with Regu­la­ti­on (EU) 2019/881. In order to faci­li­ta­te the assess­ment of con­for­mi­ty with the requi­re­ments laid down in this Regu­la­ti­on, devices with digi­tal ele­ments that have been cer­ti­fi­ed under a Euro­pean cyber­se­cu­ri­ty sche­me estab­lished by the Com­mis­si­on in an imple­men­ting act in accordance with Regu­la­ti­on (EU) 2019/881, or for which a decla­ra­ti­on of con­for­mi­ty has been issued under such a sche­me, are pre­su­med to com­ply with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on, pro­vi­ded that the Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­te or decla­ra­ti­on of con­for­mi­ty or parts the­reof cover tho­se requi­re­ments. The need for new Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­mes for devices with digi­tal ele­ments should be con­side­red in the light of this Regu­la­ti­on, inclu­ding in the deve­lo­p­ment of the Uni­on rol­ling work pro­gram under Regu­la­ti­on (EU) 2019/881. Whe­re a new sche­me for devices with digi­tal ele­ments is nee­ded, for exam­p­le to faci­li­ta­te com­pli­ance with this Regu­la­ti­on, the Com­mis­si­on may request ENISA to deve­lop pos­si­ble sche­mes in accordance with Artic­le 48 of Regu­la­ti­on (EU) 2019/881. Such future Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­mes for pro­ducts with digi­tal ele­ments should take into account the essen­ti­al cyber­se­cu­ri­ty requi­re­ments and con­for­mi­ty assess­ment pro­ce­du­res laid down in this Regu­la­ti­on and faci­li­ta­te com­pli­ance with this Regu­la­ti­on. For Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­mes that enter into force befo­re the ent­ry into force of this Regu­la­ti­on, fur­ther spe­ci­fi­ca­ti­ons may be requi­red on detail­ed aspects con­cer­ning the appli­ca­ti­on of a pre­sump­ti­on of con­for­mi­ty. The Com­mis­si­on should be empowered to adopt dele­ga­ted acts to spe­ci­fy the con­di­ti­ons under which the Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­mes may be used to demon­stra­te com­pli­ance with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on. Moreo­ver, in order to avo­id an exce­s­si­ve admi­ni­stra­ti­ve bur­den, manu­fac­tu­r­ers should not be obli­ged to have a third-par­ty con­for­mi­ty assess­ment car­ri­ed out for the rele­vant requi­re­ments, as pro­vi­ded for in this Regu­la­ti­on, whe­re a Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­te for at least level ‘medi­um’ has been issued under such Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on schemes.
(82) Upon the ent­ry into force of Imple­men­ting Regu­la­ti­on (EU) 2024/482, which con­cerns pro­ducts fal­ling within the scope of this Regu­la­ti­on, such as hard­ware secu­ri­ty modu­les and micro­pro­ces­sors, the Com­mis­si­on should be able to spe­ci­fy, by means of a dele­ga­ted act, how the EUCC may con­fer a pre­sump­ti­on of con­for­mi­ty with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments or parts the­reof laid down in this Regu­la­ti­on. In addi­ti­on, such a dele­ga­ted act may spe­ci­fy how a cer­ti­fi­ca­te issued under the EUCC may wai­ve the obli­ga­ti­on for manu­fac­tu­r­ers under this Regu­la­ti­on to have a third-par­ty assess­ment car­ri­ed out for the requi­re­ments concerned.
(83) The exi­sting Euro­pean stan­dar­dizati­on frame­work, which is based on the prin­ci­ples of the New Approach as set out in the Coun­cil Reso­lu­ti­on of 7 May 1985 on a new approach to tech­ni­cal har­mo­nizati­on and stan­dar­dizati­on and Regu­la­ti­on (EU) No 1025/2012, pro­vi­des the stan­dard frame­work for the deve­lo­p­ment of stan­dards pro­vi­ding for a pre­sump­ti­on of con­for­mi­ty with the rele­vant essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on. Euro­pean stan­dards should be mar­ket-dri­ven, take into account the public inte­rest and the poli­cy objec­ti­ves set out in the Commission’s man­da­te to one or more Euro­pean stan­dar­dizati­on bodies to deve­lop har­mo­ni­zed stan­dards within a given dead­line, and be based on con­sen­sus. Howe­ver, in the absence of rele­vant refe­ren­ces to har­mo­ni­zed stan­dards, the Com­mis­si­on should be able to adopt imple­men­ting acts estab­li­shing com­mon spe­ci­fi­ca­ti­ons for the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on in excep­tio­nal cases, as a fall­back solu­ti­on and with due respect for the role and tasks of the Euro­pean stan­dar­dizati­on orga­ni­sa­ti­ons, in order to faci­li­ta­te the manufacturer’s obli­ga­ti­on to com­ply with tho­se essen­ti­al cyber­se­cu­ri­ty requi­re­ments whe­re the stan­dar­dizati­on pro­cess is blocked or whe­re the­re is a delay in the deve­lo­p­ment of appro­pria­te har­mo­ni­zed stan­dards. Whe­re such a delay is due to the tech­ni­cal com­ple­xi­ty of the stan­dard con­cer­ned, the Com­mis­si­on should take this into account befo­re con­side­ring the estab­lish­ment of com­mon specifications.
(84) In order to be as effi­ci­ent as pos­si­ble in defi­ning com­mon spe­ci­fi­ca­ti­ons cove­ring the essen­ti­al cyber­se­cu­ri­ty requi­re­ments refer­red to in this Regu­la­ti­on, the Com­mis­si­on should invol­ve rele­vant stake­hol­ders in the process.
(85) With regard to the publi­ca­ti­on of the refe­rence of har­mo­ni­zed stan­dards in the Offi­ci­al Jour­nal of the Euro­pean Uni­on in accordance with Regu­la­ti­on (EU) No 1025/2012, a rea­sonable peri­od means a peri­od during which the refe­rence of the stan­dard, its cor­ri­gen­dum or its amend­ment is expec­ted to be published in the Offi­ci­al Jour­nal of the Euro­pean Uni­on and which should not exce­ed one year after the dead­line for the pre­pa­ra­ti­on of the draft Euro­pean stan­dard in accordance with Regu­la­ti­on (EU) No 1025/2012.
(86) In order to faci­li­ta­te the assess­ment of con­for­mi­ty with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on, a pre­sump­ti­on of con­for­mi­ty should app­ly to pro­ducts incor­po­ra­ting digi­tal ele­ments that com­ply with the com­mon spe­ci­fi­ca­ti­ons adopted by the Com­mis­si­on pur­su­ant to this Regu­la­ti­on in order to for­mu­la­te detail­ed tech­ni­cal spe­ci­fi­ca­ti­ons for tho­se requirements.
(87) The use of har­mo­ni­zed stan­dards, com­mon spe­ci­fi­ca­ti­ons or Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­mes adopted in accordance with Regu­la­ti­on (EU) 2019/881, which pro­vi­de a pre­sump­ti­on of con­for­mi­ty with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments for pro­ducts incor­po­ra­ting digi­tal ele­ments, will faci­li­ta­te con­for­mi­ty assess­ment by manu­fac­tu­r­ers. If the manu­fac­tu­rer choo­ses not to use the­se means for cer­tain requi­re­ments, he must indi­ca­te in his tech­ni­cal docu­men­ta­ti­on how con­for­mi­ty is achie­ved by other means. In addi­ti­on, the appli­ca­ti­on of har­mo­ni­zed stan­dards, com­mon spe­ci­fi­ca­ti­ons or Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­mes adopted under Regu­la­ti­on (EU) 2019/881 would faci­li­ta­te the veri­fi­ca­ti­on of con­for­mi­ty of pro­ducts with digi­tal ele­ments by mar­ket sur­veil­lan­ce aut­ho­ri­ties by con­fer­ring a pre­sump­ti­on of con­for­mi­ty on manu­fac­tu­r­ers. The­r­e­fo­re, manu­fac­tu­r­ers of pro­ducts with digi­tal ele­ments are encou­ra­ged to app­ly the­se har­mo­ni­zed stan­dards, com­mon spe­ci­fi­ca­ti­ons or Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on schemes.
(88) Manu­fac­tu­r­ers should draw up an EU decla­ra­ti­on of con­for­mi­ty to pro­vi­de the infor­ma­ti­on requi­red under this Regu­la­ti­on on the com­pli­ance of the devices with digi­tal ele­ments with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on and, whe­re appli­ca­ble, with other rele­vant Uni­on har­mo­nizati­on legis­la­ti­on to which the device with digi­tal ele­ments is sub­ject. Manu­fac­tu­r­ers may also be requi­red by other Uni­on acts to draw up an EU decla­ra­ti­on of con­for­mi­ty. In order to ensu­re effec­ti­ve access to infor­ma­ti­on for the pur­po­ses of mar­ket sur­veil­lan­ce, a sin­gle EU decla­ra­ti­on of con­for­mi­ty should be drawn up in rela­ti­on to com­pli­ance with all rele­vant Uni­on acts. In order to redu­ce the admi­ni­stra­ti­ve bur­den on eco­no­mic ope­ra­tors, it should be per­mis­si­ble for that sin­gle EU decla­ra­ti­on of con­for­mi­ty to con­sist of a file com­po­sed of the rele­vant indi­vi­du­al decla­ra­ti­ons of conformity.
(89) The CE mar­king expres­ses the con­for­mi­ty of a pro­duct and is the visi­ble result of a who­le pro­cess that inclu­des con­for­mi­ty assess­ment in a broad sen­se. The gene­ral prin­ci­ples gover­ning the CE mar­king are laid down in Regu­la­ti­on (EC) No 765/2008 of the Euro­pean Par­lia­ment and of the Coun­cil (29). The rules for the affixing of the CE mar­king on pro­ducts incor­po­ra­ting digi­tal ele­ments should be laid down in this Regu­la­ti­on. The CE mar­king should be the only mar­king which gua­ran­tees the con­for­mi­ty of pro­ducts incor­po­ra­ting digi­tal ele­ments with the requi­re­ments laid down in this Regulation.
(90) In order to enable eco­no­mic ope­ra­tors to demon­stra­te con­for­mi­ty with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on and to enable mar­ket sur­veil­lan­ce aut­ho­ri­ties to ensu­re that pro­ducts with digi­tal ele­ments made available on the mar­ket com­ply with tho­se requi­re­ments, it is neces­sa­ry to pro­vi­de for con­for­mi­ty assess­ment pro­ce­du­res. Decis­i­on No 768/2008/EC of the Euro­pean Par­lia­ment and of the Coun­cil (30) lays down modu­les for con­for­mi­ty assess­ment pro­ce­du­res pro­por­tio­na­te to the level of risk and the level of secu­ri­ty requi­red. In order to ensu­re cross-sec­to­ral con­si­sten­cy and to avo­id ad hoc vari­ants, the con­for­mi­ty assess­ment pro­ce­du­res for checking the com­pli­ance of pro­ducts incor­po­ra­ting digi­tal ele­ments with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on should be based on tho­se modu­les. The con­for­mi­ty assess­ment pro­ce­du­res should exami­ne and veri­fy both pro­duct- and pro­cess-rela­ted requi­re­ments cove­ring the who­le life cycle of devices incor­po­ra­ting digi­tal ele­ments, inclu­ding plan­ning, design, deve­lo­p­ment or manu­fac­tu­re, test­ing and main­ten­an­ce of the device incor­po­ra­ting digi­tal elements.
(91) Con­for­mi­ty assess­ment of devices with digi­tal ele­ments that are not listed in this Regu­la­ti­on as essen­ti­al or cri­ti­cal devices with digi­tal ele­ments may be car­ri­ed out by the manu­fac­tu­rer under its own respon­si­bi­li­ty in accordance with the inter­nal con­trol pro­ce­du­re based on Modu­le A of Decis­i­on No 768/2008/EC pur­su­ant to this Regu­la­ti­on. This shall also app­ly in cases whe­re a manu­fac­tu­rer deci­des not to app­ly all or part of an appli­ca­ble har­mo­ni­zed stan­dard, com­mon spe­ci­fi­ca­ti­on or Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­me. The manu­fac­tu­rer remains free to choo­se a more strin­gent con­for­mi­ty assess­ment pro­ce­du­re invol­ving a third par­ty. As part of the con­for­mi­ty assess­ment car­ri­ed out in accordance with the inter­nal con­trol pro­ce­du­re, the manu­fac­tu­rer shall ensu­re and decla­re, on its own respon­si­bi­li­ty, that the device with digi­tal ele­ments and the manufacturer’s pro­ce­s­ses com­ply with the appli­ca­ble essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in this Regu­la­ti­on. Whe­re a cri­ti­cal device with digi­tal ele­ments falls within Class I, an addi­tio­nal assu­rance test is requi­red to demon­stra­te con­for­mi­ty with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on. The manu­fac­tu­rer should use har­mo­ni­zed stan­dards, com­mon spe­ci­fi­ca­ti­ons or Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­mes adopted in accordance with Regu­la­ti­on (EU) 2019/881 and iden­ti­fi­ed by the Com­mis­si­on in an imple­men­ting act if it wis­hes to car­ry out the con­for­mi­ty assess­ment under its own respon­si­bi­li­ty (Modu­le A). If the manu­fac­tu­rer does not use such har­mo­ni­zed stan­dards, com­mon spe­ci­fi­ca­ti­ons or Euro­pean sche­mes for cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on, a con­for­mi­ty assess­ment should be car­ri­ed out with the invol­vement of a third par­ty (based on modu­les B and C or H). Taking into account the admi­ni­stra­ti­ve bur­den for manu­fac­tu­r­ers and the fact that cyber­se­cu­ri­ty plays an important role in the design and deve­lo­p­ment pha­se of tan­gi­ble and intan­gi­ble pro­ducts with digi­tal ele­ments, con­for­mi­ty assess­ment pro­ce­du­res based on Modu­les B and C or Modu­le H of Decis­i­on No 768/2008/EC have been sel­ec­ted as the most appro­pria­te to assess the con­for­mi­ty of cri­ti­cal pro­ducts with digi­tal ele­ments in a pro­por­tio­na­te and effec­ti­ve way. The manu­fac­tu­rer who has the con­for­mi­ty assess­ment car­ri­ed out by a third par­ty can choo­se the pro­ce­du­re that best suits his design and manu­fac­tu­ring pro­cess. Given the even grea­ter cyber­se­cu­ri­ty risk asso­cia­ted with the use of class II cri­ti­cal devices with digi­tal ele­ments, a third par­ty should always be invol­ved in their con­for­mi­ty assess­ment, even if the device ful­ly or par­ti­al­ly com­plies with har­mo­ni­zed stan­dards, com­mon spe­ci­fi­ca­ti­ons or Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­mes. Manu­fac­tu­r­ers of cri­ti­cal devices with digi­tal ele­ments that are con­side­red free and open source soft­ware should be able to app­ly the inter­nal con­trol pro­ce­du­re based on Modu­le A, pro­vi­ded that they make the tech­ni­cal docu­men­ta­ti­on available to the public.
(92) While the manu­fac­tu­re of phy­si­cal pro­ducts with digi­tal ele­ments gene­ral­ly requi­res a con­sidera­ble amount of effort throug­hout the design, deve­lo­p­ment and manu­fac­tu­ring pha­ses, the manu­fac­tu­re of pro­ducts with digi­tal ele­ments in the form of soft­ware focu­ses almost exclu­si­ve­ly on the design and deve­lo­p­ment, whe­re­as the manu­fac­tu­ring pha­se plays a sub­or­di­na­te role. Nevert­hel­ess, soft­ware pro­ducts often still have to be com­pi­led and assem­bled into ver­si­ons, packa­ged, made available for down­load or copied onto phy­si­cal data car­ri­ers befo­re they are pla­ced on the mar­ket. When app­ly­ing the rele­vant con­for­mi­ty assess­ment modu­les to veri­fy the con­for­mi­ty of the pro­duct with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on in the design, deve­lo­p­ment and manu­fac­tu­ring pha­ses, tho­se acti­vi­ties should be con­side­red as equi­va­lent to the manu­fac­tu­ring process.
(93) With regard to micro and small enter­pri­ses, in order to ensu­re pro­por­tio­na­li­ty, it is appro­pria­te to redu­ce admi­ni­stra­ti­ve costs wit­hout com­pro­mi­sing the level of cyber­se­cu­ri­ty of pro­ducts with digi­tal ele­ments fal­ling within the scope of this Regu­la­ti­on or the exi­stence of a level play­ing field bet­ween manu­fac­tu­r­ers. The­r­e­fo­re, the Com­mis­si­on should estab­lish a sim­pli­fi­ed tech­ni­cal docu­men­ta­ti­on form tail­o­red to the needs of micro and small enter­pri­ses. The sim­pli­fi­ed tech­ni­cal docu­men­ta­ti­on form adopted by the Com­mis­si­on should cover all appli­ca­ble ele­ments rela­ted to tech­ni­cal docu­men­ta­ti­on under this Regu­la­ti­on and indi­ca­te how a micro or small enter­pri­se can pro­vi­de the reque­sted ele­ments in a con­cise form, such as the descrip­ti­on of the design, deve­lo­p­ment and manu­fac­tu­ring of the pro­duct with digi­tal ele­ments. In this way, the form would help to redu­ce the admi­ni­stra­ti­ve bur­den of com­pli­ance by pro­vi­ding legal cer­tain­ty to the busi­nesses con­cer­ned as to the scope and details of the infor­ma­ti­on to be pro­vi­ded. Micro and small enter­pri­ses should have the opti­on to pro­vi­de the appli­ca­ble ele­ments rela­ted to the tech­ni­cal docu­men­ta­ti­on in a com­pre­hen­si­ve form and not to use the sim­pli­fi­ed tech­ni­cal form available to them.
(94) In order to pro­mo­te and pro­tect inno­va­ti­on, it is important that the inte­rests of manu­fac­tu­r­ers that are micro, small or medi­um-sized enter­pri­ses, in par­ti­cu­lar micro and small enter­pri­ses, inclu­ding start-ups, be given spe­cial con­side­ra­ti­on. To this end, Mem­ber Sta­tes could deve­lop initia­ti­ves aimed at manu­fac­tu­r­ers that are micro or small enter­pri­ses, inclu­ding in the are­as of trai­ning, awa­re­ness-rai­sing, com­mu­ni­ca­ti­on of infor­ma­ti­on, test­ing, third-par­ty con­for­mi­ty assess­ment and the estab­lish­ment of living labo­ra­to­ries. Trans­la­ti­on costs rela­ted to the man­da­to­ry docu­men­ta­ti­on, such as tech­ni­cal docu­men­ta­ti­on, and the infor­ma­ti­on and ins­truc­tions to users requi­red under this Regu­la­ti­on, as well as com­mu­ni­ca­ti­on with aut­ho­ri­ties, can ent­ail signi­fi­cant expen­dit­u­re for manu­fac­tu­r­ers, in par­ti­cu­lar for small manu­fac­tu­r­ers. Mem­ber Sta­tes should the­r­e­fo­re also be able to veri­fy that one of the lan­guages they deter­mi­ne and accept for the rele­vant docu­men­ta­ti­on of manu­fac­tu­r­ers and for com­mu­ni­ca­ti­on with manu­fac­tu­r­ers is a lan­guage that is wide­ly under­s­tood by the lar­gest pos­si­ble num­ber of users.
(95) In order to ensu­re the smooth appli­ca­ti­on of this Regu­la­ti­on, Mem­ber Sta­tes should ensu­re, as far as pos­si­ble, that the­re are a suf­fi­ci­ent num­ber of noti­fi­ed bodies capa­ble of car­ry­ing out third-par­ty con­for­mi­ty assess­ments befo­re the date of appli­ca­ti­on of this Regu­la­ti­on. The Com­mis­si­on should assist Mem­ber Sta­tes and other rele­vant par­ties in this endea­vor as far as pos­si­ble in order to avo­id bot­t­len­ecks and bar­riers to mar­ket access for manu­fac­tu­r­ers. Tar­ge­ted trai­ning acti­vi­ties led by the Mem­ber Sta­tes, whe­re appro­pria­te with the sup­port of the Com­mis­si­on, can con­tri­bu­te to the avai­la­bi­li­ty of qua­li­fi­ed pro­fes­sio­nals and also sup­port the acti­vi­ties of noti­fi­ed bodies under this Regu­la­ti­on. Fur­ther­mo­re, given the costs that third-par­ty con­for­mi­ty assess­ment can ent­ail, fun­ding initia­ti­ves at Uni­on and natio­nal level aimed at redu­cing tho­se costs for micro and small enter­pri­ses should be considered.
(96) In order to ensu­re pro­por­tio­na­li­ty, con­for­mi­ty assess­ment bodies should take into account the spe­ci­fic inte­rests and needs of micro, small and medi­um-sized enter­pri­ses, inclu­ding start-ups, when set­ting the fees for con­for­mi­ty assess­ment pro­ce­du­res. In par­ti­cu­lar, con­for­mi­ty assess­ment bodies should app­ly the rele­vant veri­fi­ca­ti­on pro­ce­du­res and tests pro­vi­ded for in this Regu­la­ti­on only whe­re appro­pria­te and fol­lo­wing a risk-based approach.
(97) The objec­ti­ves of real-world labo­ra­to­ries should be to foster inno­va­ti­on and com­pe­ti­ti­ve­ness for busi­nesses by crea­ting con­trol­led test envi­ron­ments befo­re pro­ducts with digi­tal ele­ments are pla­ced on the mar­ket. Real-world labo­ra­to­ries should con­tri­bu­te to impro­ving legal cer­tain­ty for all actors fal­ling within the scope of this Regu­la­ti­on and to faci­li­ta­ting and acce­le­ra­ting the access of pro­ducts with digi­tal ele­ments to the Uni­on mar­ket, in par­ti­cu­lar when they are pro­vi­ded by micro and small enter­pri­ses, inclu­ding start-ups.
(98) In order to allow pro­ducts incor­po­ra­ting digi­tal ele­ments to be sub­ject to third-par­ty con­for­mi­ty assess­ment, natio­nal noti­fy­ing aut­ho­ri­ties should noti­fy the Com­mis­si­on and the other Mem­ber Sta­tes of con­for­mi­ty assess­ment bodies pro­vi­ded that they meet a num­ber of requi­re­ments, in par­ti­cu­lar as regards inde­pen­dence, com­pe­tence and absence of con­flicts of interest.
(99) In order to ensu­re a con­si­stent level of qua­li­ty in the per­for­mance of con­for­mi­ty assess­ments of pro­ducts incor­po­ra­ting digi­tal ele­ments, it is also neces­sa­ry to lay down requi­re­ments for noti­fy­ing aut­ho­ri­ties and other bodies invol­ved in the assess­ment, noti­fi­ca­ti­on and moni­to­ring of noti­fi­ed bodies. The system pro­vi­ded for in this Regu­la­ti­on should be com­ple­men­ted by the accre­di­ta­ti­on system pro­vi­ded for in Regu­la­ti­on (EC) No 765/2008. Sin­ce accre­di­ta­ti­on is an important means of veri­fy­ing the com­pe­tence of con­for­mi­ty assess­ment bodies, it should also be used for noti­fi­ca­ti­on purposes.
(100) Con­for­mi­ty assess­ment bodies accre­di­ted and noti­fi­ed under Uni­on law set­ting out requi­re­ments simi­lar to tho­se laid down in this Regu­la­ti­on, such as a con­for­mi­ty assess­ment body noti­fi­ed for a Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­me adopted under Regu­la­ti­on (EU) 2019/881 or under Dele­ga­ted Regu­la­ti­on (EU) 2022/30, should be reas­ses­sed and noti­fi­ed under this Regu­la­ti­on. Howe­ver, the rele­vant aut­ho­ri­ties may defi­ne syn­er­gies in rela­ti­on to over­lap­ping requi­re­ments in order to avo­id unneces­sa­ry finan­cial and admi­ni­stra­ti­ve bur­den and to ensu­re a smooth and time­ly noti­fi­ca­ti­on process.
(101) Trans­pa­rent accre­di­ta­ti­on in accordance with Regu­la­ti­on (EC) No 765/2008, which ensu­res the neces­sa­ry level of con­fi­dence in cer­ti­fi­ca­tes of con­for­mi­ty, should be regard­ed by natio­nal aut­ho­ri­ties throug­hout the Uni­on as the pre­fer­red means of demon­st­ra­ting the tech­ni­cal com­pe­tence of con­for­mi­ty assess­ment bodies. Howe­ver, natio­nal aut­ho­ri­ties may con­sider that they have the appro­pria­te means to car­ry out this assess­ment them­sel­ves. In such cases, in order to ensu­re the cre­di­bi­li­ty of assess­ments car­ri­ed out by other natio­nal aut­ho­ri­ties, they should pro­vi­de the Com­mis­si­on and the other Mem­ber Sta­tes with all neces­sa­ry docu­men­ta­ry evi­dence demon­st­ra­ting that the con­for­mi­ty assess­ment bodies asses­sed com­ply with the rele­vant legal requirements.
(102) Con­for­mi­ty assess­ment bodies often sub­con­tract parts of their work rela­ted to con­for­mi­ty assess­ment or dele­ga­te it to sub­si­dia­ries. In order to main­tain the level of pro­tec­tion requi­red for the pla­cing on the mar­ket of pro­ducts with digi­tal ele­ments in the Uni­on, it is essen­ti­al that sub­con­trac­tors and sub­si­dia­ries meet the same requi­re­ments as noti­fi­ed bodies when car­ry­ing out con­for­mi­ty assess­ment tasks.
(103) The noti­fi­ca­ti­on of a con­for­mi­ty assess­ment body should be sent by the noti­fy­ing aut­ho­ri­ty to the Com­mis­si­on and the other Mem­ber Sta­tes via the NANDO (New Approach Noti­fi­ed and Desi­gna­ted Orga­nizati­ons) Infor­ma­ti­on System. The NANDO Infor­ma­ti­on System is the elec­tro­nic noti­fi­ca­ti­on tool deve­lo­ped and mana­ged by the Com­mis­si­on to main­tain a list of all noti­fi­ed bodies.
(104) Sin­ce noti­fi­ed bodies may offer their ser­vices throug­hout the Uni­on, the other Mem­ber Sta­tes and the Com­mis­si­on should be given the oppor­tu­ni­ty to rai­se objec­tions against a noti­fi­ed body. It is the­r­e­fo­re important to pro­vi­de for a peri­od during which any doubts or con­cerns as to the com­pe­tence of con­for­mi­ty assess­ment bodies can be cla­ri­fi­ed befo­re they start ope­ra­ting as noti­fi­ed bodies.
(105) In the inte­rests of com­pe­ti­ti­ve­ness, it is essen­ti­al that noti­fi­ed bodies app­ly the con­for­mi­ty assess­ment pro­ce­du­res wit­hout crea­ting unneces­sa­ry bur­dens for eco­no­mic ope­ra­tors. For the same rea­son, and in order to ensu­re equal tre­at­ment of eco­no­mic ope­ra­tors, a uni­form tech­ni­cal appli­ca­ti­on of con­for­mi­ty assess­ment pro­ce­du­res should be ensu­red. This can best be achie­ved through appro­pria­te coor­di­na­ti­on and coope­ra­ti­on bet­ween noti­fi­ed bodies.
(106) Mar­ket sur­veil­lan­ce is an essen­ti­al tool to ensu­re the cor­rect and uni­form appli­ca­ti­on of Uni­on law. A legal frame­work should the­r­e­fo­re be estab­lished within which mar­ket sur­veil­lan­ce can be car­ri­ed out in an appro­pria­te man­ner. The rules of Regu­la­ti­on (EU) 2019/1020 on Uni­on mar­ket sur­veil­lan­ce and con­trol of pro­ducts ente­ring the Uni­on mar­ket also app­ly to pro­ducts with digi­tal ele­ments that fall within the scope of this Regulation.
(107) Under Regu­la­ti­on (EU) 2019/1020, a mar­ket sur­veil­lan­ce aut­ho­ri­ty car­ri­es out mar­ket sur­veil­lan­ce on the ter­ri­to­ry of the Mem­ber Sta­te that desi­gna­tes it. This Regu­la­ti­on should not pre­vent Mem­ber Sta­tes from deci­ding which aut­ho­ri­ties are com­pe­tent to car­ry out mar­ket sur­veil­lan­ce tasks. Each Mem­ber Sta­te should desi­gna­te one or more mar­ket sur­veil­lan­ce aut­ho­ri­ties on its ter­ri­to­ry. Mem­ber Sta­tes should be able to deci­de to desi­gna­te an exi­sting or a new aut­ho­ri­ty as mar­ket sur­veil­lan­ce aut­ho­ri­ty, inclu­ding the com­pe­tent aut­ho­ri­ties desi­gna­ted or desi­gna­ted pur­su­ant to Artic­le 8 of Direc­ti­ve (EU) 2022/2555, the natio­nal cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on aut­ho­ri­ties desi­gna­ted pur­su­ant to Artic­le 58 of Regu­la­ti­on (EU) 2019/881 or the mar­ket sur­veil­lan­ce aut­ho­ri­ties desi­gna­ted pur­su­ant to Direc­ti­ve 2014/53/EU. Eco­no­mic ope­ra­tors should coope­ra­te ful­ly with mar­ket sur­veil­lan­ce aut­ho­ri­ties and other com­pe­tent aut­ho­ri­ties. Each Mem­ber Sta­te should inform the Com­mis­si­on and the other Mem­ber Sta­tes about its mar­ket sur­veil­lan­ce aut­ho­ri­ties and their respec­ti­ve are­as of com­pe­tence and ensu­re that they have the neces­sa­ry resour­ces and capa­bi­li­ties to car­ry out the mar­ket sur­veil­lan­ce tasks rela­ted to this Regu­la­ti­on. In accordance with Artic­le 10(2) and (3) of Regu­la­ti­on (EU) 2019/1020, each Mem­ber Sta­te should desi­gna­te a sin­gle liai­son body which should be respon­si­ble, inter alia, for repre­sen­ting the coor­di­na­ted posi­ti­on of mar­ket sur­veil­lan­ce aut­ho­ri­ties and sup­port­ing coope­ra­ti­on bet­ween mar­ket sur­veil­lan­ce aut­ho­ri­ties in dif­fe­rent Mem­ber States.
(108) With a view to the uni­form appli­ca­ti­on of this Regu­la­ti­on, an ADCO on cyber resi­li­ence of pro­ducts with digi­tal ele­ments should be estab­lished in accordance with Artic­le 30(2) of Regu­la­ti­on (EU) 2019/1020. The ADCO should be com­po­sed of repre­sen­ta­ti­ves of the desi­gna­ted mar­ket sur­veil­lan­ce aut­ho­ri­ties and, whe­re appro­pria­te, repre­sen­ta­ti­ves of the sin­gle liai­son offices. The Com­mis­si­on should sup­port and pro­mo­te coope­ra­ti­on bet­ween mar­ket sur­veil­lan­ce aut­ho­ri­ties through the Uni­on net­work on pro­duct com­pli­ance estab­lished under Artic­le 29 of Regu­la­ti­on (EU) 2019/1020, com­po­sed of repre­sen­ta­ti­ves of each Mem­ber Sta­te, inclu­ding a repre­sen­ta­ti­ve of each sin­gle liai­son office refer­red to in Artic­le 10 of that Regu­la­ti­on and an optio­nal natio­nal expert, as well as the chairs of the ADCO and repre­sen­ta­ti­ves of the Com­mis­si­on. The Com­mis­si­on should par­ti­ci­pa­te in the mee­tings of the Uni­on Pro­duct Con­for­mi­ty Net­work, its sub-groups and the ADCO. It should sup­port the ADCO through an exe­cu­ti­ve secre­ta­ri­at pro­vi­ding tech­ni­cal and logi­sti­cal sup­port. The ADCO may also invi­te inde­pen­dent experts to par­ti­ci­pa­te and liai­se with other ADCOs, such as the one estab­lished under Direc­ti­ve 2014/53/EU.
(109) Mar­ket sur­veil­lan­ce aut­ho­ri­ties should coope­ra­te clo­se­ly through the ADCO estab­lished under this Regu­la­ti­on and be able to deve­lop gui­dance docu­ments to faci­li­ta­te mar­ket sur­veil­lan­ce acti­vi­ties at natio­nal level, for exam­p­le by deve­lo­ping best prac­ti­ces and indi­ca­tors to effec­tively veri­fy the com­pli­ance of pro­ducts incor­po­ra­ting digi­tal ele­ments with this Regulation.
(110) In order to enable time­ly, pro­por­tio­na­te and effec­ti­ve action to be taken in rela­ti­on to pro­ducts with digi­tal ele­ments that pose a signi­fi­cant cyber­se­cu­ri­ty risk, a Uni­on safe­guard pro­ce­du­re should be made available to inform inte­re­sted par­ties of plan­ned mea­su­res in rela­ti­on to such pro­ducts. This would allow mar­ket sur­veil­lan­ce aut­ho­ri­ties, in coope­ra­ti­on with the rele­vant eco­no­mic ope­ra­tors, to inter­ve­ne at an ear­lier stage if neces­sa­ry. Whe­re the Mem­ber Sta­tes and the Com­mis­si­on agree that a mea­su­re taken by a Mem­ber Sta­te is justi­fi­ed, the Com­mis­si­on should only be requi­red to take fur­ther action if the non-com­pli­ance is due to short­co­mings in a har­mo­ni­zed standard.
(111) In cer­tain cases, a pro­duct with digi­tal ele­ments that com­plies with this Regu­la­ti­on may nevert­hel­ess pose a signi­fi­cant cyber­se­cu­ri­ty risk or a risk to the health or safe­ty of per­sons, to the ful­fill­ment of obli­ga­ti­ons under Uni­on or natio­nal law pro­tec­ting fun­da­men­tal rights, to the avai­la­bi­li­ty, authen­ti­ci­ty, inte­gri­ty or con­fi­den­tia­li­ty of ser­vices pro­vi­ded through an elec­tro­nic infor­ma­ti­on system by essen­ti­al enti­ties within the mea­ning of Artic­le 3(1) of Direc­ti­ve (EU) 2022/2555, or to other aspects of the pro­tec­tion of public inte­rests. It is the­r­e­fo­re neces­sa­ry to lay down rules to ensu­re the miti­ga­ti­on of such risks. As a con­se­quence, mar­ket sur­veil­lan­ce aut­ho­ri­ties should take mea­su­res requi­ring the eco­no­mic ope­ra­tor, depen­ding on the risk, to ensu­re that the pro­duct no lon­ger pres­ents that risk, to recall it or to with­draw it from the mar­ket. As soon as a mar­ket sur­veil­lan­ce aut­ho­ri­ty rest­ricts or pro­hi­bits the free move­ment of a pro­duct with digi­tal ele­ments in this way, the Mem­ber Sta­te should imme­dia­te­ly inform the Com­mis­si­on and the other Mem­ber Sta­tes, giving rea­sons and justi­fi­ca­ti­on for the decis­i­on. Whe­re a mar­ket sur­veil­lan­ce aut­ho­ri­ty takes such mea­su­res against pro­ducts incor­po­ra­ting digi­tal ele­ments pre­sen­ting a risk, the Com­mis­si­on should imme­dia­te­ly enter into con­sul­ta­ti­ons with the Mem­ber Sta­tes and the rele­vant eco­no­mic operator(s) and eva­lua­te the natio­nal mea­su­re. On the basis of the results of that assess­ment, the Com­mis­si­on should deci­de whe­ther the natio­nal mea­su­re is justi­fi­ed or not. The Com­mis­si­on should address its decis­i­on to all Mem­ber Sta­tes and com­mu­ni­ca­te it wit­hout delay to them and the rele­vant eco­no­mic operator(s). If the mea­su­re is con­side­red justi­fi­ed, the Com­mis­si­on should also be able to con­sider pro­po­sals to revi­se the rele­vant Uni­on law.
(112) for pro­ducts with digi­tal ele­ments that pose a signi­fi­cant cyber­se­cu­ri­ty risk and whe­re the­re is rea­son to belie­ve that they do not com­ply with this Regu­la­ti­on, or for pro­ducts that com­ply with this Regu­la­ti­on but pose other signi­fi­cant risks, such as risks to the health or safe­ty of per­sons, to the ful­fill­ment of obli­ga­ti­ons under Uni­on or natio­nal law for the pro­tec­tion of fun­da­men­tal rights, or to the avai­la­bi­li­ty, authen­ti­ci­ty, inte­gri­ty or con­fi­den­tia­li­ty of ser­vices pro­vi­ded through an elec­tro­nic infor­ma­ti­on system by essen­ti­al enti­ties within the mea­ning of Artic­le 3(1) of Direc­ti­ve (EU) 2022/2555, the Com­mis­si­on should be able to request ENISA to car­ry out an assess­ment. On the basis of that assess­ment, the Com­mis­si­on should be able to adopt, by means of imple­men­ting acts, cor­rec­ti­ve or rest­ric­ti­ve mea­su­res at Uni­on level, inclu­ding orde­ring the with­dra­wal from the mar­ket or recall of the affec­ted pro­ducts with digi­tal ele­ments within a peri­od pro­por­tio­na­te to the natu­re of the risk. Such inter­ven­ti­on by the Com­mis­si­on should only be pos­si­ble in excep­tio­nal cir­cum­stances that justi­fy imme­dia­te inter­ven­ti­on to pre­ser­ve the pro­per func­tio­ning of the inter­nal mar­ket and only whe­re the mar­ket sur­veil­lan­ce aut­ho­ri­ties have not taken effec­ti­ve action to reme­dy the situa­ti­on. Such excep­tio­nal cir­cum­stances may be emer­gen­ci­es whe­re, for exam­p­le, a non-com­pli­ant pro­duct with digi­tal ele­ments is made wide­ly available on the mar­ket by the manu­fac­tu­rer in seve­ral Mem­ber Sta­tes and is also used in key sec­tors of enti­ties fal­ling within the scope of Direc­ti­ve (EU) 2022/2555 and has known vul­nerabi­li­ties that are exploi­ted by mali­cious actors and for which the manu­fac­tu­rer does not pro­vi­de available patches. The Com­mis­si­on should be able to inter­ve­ne in such emer­gen­ci­es only for the dura­ti­on of the excep­tio­nal cir­cum­stances and only for as long as the non-com­pli­ance with this Regu­la­ti­on or the high risks persist.
(113) Whe­re the­re is evi­dence of non-com­pli­ance with this Regu­la­ti­on in seve­ral Mem­ber Sta­tes, mar­ket sur­veil­lan­ce aut­ho­ri­ties should be able to car­ry out joint acti­vi­ties with other aut­ho­ri­ties to veri­fy com­pli­ance and iden­ti­fy cyber­se­cu­ri­ty risks of pro­ducts with digi­tal elements.
(114) Simul­ta­neous coor­di­na­ted con­trols (“sweeps”) are spe­ci­fic enforce­ment actions car­ri­ed out by mar­ket sur­veil­lan­ce aut­ho­ri­ties that can fur­ther impro­ve pro­duct safe­ty. Sweeps should be car­ri­ed out in par­ti­cu­lar when mar­ket deve­lo­p­ments, con­su­mer com­plaints or other indi­ca­ti­ons sug­gest that cer­tain cate­go­ries of pro­ducts with digi­tal ele­ments often pre­sent cyber­se­cu­ri­ty risks. In addi­ti­on, mar­ket sur­veil­lan­ce aut­ho­ri­ties should also take into account cir­cum­stances rela­ted to non-tech­ni­cal risk fac­tors when deter­mi­ning the cate­go­ries of pro­ducts to be swept. To that end, mar­ket sur­veil­lan­ce aut­ho­ri­ties should be able to take into account the results of the coor­di­na­ted risk assess­ments car­ri­ed out in accordance with Artic­le 22 of Direc­ti­ve (EU) 2022/2555 in rela­ti­on to the secu­ri­ty of cri­ti­cal sup­p­ly chains at Uni­on level, inclu­ding cir­cum­stances rela­ted to non-tech­ni­cal risk fac­tors. ENISA should sub­mit pro­po­sals to mar­ket sur­veil­lan­ce aut­ho­ri­ties for cate­go­ries of pro­ducts with digi­tal ele­ments for which sweeps could be orga­ni­zed, inclu­ding on the basis of vul­nerabi­li­ty and secu­ri­ty inci­dent noti­fi­ca­ti­ons recei­ved by ENISA.
(115) Given its exper­ti­se and man­da­te, ENISA should be able to sup­port the pro­cess of imple­men­ta­ti­on of this Regu­la­ti­on. In par­ti­cu­lar, ENISA should be able to pro­po­se joint acti­vi­ties to be car­ri­ed out by mar­ket sur­veil­lan­ce aut­ho­ri­ties on the basis of indi­ca­ti­ons or infor­ma­ti­on on pos­si­ble non-com­pli­ance of pro­ducts with digi­tal ele­ments with this Regu­la­ti­on in seve­ral Mem­ber Sta­tes or to iden­ti­fy cate­go­ries of pro­ducts for which sweeps should be orga­ni­zed. In excep­tio­nal cir­cum­stances, ENISA should be able, at the request of the Com­mis­si­on, to car­ry out assess­ments in rela­ti­on to spe­ci­fic pro­ducts with digi­tal ele­ments that pose a signi­fi­cant cyber­se­cu­ri­ty risk, whe­re imme­dia­te inter­ven­ti­on is neces­sa­ry to pre­ser­ve the smooth func­tio­ning of the inter­nal market.
(116) This Regu­la­ti­on ent­rusts ENISA with cer­tain tasks that requi­re ade­qua­te resour­ces, both in terms of exper­ti­se and human resour­ces, in order to enable ENISA to car­ry out tho­se tasks effec­tively. When pre­pa­ring the draft gene­ral bud­get of the Uni­on, the Com­mis­si­on will pro­po­se the neces­sa­ry bud­ge­ta­ry resour­ces for ENISA’s estab­lish­ment plan in accordance with the pro­ce­du­re laid down in Artic­le 29 of Regu­la­ti­on (EU) 2019/881. During that pro­cess, the Com­mis­si­on shall take into account the over­all resour­ces of ENISA to enable it to car­ry out its tasks, inclu­ding tho­se con­fer­red on it under this Regulation.
(117) In order to adapt the regu­la­to­ry frame­work whe­re neces­sa­ry, the power to adopt acts in accordance with Artic­le 290 of the Trea­ty on the Func­tio­ning of the Euro­pean Uni­on (TFEU) should be dele­ga­ted to the Com­mis­si­on in respect of updating the list of essen­ti­al pro­ducts with digi­tal ele­ments and their inclu­si­on in the Annex to this Regu­la­ti­on. The power to adopt acts in accordance with that Artic­le should be dele­ga­ted to the Com­mis­si­on in respect of iden­ti­fy­ing pro­ducts with digi­tal ele­ments cover­ed by other Uni­on legis­la­ti­on pro­vi­ding for the same level of pro­tec­tion as this Regu­la­ti­on, deter­mi­ning whe­ther a rest­ric­tion or exclu­si­on from the scope of this Regu­la­ti­on would be neces­sa­ry and, whe­re appro­pria­te, defi­ning the scope of that rest­ric­tion. The power to adopt acts in accordance with that Artic­le should also be dele­ga­ted to the Com­mis­si­on in respect of requi­ring, whe­re appro­pria­te, the cer­ti­fi­ca­ti­on of cri­ti­cal pro­ducts with digi­tal ele­ments set out in an Annex to this Regu­la­ti­on under a Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­me, to update the list of cri­ti­cal pro­ducts with digi­tal ele­ments on the basis of the cri­ti­cal­i­ty cri­te­ria set out in this Regu­la­ti­on and to spe­ci­fy the Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­mes adopted pur­su­ant to Regu­la­ti­on (EU) 2019/881 that may be used to demon­stra­te com­pli­ance with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments or parts the­reof set out in an Annex to this Regu­la­ti­on. The power to adopt acts should also be dele­ga­ted to the Com­mis­si­on in respect of deter­mi­ning the mini­mum peri­od of sup­port for cer­tain cate­go­ries of pro­ducts whe­re mar­ket sur­veil­lan­ce data indi­ca­te insuf­fi­ci­ent sup­port peri­ods and in respect of deter­mi­ning the terms and con­di­ti­ons for the appli­ca­ti­on of the grounds rela­ting to cyber­se­cu­ri­ty risk whe­re the­re is a delay in the dis­clo­sure of reports of actively exploi­ted vul­nerabi­li­ties. In addi­ti­on, the power to adopt acts should be dele­ga­ted to the Com­mis­si­on in respect of estab­li­shing vol­un­t­a­ry secu­ri­ty atte­sta­ti­on sche­mes to assess the com­pli­ance of pro­ducts con­tai­ning digi­tal items that qua­li­fy as free and open source soft­ware with all or cer­tain essen­ti­al cyber­se­cu­ri­ty requi­re­ments or other obli­ga­ti­ons set out in this Regu­la­ti­on, as well as to pre­scri­be the mini­mum infor­ma­ti­on to be inclu­ded in the EU decla­ra­ti­on of con­for­mi­ty and to sup­ple­ment the ele­ments to be inclu­ded in the tech­ni­cal docu­men­ta­ti­on. It is of par­ti­cu­lar importance that the Com­mis­si­on car­ry out appro­pria­te con­sul­ta­ti­ons during its pre­pa­ra­to­ry work, inclu­ding at expert level, in accordance with the prin­ci­ples laid down in the Inter­in­sti­tu­tio­nal Agree­ment of 13 April 2016 on Bet­ter Law-Making (31). In par­ti­cu­lar, to ensu­re equal par­ti­ci­pa­ti­on in the pre­pa­ra­ti­on of dele­ga­ted acts, the Euro­pean Par­lia­ment and the Coun­cil recei­ve all docu­ments at the same time as Mem­ber Sta­tes’ experts, and their experts syste­ma­ti­cal­ly have access to mee­tings of Com­mis­si­on expert groups deal­ing with the pre­pa­ra­ti­on of dele­ga­ted acts. The power to adopt dele­ga­ted acts in accordance with this Regu­la­ti­on is con­fer­red on the Com­mis­si­on for a peri­od of five years from 10 Decem­ber 2024. The Com­mis­si­on should draw up a report in respect of the dele­ga­ti­on of power not later than nine months befo­re the end of the five-year peri­od. The dele­ga­ti­on of power should be taci­t­ly exten­ded for peri­ods of an iden­ti­cal dura­ti­on, unless the Euro­pean Par­lia­ment or the Coun­cil oppo­ses such exten­si­on not later than three months befo­re the end of each period.
(118) In order to ensu­re uni­form con­di­ti­ons for the imple­men­ta­ti­on of this Regu­la­ti­on, imple­men­ting powers should be con­fer­red on the Com­mis­si­on in respect of the fol­lo­wing: spe­ci­fy­ing the tech­ni­cal descrip­ti­on of the cate­go­ries of cri­ti­cal pro­ducts with digi­tal ele­ments listed in an Annex to this Regu­la­ti­on, spe­ci­fy­ing the for­mat and ele­ments of the soft­ware BOM, spe­ci­fy­ing the for­mat and pro­ce­du­re of noti­fi­ca­ti­ons of actively exploi­ted vul­nerabi­li­ties and serious secu­ri­ty inci­dents affec­ting the secu­ri­ty of pro­ducts with digi­tal ele­ments as sub­mit­ted by manu­fac­tu­r­ers, spe­ci­fy­ing com­mon spe­ci­fi­ca­ti­ons for tech­ni­cal requi­re­ments to meet the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in an Annex to this Regu­la­ti­on, spe­ci­fy­ing tech­ni­cal spe­ci­fi­ca­ti­ons for labels, pic­to­grams or other mar­kings rela­ting to the secu­ri­ty of pro­ducts with digi­tal ele­ments and their sup­port peri­od and mecha­nisms to pro­mo­te their use and to rai­se public awa­re­ness of the secu­ri­ty of pro­ducts with digi­tal ele­ments, estab­li­shing the sim­pli­fi­ed form for docu­men­ta­ti­on tail­o­red to the needs of micro and small enter­pri­ses, and deci­ding on cor­rec­ti­ve or rest­ric­ti­ve mea­su­res at Uni­on level in excep­tio­nal cir­cum­stances that justi­fy imme­dia­te inter­ven­ti­on in order to pre­ser­ve the smooth func­tio­ning of the inter­nal mar­ket. Tho­se powers should be exer­cis­ed in accordance with Regu­la­ti­on (EU) No 182/2011 of the Euro­pean Par­lia­ment and of the Coun­cil (32).
(119) In order to ensu­re trustful and cons­truc­ti­ve coope­ra­ti­on bet­ween mar­ket sur­veil­lan­ce aut­ho­ri­ties at Uni­on and Mem­ber Sta­te level, all par­ties invol­ved in the appli­ca­ti­on of this Regu­la­ti­on should respect the con­fi­den­tia­li­ty of infor­ma­ti­on and data obtai­ned in the cour­se of car­ry­ing out their activities.
(120) In order to ensu­re the effec­ti­ve enforce­ment of the obli­ga­ti­ons laid down in this Regu­la­ti­on, each mar­ket sur­veil­lan­ce aut­ho­ri­ty should have the power to impo­se or request the impo­si­ti­on of fines. It is the­r­e­fo­re also appro­pria­te to set upper limits for fines to be pro­vi­ded for in natio­nal law for inf­rin­ge­ments of the obli­ga­ti­ons laid down in this Regu­la­ti­on. When deci­ding on the amount of the fine, account should be taken in each indi­vi­du­al case of all rele­vant cir­cum­stances of the spe­ci­fic situa­ti­on and at least of the cir­cum­stances expli­ci­t­ly set out in this Regu­la­ti­on, inclu­ding whe­ther the manu­fac­tu­rer is a microen­ter­pri­se or a small or medi­um-sized enter­pri­se, inclu­ding a start-up, and whe­ther the same mar­ket sur­veil­lan­ce aut­ho­ri­ty or other mar­ket sur­veil­lan­ce aut­ho­ri­ties have alre­a­dy impo­sed fines on the same eco­no­mic ope­ra­tor for a simi­lar inf­rin­ge­ment. Such cir­cum­stances could eit­her be aggravating, if the inf­rin­ge­ment by the same eco­no­mic ope­ra­tor con­ti­nues on the ter­ri­to­ry of a Mem­ber Sta­te other than the one whe­re a fine has alre­a­dy been impo­sed, or miti­ga­ting, by ensu­ring that sanc­tions impo­sed in other Mem­ber Sta­tes and their amount, as well as other rele­vant con­cre­te cir­cum­stances, are taken into account when ano­ther mar­ket sur­veil­lan­ce aut­ho­ri­ty is con­side­ring a fur­ther fine for the same eco­no­mic ope­ra­tor or the same type of inf­rin­ge­ment. In any event, the total amount of fines that mar­ket sur­veil­lan­ce aut­ho­ri­ties of seve­ral Mem­ber Sta­tes could impo­se on the same eco­no­mic ope­ra­tor for the same type of inf­rin­ge­ments should com­ply with the prin­ci­ple of pro­por­tio­na­li­ty. Sin­ce fines are not impo­sed on microen­ter­pri­ses or small enter­pri­ses for non-com­pli­ance with the 24-hour ear­ly noti­fi­ca­ti­on peri­od for actively exploi­ted vul­nerabi­li­ties or serious secu­ri­ty inci­dents affec­ting the secu­ri­ty of the pro­duct with digi­tal ele­ments, nor on admi­ni­stra­tors of open source soft­ware for inf­rin­ge­ments of this Regu­la­ti­on, and sub­ject to the prin­ci­ple that pen­al­ties should be effec­ti­ve, pro­por­tio­na­te and dissua­si­ve, Mem­ber Sta­tes should not impo­se any other finan­cial pen­al­ties on tho­se entities.
(121) Whe­re fines are impo­sed on a per­son other than an under­ta­king, the com­pe­tent aut­ho­ri­ty should take into account the gene­ral level of inco­me in the Mem­ber Sta­te con­cer­ned and the eco­no­mic situa­ti­on of the per­sons when set­ting the fine. Mem­ber Sta­tes should be able to deter­mi­ne whe­ther and to what ext­ent fines can be impo­sed on public authorities.
(122) Mem­ber Sta­tes should con­sider, taking into account natio­nal cir­cum­stances, whe­ther the reve­nues from the pen­al­ties pro­vi­ded for in this Regu­la­ti­on or equi­va­lent reve­nues can be used to sup­port cyber­se­cu­ri­ty poli­ci­es and impro­ve the level of cyber­se­cu­ri­ty in the Uni­on, inclu­ding by incre­a­sing the num­ber of qua­li­fi­ed cyber­se­cu­ri­ty pro­fes­sio­nals, streng­thening capa­ci­ty buil­ding for micro, small and medi­um-sized enter­pri­ses and rai­sing public awa­re­ness of cyber threats.
(123) In its rela­ti­ons with third count­ries, the Uni­on aims to pro­mo­te inter­na­tio­nal trade in regu­la­ted pro­ducts. A ran­ge of mea­su­res can be used to faci­li­ta­te trade, inclu­ding various legal instru­ments such as bila­te­ral (inter­go­vern­men­tal) Mutu­al Reco­gni­ti­on Agree­ments (MRAs) on con­for­mi­ty assess­ment and labe­l­ing of regu­la­ted pro­ducts. Mutu­al Reco­gni­ti­on Agree­ments are con­clu­ded bet­ween the Uni­on and third count­ries that are at a com­pa­ra­ble level of tech­ni­cal deve­lo­p­ment and who­se approach to con­for­mi­ty assess­ment is con­side­red com­pa­ti­ble. The­se agree­ments are based on the mutu­al reco­gni­ti­on of cer­ti­fi­ca­tes, marks of con­for­mi­ty and test reports issued by the con­for­mi­ty assess­ment bodies of the Par­ties in accordance with each other’s legis­la­ti­on. Such mutu­al reco­gni­ti­on agree­ments curr­ent­ly exist with seve­ral third count­ries. The­se agree­ments are con­clu­ded for a num­ber of spe­ci­fic sec­tors, which may dif­fer from one third coun­try to ano­ther. In order to fur­ther faci­li­ta­te trade and reco­gnizing that the sup­p­ly chains for pro­ducts with digi­tal ele­ments are glo­bal, the Uni­on may con­clude mutu­al reco­gni­ti­on agree­ments on con­for­mi­ty assess­ment for pro­ducts cover­ed by this Regu­la­ti­on in accordance with Artic­le 218 TFEU. It is also important to coope­ra­te with part­ner count­ries to streng­then glo­bal resi­li­ence against cyber-attacks, as this will con­tri­bu­te to a stron­ger cyber­se­cu­ri­ty frame­work both insi­de and out­side the Uni­on in the long term.
(124) Con­su­mers should be able to enforce their rights in rela­ti­on to the obli­ga­ti­ons appli­ca­ble to eco­no­mic ope­ra­tors under this Regu­la­ti­on by means of repre­sen­ta­ti­ve actions in accordance with Direc­ti­ve (EU) 2020/1828 of the Euro­pean Par­lia­ment and of the Coun­cil (33). To that end, this Regu­la­ti­on should pro­vi­de that Direc­ti­ve (EU) 2020/1828 applies to repre­sen­ta­ti­ve actions for inf­rin­ge­ments of this Regu­la­ti­on that harm or are likely to harm the coll­ec­ti­ve inte­rests of con­su­mers. Con­se­quent­ly, Annex I to that Direc­ti­ve should be amen­ded accor­din­gly. It is for Mem­ber Sta­tes to ensu­re that tho­se amend­ments are reflec­ted in the trans­po­si­ti­on mea­su­res they adopt pur­su­ant to that Direc­ti­ve, alt­hough the adop­ti­on of natio­nal trans­po­si­ti­on mea­su­res in this respect is not a pre­con­di­ti­on for the appli­ca­ti­on of that Direc­ti­ve to such repre­sen­ta­ti­ve actions. That Direc­ti­ve should app­ly from 11 Decem­ber 2027 to repre­sen­ta­ti­ve actions brought for inf­rin­ge­ments by eco­no­mic ope­ra­tors of pro­vi­si­ons of this Regu­la­ti­on that harm or are likely to harm the coll­ec­ti­ve inte­rests of consumers.
(125) The Com­mis­si­on should regu­lar­ly assess and review this Regu­la­ti­on in con­sul­ta­ti­on with rele­vant stake­hol­ders, in par­ti­cu­lar to deter­mi­ne whe­ther it needs to be adapt­ed to chan­ging social, poli­ti­cal, tech­ni­cal or mar­ket con­di­ti­ons. This Regu­la­ti­on faci­li­ta­tes com­pli­ance with sup­p­ly chain secu­ri­ty obli­ga­ti­ons by enti­ties fal­ling within the scope of Regu­la­ti­on (EU) 2022/2554 and Direc­ti­ve (EU) 2022/2555 that use pro­ducts with digi­tal ele­ments. The Com­mis­si­on should assess the com­bi­ned impact of the Uni­on cyber­se­cu­ri­ty frame­work as part of that peri­odic review.
(126) Eco­no­mic ope­ra­tors should be given suf­fi­ci­ent time to adapt to the requi­re­ments laid down in this Regu­la­ti­on. This Regu­la­ti­on should app­ly from 11 Decem­ber 2027, with the excep­ti­on of the noti­fi­ca­ti­on requi­re­ments for actively exploi­ted vul­nerabi­li­ties and serious secu­ri­ty inci­dents affec­ting the secu­ri­ty of pro­ducts with digi­tal ele­ments, which should app­ly from 11 Sep­tem­ber 2026, and the pro­vi­si­ons on the noti­fi­ca­ti­on of con­for­mi­ty assess­ment bodies, which should app­ly from 11 June 2026.
(127) It is important to sup­port micro, small and medi­um-sized enter­pri­ses, inclu­ding start-ups, in the imple­men­ta­ti­on of this Regu­la­ti­on and to mini­mi­ze the risks to imple­men­ta­ti­on ari­sing from a lack of know­ledge and exper­ti­se in the mar­ket and to faci­li­ta­te manu­fac­tu­r­ers’ com­pli­ance with their obli­ga­ti­ons under this Regu­la­ti­on. The Digi­tal Euro­pe Pro­gram and other rele­vant Uni­on pro­grams pro­vi­de finan­cial and tech­ni­cal sup­port to enable tho­se com­pa­nies to con­tri­bu­te to the growth of the Uni­on eco­no­my and to the streng­thening of the com­mon level of cyber­se­cu­ri­ty in the Uni­on. The Euro­pean Cyber­se­cu­ri­ty Rese­arch Com­pe­tence Cen­ter and the Natio­nal Coor­di­na­ti­on Cen­ters as well as the Euro­pean Digi­tal Inno­va­ti­on Hubs estab­lished by the Com­mis­si­on and the Mem­ber Sta­tes at Uni­on or natio­nal level could also sup­port busi­nesses and public sec­tor enti­ties and con­tri­bu­te to the imple­men­ta­ti­on of this Regu­la­ti­on. Within their respec­ti­ve roles and respon­si­bi­li­ties, they could pro­vi­de tech­ni­cal and sci­en­ti­fic sup­port to micro, small and medi­um-sized enter­pri­ses, for exam­p­le in test­ing acti­vi­ties and third-par­ty con­for­mi­ty assess­ments. They could also pro­mo­te the use of tools to faci­li­ta­te the imple­men­ta­ti­on of this Regulation.
(128) Mem­ber Sta­tes should also con­sider taking com­ple­men­ta­ry mea­su­res aimed at pro­vi­ding gui­dance and sup­port to micro, small and medi­um-sized enter­pri­ses, inclu­ding through the estab­lish­ment of living labs and tar­ge­ted com­mu­ni­ca­ti­on chan­nels. In order to streng­then the level of cyber­se­cu­ri­ty in the Uni­on, Mem­ber Sta­tes may also con­sider sup­port­ing the deve­lo­p­ment of capa­ci­ties and com­pe­ten­ces rela­ted to the cyber­se­cu­ri­ty of pro­ducts with digi­tal ele­ments, impro­ving the resi­li­ence of eco­no­mic ope­ra­tors against cyber-attacks, in par­ti­cu­lar when it comes to micro, small and medi­um-sized enter­pri­ses, and rai­sing public awa­re­ness on the cyber­se­cu­ri­ty of pro­ducts with digi­tal elements.
(129) Sin­ce the objec­ti­ve of this Regu­la­ti­on can­not be suf­fi­ci­ent­ly achie­ved by the Mem­ber Sta­tes but can rather, by rea­son of the effects of the action, be bet­ter achie­ved at Uni­on level, the Uni­on may adopt mea­su­res, in accordance with the prin­ci­ple of sub­si­dia­ri­ty as set out in Artic­le 5 of the Trea­ty on Euro­pean Uni­on. In accordance with the prin­ci­ple of pro­por­tio­na­li­ty, as set out in that Artic­le, this Regu­la­ti­on does not go bey­ond what is neces­sa­ry in order to achie­ve that objective.
(130) The Euro­pean Data Pro­tec­tion Super­vi­sor was con­sul­ted in accordance with Artic­le 42(1) of Regu­la­ti­on (EU) 2018/1725 of the Euro­pean Par­lia­ment and of the Coun­cil (34) and deli­ver­ed an opi­ni­on on Novem­ber 9, 2022 (35).

Chap­ter I Gene­ral provisions 

Artic­le 1 Object
This Regu­la­ti­on lays down the fol­lo­wing:
a) Regu­la­ti­ons for the pro­vi­si­on on the mar­ket of pro­ducts with digi­tal ele­ments to ensu­re the cyber­se­cu­ri­ty of such products;
b) basic cyber­se­cu­ri­ty requi­re­ments for the design, deve­lo­p­ment and manu­fac­tu­re of pro­ducts with digi­tal ele­ments and the obli­ga­ti­ons of eco­no­mic ope­ra­tors in rela­ti­on to the­se pro­ducts with regard to cybersecurity;
c) basic cyber­se­cu­ri­ty requi­re­ments for the vul­nerabi­li­ty hand­ling pro­ce­du­res estab­lished by manu­fac­tu­r­ers to ensu­re the cyber­se­cu­ri­ty of pro­ducts with digi­tal ele­ments during the expec­ted life­time of the pro­ducts, and obli­ga­ti­ons of eco­no­mic ope­ra­tors in rela­ti­on to tho­se procedures;
d) rules for mar­ket sur­veil­lan­ce, inclu­ding moni­to­ring, and enforce­ment of the rules and requi­re­ments refer­red to in this Article.
Artic­le 2 Scope of application
(1) This Regu­la­ti­on applies to pro­ducts made available on the mar­ket with digi­tal ele­ments who­se inten­ded pur­po­se or rea­son­ab­ly fore­seeable use invol­ves a direct or indi­rect logi­cal or phy­si­cal data con­nec­tion to a device or network.
(2) This Regu­la­ti­on shall not app­ly to pro­ducts with digi­tal ele­ments to which the fol­lo­wing Uni­on acts apply:
a) Regu­la­ti­on (EU) 2017/745,
b) Regu­la­ti­on (EU) 2017/746,
c) Regu­la­ti­on (EU) 2019/2144.
(3) This Regu­la­ti­on shall not app­ly to pro­ducts with digi­tal ele­ments that have been cer­ti­fi­ed in accordance with Regu­la­ti­on (EU) 2018/1139.
(4) This Regu­la­ti­on shall not app­ly to devices fal­ling within the scope of Direc­ti­ve 2014/90/EU of the Euro­pean Par­lia­ment and of the Coun­cil (36).
(5) The appli­ca­ti­on of this Regu­la­ti­on to devices with digi­tal ele­ments cover­ed by other Uni­on legis­la­ti­on with requi­re­ments for all or some of the risks cover­ed by the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I may be limi­t­ed or exclu­ded where
a) such rest­ric­tion or exclu­si­on is com­pa­ti­ble with the gene­ral legal frame­work appli­ca­ble to the­se pro­ducts, and
b) the sec­tor-spe­ci­fic rules achie­ve the same level of pro­tec­tion as gua­ran­teed by this Regu­la­ti­on or a hig­her level.
The Com­mis­si­on shall be empowered to adopt dele­ga­ted acts in accordance with Artic­le 61 to sup­ple­ment this Regu­la­ti­on by deter­mi­ning the need for such rest­ric­tion or exclu­si­on and, whe­re appro­pria­te, by spe­ci­fy­ing the pro­ducts and rules con­cer­ned and the scope of the rest­ric­tion.
(6) This Regu­la­ti­on shall not app­ly to spa­re parts which are made available on the mar­ket to replace iden­ti­cal com­pon­ents in pro­ducts with digi­tal ele­ments and which are manu­fac­tu­red to the same spe­ci­fi­ca­ti­ons as the com­pon­ents they are inten­ded to replace.
(7) This Regu­la­ti­on shall not app­ly to pro­ducts with digi­tal ele­ments desi­gned or modi­fi­ed exclu­si­ve­ly for natio­nal secu­ri­ty or defen­se pur­po­ses, or to pro­ducts spe­ci­fi­cal­ly desi­gned for the pro­ce­s­sing of clas­si­fi­ed information.
(8) The obli­ga­ti­ons laid down in this Regu­la­ti­on shall not include the pro­vi­si­on of infor­ma­ti­on the dis­clo­sure of which would be con­tra­ry to the essen­ti­al inte­rests of Mem­ber Sta­tes in the area of natio­nal secu­ri­ty, public secu­ri­ty or defense.
Artic­le 3 Definitions
For the pur­po­ses of this Regu­la­ti­on, the fol­lo­wing defi­ni­ti­ons shall app­ly
1.‘pro­duct with digi­tal ele­ments’ means a soft­ware or hard­ware pro­duct and its remo­te com­pu­ting solu­ti­ons, inclu­ding soft­ware or hard­ware com­pon­ents, which are pla­ced on the mar­ket separately;
2.“Remo­te data pro­ce­s­sing” means remo­te data pro­ce­s­sing for which soft­ware is desi­gned and deve­lo­ped by the manu­fac­tu­rer its­elf or under its respon­si­bi­li­ty and wit­hout which the pro­duct with digi­tal ele­ments could not ful­fill one of its functions;
3.‘cyber­se­cu­ri­ty’ means cyber­se­cu­ri­ty as defi­ned in Artic­le 2(1) of Regu­la­ti­on (EU) 2019/881
4.“Soft­ware” means the part of an elec­tro­nic infor­ma­ti­on system that con­sists of com­pu­ter code;
5.‘hard­ware’ means a phy­si­cal elec­tro­nic infor­ma­ti­on system capa­ble of pro­ce­s­sing, sto­ring or trans­mit­ting digi­tal data, or parts of such a system;
6.“Com­po­nent” means soft­ware or hard­ware inten­ded for inte­gra­ti­on into an elec­tro­nic infor­ma­ti­on system;
7.‘elec­tro­nic infor­ma­ti­on system’ means a system, inclu­ding elec­tri­cal or elec­tro­nic equip­ment, capa­ble of pro­ce­s­sing, sto­ring or trans­mit­ting digi­tal data
8.“logi­cal con­nec­tion” means a vir­tu­al repre­sen­ta­ti­on of a data con­nec­tion that is estab­lished via a soft­ware interface;
9.‘phy­si­cal con­nec­tion’ means a con­nec­tion bet­ween elec­tro­nic infor­ma­ti­on systems or com­pon­ents estab­lished by phy­si­cal means such as elec­tri­cal, opti­cal or mecha­ni­cal inter­faces, wires or radio waves;
10.“indi­rect con­nec­tion” means a con­nec­tion to a device or net­work that is not made direct­ly, but as part of a lar­ger system that can in turn be con­nec­ted direct­ly to that device or network;
11.“End­point” means a device that is con­nec­ted to a net­work and ser­ves as an access point to this network;
12.‘eco­no­mic ope­ra­tor’ means the manu­fac­tu­rer, the aut­ho­ri­zed repre­sen­ta­ti­ve, the importer, the dis­tri­bu­tor or any other natu­ral or legal per­son who is sub­ject to obli­ga­ti­ons in rela­ti­on to the manu­fac­tu­re of pro­ducts incor­po­ra­ting digi­tal ele­ments or the making available on the mar­ket of pro­ducts incor­po­ra­ting digi­tal ele­ments in accordance with this Regulation;
13.“Manu­fac­tu­rer” means a natu­ral or legal per­son who deve­lo­ps or manu­fac­tures pro­ducts with digi­tal ele­ments or who has pro­ducts with digi­tal ele­ments desi­gned, deve­lo­ped or manu­fac­tu­red and mar­kets them under their name or brand, whe­ther for payment, mone­tizati­on or free of charge;
14.‘open source soft­ware mana­ger’ means a legal enti­ty, other than a manu­fac­tu­rer, which has the pur­po­se or objec­ti­ve of syste­ma­ti­cal­ly and sus­tain­ab­ly sup­port­ing the deve­lo­p­ment of spe­ci­fic pro­ducts with digi­tal ele­ments that are con­side­red free and open source soft­ware and are inten­ded for com­mer­cial acti­vi­ties, and which ensu­res the usa­bi­li­ty of the­se products;
15.‘aut­ho­ri­zed repre­sen­ta­ti­ve’ means a natu­ral or legal per­son resi­dent or estab­lished in the Uni­on who has recei­ved a writ­ten man­da­te from a manu­fac­tu­rer to act on his behalf in rela­ti­on to spe­ci­fic tasks
16.‘importer’ means a natu­ral or legal per­son resi­dent or estab­lished in the Uni­on who places a pro­duct incor­po­ra­ting digi­tal ele­ments on the mar­ket in the Uni­on under the name or trade­mark of a natu­ral or legal per­son resi­dent or estab­lished out­side the Union;
17.‘dis­tri­bu­tor’ means a natu­ral or legal per­son in the sup­p­ly chain, other than the manu­fac­tu­rer or the importer, who makes a pro­duct with digi­tal ele­ments available on the Uni­on mar­ket wit­hout modi­fy­ing its characteristics;
18.“Con­su­mer” means a natu­ral per­son who is acting for pur­po­ses which are out­side his trade, busi­ness, craft or profession;
19.“microen­ter­pri­ses”, “small enter­pri­ses” and “medi­um-sized enter­pri­ses” microen­ter­pri­ses, small enter­pri­ses and medi­um-sized enter­pri­ses respec­tively as defi­ned in the Annex to Recom­men­da­ti­on 2003/361/EC;
20.’sup­port peri­od’ means the peri­od during which the manu­fac­tu­rer shall ensu­re that the vul­nerabi­li­ties of the pro­duct with digi­tal ele­ments are effec­tively addres­sed in accordance with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part II of Annex I;
21.“Pla­cing on the mar­ket” means the first making available of a pro­duct with digi­tal ele­ments on the Uni­on market;
22.‘making available on the mar­ket’ means the sup­p­ly of a pro­duct with digi­tal ele­ments for dis­tri­bu­ti­on or use on the Uni­on mar­ket in the cour­se of a com­mer­cial acti­vi­ty, whe­ther in return for payment or free of charge;
23.“Inten­ded use” means the use for which a pro­duct with digi­tal ele­ments is inten­ded accor­ding to the manu­fac­tu­rer, inclu­ding the spe­ci­fic cir­cum­stances of use and con­di­ti­ons of use as spe­ci­fi­ed by the manu­fac­tu­rer in the ins­truc­tions for use, in adver­ti­sing or sales mate­ri­al and in decla­ra­ti­ons as well as in the tech­ni­cal documentation;
24.“rea­son­ab­ly fore­seeable use” means a use which does not neces­s­a­ri­ly cor­re­spond to the inten­ded pur­po­se sta­ted by the manu­fac­tu­rer in the ins­truc­tions for use, in adver­ti­sing or sales mate­ri­al and in decla­ra­ti­ons and tech­ni­cal docu­men­ta­ti­on, but which is likely to result from rea­son­ab­ly fore­seeable human beha­vi­or or from tech­ni­cal pro­ce­s­ses or interactions;
25.“rea­son­ab­ly fore­seeable misu­se” means the use of a pro­duct with digi­tal ele­ments in a man­ner incon­si­stent with its inten­ded pur­po­se, but which may result from rea­son­ab­ly fore­seeable human beha­vi­or or rea­son­ab­ly fore­seeable inter­ac­tion with other systems;
26.’noti­fy­ing aut­ho­ri­ty’ means the natio­nal aut­ho­ri­ty respon­si­ble for set­ting up, car­ry­ing out and moni­to­ring the neces­sa­ry pro­ce­du­res for the assess­ment, desi­gna­ti­on and noti­fi­ca­ti­on of con­for­mi­ty assess­ment bodies;
27.‘con­for­mi­ty assess­ment’ means the pro­cess of veri­fy­ing com­pli­ance with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I
28.‘con­for­mi­ty assess­ment body’ means a con­for­mi­ty assess­ment body as defi­ned in point 13 of Artic­le 2 of Regu­la­ti­on (EC) No 765/2008.
29.’noti­fi­ed body’ means a con­for­mi­ty assess­ment body desi­gna­ted in accordance with Artic­le 43 of this Regu­la­ti­on and other rele­vant Uni­on har­mo­nizati­on legislation;
30.’sub­stan­ti­al chan­ge’ means a chan­ge to the pro­duct with digi­tal ele­ments after it has been pla­ced on the mar­ket that affects the con­for­mi­ty of the pro­duct with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part I of Annex I or leads to a chan­ge in the inten­ded pur­po­se for which the pro­duct has been tested;
31.‘CE mar­king’ means a mar­king by which a manu­fac­tu­rer decla­res that a device incor­po­ra­ting digi­tal ele­ments and the pro­ce­du­res spe­ci­fi­ed by the manu­fac­tu­rer meet the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I and other appli­ca­ble Uni­on har­mo­nizati­on legis­la­ti­on pro­vi­ding for its affixing;
32.‘Uni­on har­mo­nizati­on legis­la­ti­on’ means the Uni­on legis­la­ti­on listed in Annex I to Regu­la­ti­on (EU) 2019/1020 and any other Uni­on legis­la­ti­on har­mo­ni­zing the con­di­ti­ons for the mar­ke­ting of pro­ducts to which that Regu­la­ti­on applies;
33.‘mar­ket sur­veil­lan­ce aut­ho­ri­ty’ means a mar­ket sur­veil­lan­ce aut­ho­ri­ty as defi­ned in Artic­le 3(4) of Regu­la­ti­on (EU) 2019/1020
34.‘inter­na­tio­nal stan­dard’ means an inter­na­tio­nal stan­dard as defi­ned in Artic­le 2(1)(a) of Regu­la­ti­on (EU) No 1025/2012
35.‘Euro­pean stan­dard’ means a Euro­pean stan­dard as defi­ned in Artic­le 2(1)(b) of Regu­la­ti­on (EU) No 1025/2012;
36.‘har­mo­ni­zed stan­dard’ means a har­mo­ni­zed stan­dard as defi­ned in Artic­le 2(1)(c) of Regu­la­ti­on (EU) No 1025/2012
37.“cyber­se­cu­ri­ty risk” means the poten­ti­al for loss or dis­rup­ti­on cau­sed by a secu­ri­ty inci­dent, expres­sed as a com­bi­na­ti­on of the magnitu­de of such loss or dis­rup­ti­on and the likeli­hood of the secu­ri­ty inci­dent occurring;
38.“signi­fi­cant cyber­se­cu­ri­ty risk” means a cyber­se­cu­ri­ty risk that, due to its tech­ni­cal cha­rac­te­ri­stics, is likely to lead to a secu­ri­ty inci­dent that could have a serious nega­ti­ve impact and cau­se signi­fi­cant mate­ri­al or imma­te­ri­al loss or disruption;
39.’soft­ware bill of mate­ri­als’ means a for­mal record of the details and sup­p­ly chain rela­ti­on­ships of the com­pon­ents con­tai­ned in the soft­ware ele­ments of a pro­duct with digi­tal elements;
40.“Vul­nerabi­li­ty” means a weak­ne­ss, sus­cep­ti­bi­li­ty or mal­func­tion of a pro­duct with digi­tal ele­ments that can be exploi­ted in the event of a cyber threat;
41.“explo­ita­ble vul­nerabi­li­ty” means a vul­nerabi­li­ty that can be effec­tively exploi­ted by an unaut­ho­ri­zed third par­ty under prac­ti­cal ope­ra­ting conditions;
42.“actively exploi­ted vul­nerabi­li­ty” means a vul­nerabi­li­ty for which the­re is relia­ble evi­dence that a mali­cious actor has exploi­ted it in a system wit­hout the con­sent of the system owner;
43.’secu­ri­ty inci­dent’ means a secu­ri­ty inci­dent as defi­ned in Artic­le 6(6) of Direc­ti­ve (EU) 2022/2555;
44.“secu­ri­ty inci­dent affec­ting the secu­ri­ty of the pro­duct with digi­tal ele­ments” means a secu­ri­ty inci­dent that has or may have a nega­ti­ve impact on the abili­ty of a pro­duct with digi­tal ele­ments to pro­tect the avai­la­bi­li­ty, authen­ti­ci­ty, inte­gri­ty or con­fi­den­tia­li­ty of data or functionality;
45.’near-miss inci­dent’ means a near-miss inci­dent as defi­ned in Artic­le 6(5) of Direc­ti­ve (EU) 2022/2555;
46.“cyber thre­at” means a cyber thre­at as defi­ned in Artic­le 2(8) of Regu­la­ti­on (EU) 2019/881
47.‘per­so­nal data’ means per­so­nal data as defi­ned in Artic­le 4(1) of Regu­la­ti­on (EU) 2016/679;
48.“free and open source soft­ware” means soft­ware who­se source code is open­ly shared and which is made available under a free open source licen­se that pro­vi­des all rights to make it free­ly acce­s­si­ble, usable, modi­fia­ble and redistributable;
49.‘recall’ means a recall as defi­ned in point 22 of Artic­le 3 of Regu­la­ti­on (EU) 2019/1020
50.“with­dra­wal from the mar­ket” means with­dra­wal from the mar­ket as defi­ned in Artic­le 3(23) of Regu­la­ti­on (EU) 2019/1020;
51.‘CSIRT desi­gna­ted as coor­di­na­tor’ means a CSIRT desi­gna­ted as coor­di­na­tor in accordance with Artic­le 12(1) of Direc­ti­ve (EU) 2022/2555
Artic­le 4 Free movement
(1) Mem­ber Sta­tes shall not impe­de the making available on the mar­ket of pro­ducts with digi­tal ele­ments that com­ply with this Regu­la­ti­on in the respects cover­ed by this Regulation.
(2) Mem­ber Sta­tes shall not pre­vent the pre­sen­ta­ti­on or use of a pro­duct with digi­tal ele­ments that does not com­ply with this Regu­la­ti­on at trade fairs, exhi­bi­ti­ons, demon­stra­ti­ons or simi­lar events, inclu­ding pro­to­ty­pes, pro­vi­ded that the pro­duct is visi­bly mark­ed to indi­ca­te cle­ar­ly that it does not com­ply with this Regu­la­ti­on and may not be made available on the mar­ket until it does so.
(3) Mem­ber Sta­tes shall not pre­vent the making available on the mar­ket of unfi­nis­hed soft­ware which does not com­ply with this Regu­la­ti­on, pro­vi­ded that the soft­ware is made available only for a limi­t­ed peri­od neces­sa­ry for test­ing pur­po­ses and cle­ar­ly indi­ca­tes with a visi­ble mar­king that it does not com­ply with this Regu­la­ti­on and will not be available on the mar­ket except for test­ing purposes.
(4) Para­graph 3 shall not app­ly to safe­ty com­pon­ents cover­ed by Uni­on har­mo­nizati­on legis­la­ti­on other than this Regulation.
Artic­le 5 Pro­cu­re­ment or use of pro­ducts with digi­tal elements
(1) This Regu­la­ti­on shall not pre­vent Mem­ber Sta­tes from impo­sing addi­tio­nal cyber­se­cu­ri­ty requi­re­ments on pro­ducts incor­po­ra­ting digi­tal ele­ments when pro­cu­ring or using tho­se pro­ducts for spe­ci­fic pur­po­ses, inclu­ding whe­re tho­se pro­ducts are pro­cu­red or used for natio­nal secu­ri­ty or defen­se pur­po­ses, pro­vi­ded that tho­se requi­re­ments are con­si­stent with Mem­ber Sta­tes’ obli­ga­ti­ons under Uni­on law and are neces­sa­ry and pro­por­tio­na­te to achie­ve tho­se purposes.
(2) Wit­hout pre­ju­di­ce to Direc­ti­ves 2014/24/EU and 2014/25/EU, when pro­cu­ring pro­ducts with digi­tal ele­ments fal­ling within the scope of this Regu­la­ti­on, Mem­ber Sta­tes shall ensu­re that com­pli­ance with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I to this Regu­la­ti­on, inclu­ding the abili­ty of manu­fac­tu­r­ers to effec­tively mana­ge vul­nerabi­li­ties, is taken into account in the pro­cu­re­ment procedure.
Artic­le 6 Requi­re­ments for pro­ducts with digi­tal elements
Pro­ducts with digi­tal ele­ments are only made available on the mar­ket if
a) they meet the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part I of Annex I and on con­di­ti­on that they are pro­per­ly instal­led, main­tai­ned and used as inten­ded or under rea­son­ab­ly fore­seeable cir­cum­stances and, whe­re appli­ca­ble, the neces­sa­ry secu­ri­ty updates have been instal­led; and
b) the pro­ce­du­res defi­ned by the manu­fac­tu­rer com­ply with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I, Part II.
Artic­le 7 Important pro­ducts with digi­tal elements
(1) Devices incor­po­ra­ting digi­tal ele­ments that per­form the core func­tions of a pro­duct cate­go­ry listed in Annex III shall be con­side­red as essen­ti­al devices incor­po­ra­ting digi­tal ele­ments and shall be sub­ject to the con­for­mi­ty assess­ment pro­ce­du­res refer­red to in Artic­le 32(2) and (3). The inte­gra­ti­on of a device incor­po­ra­ting digi­tal ele­ments that has the core func­tion­a­li­ty of a pro­duct cate­go­ry listed in Annex III shall not in its­elf make the pro­duct into which it is inte­gra­ted sub­ject to the con­for­mi­ty assess­ment pro­ce­du­res refer­red to in Artic­le 32(2) and (3).
(2) The cate­go­ries of devices with digi­tal ele­ments refer­red to in para­graph 1 of this Artic­le, divi­ded into clas­ses I and II in accordance with Annex III, shall meet at least one of the fol­lo­wing criteria:
a) The digi­tal ele­ment pro­duct pri­ma­ri­ly per­forms func­tions that are cri­ti­cal to the cyber­se­cu­ri­ty of other pro­ducts, net­works or ser­vices, inclu­ding secu­ring authen­ti­ca­ti­on and access, intru­si­on pre­ven­ti­on and detec­tion, end­point secu­ri­ty or net­work protection;
b) the pro­duct with digi­tal ele­ments per­forms a func­tion that pres­ents a signi­fi­cant risk of adver­se effects in terms of its inten­si­ty and abili­ty to dis­rupt, con­trol or harm a lar­ge num­ber of other pro­ducts or the health, safe­ty or secu­ri­ty of its users through direct mani­pu­la­ti­on, such as a key system func­tion, inclu­ding net­work manage­ment, con­fi­gu­ra­ti­on con­trol, vir­tua­lizati­on or per­so­nal data processing.
(3) The Com­mis­si­on shall be empowered to adopt dele­ga­ted acts in accordance with Artic­le 61 to amend Annex III in order to add a new cate­go­ry to the list within each class of cate­go­ries of devices incor­po­ra­ting digi­tal ele­ments and to cla­ri­fy its defi­ni­ti­on, to move a cate­go­ry of devices from one class to ano­ther or to remo­ve an exi­sting cate­go­ry from that list. When asses­sing the need to amend the list in Annex III, the Com­mis­si­on shall take into account the cyber­se­cu­ri­ty-rela­ted func­tions or the func­tion and the level of cyber­se­cu­ri­ty risk posed by devices incor­po­ra­ting digi­tal ele­ments in accordance with the cri­te­ria set out in para­graph 2 of this Article.
The dele­ga­ted acts refer­red to in the first sub­pa­ra­graph shall, whe­re appro­pria­te, pro­vi­de for a tran­si­tio­nal peri­od of at least 12 months, in par­ti­cu­lar whe­re a new cate­go­ry of class I or class II essen­ti­al devices with digi­tal ele­ments refer­red to in Annex III is added or moved from class I to class II, befo­re the rele­vant con­for­mi­ty assess­ment pro­ce­du­res refer­red to in Artic­le 32(2) and (3) are applied, unless a shorter tran­si­tio­nal peri­od is justi­fi­ed on impe­ra­ti­ve grounds of urgen­cy.
(4) By 11 Decem­ber 2025, the Com­mis­si­on shall adopt an imple­men­ting act lay­ing down the tech­ni­cal descrip­ti­on of the cate­go­ries of devices with digi­tal ele­ments fal­ling within Clas­ses I and II set out in Annex III and the tech­ni­cal descrip­ti­on of the cate­go­ries of devices with digi­tal ele­ments set out in Annex IV. That imple­men­ting act shall be adopted in accordance with the exami­na­ti­on pro­ce­du­re refer­red to in Artic­le 62(2).
Artic­le 8 Cri­ti­cal pro­ducts with digi­tal elements
(1) The Com­mis­si­on shall be empowered to adopt dele­ga­ted acts in accordance with Artic­le 61 sup­ple­men­ting this Regu­la­ti­on to spe­ci­fy which devices with digi­tal ele­ments that have the core func­tion­a­li­ty of a pro­duct cate­go­ry listed in Annex IV to this Regu­la­ti­on are to be gran­ted a Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­te of at least assu­rance level ‘medi­um’ under a Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­me adopted pur­su­ant to Regu­la­ti­on (EU) 2019/881, to demon­stra­te con­for­mi­ty with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I to this Regu­la­ti­on or parts the­reof, pro­vi­ded that a Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­me for tho­se cate­go­ries of pro­ducts with digi­tal ele­ments has been adopted in accordance with Regu­la­ti­on (EU) 2019/881 and is available to manu­fac­tu­r­ers. Tho­se dele­ga­ted acts shall spe­ci­fy the requi­red assu­rance level, which shall be pro­por­tio­na­te to the level of cyber­se­cu­ri­ty risk asso­cia­ted with pro­ducts with digi­tal ele­ments and shall take into account their inten­ded pur­po­se, inclu­ding the cri­ti­cal depen­den­cy on them by essen­ti­al enti­ties as refer­red to in Artic­le 3(1) of Direc­ti­ve (EU) 2022/2555.
Befo­re adop­ting such dele­ga­ted acts, the Com­mis­si­on shall car­ry out an assess­ment of the poten­ti­al impact of the envi­sa­ged mea­su­res on the mar­ket and con­sult the rele­vant stake­hol­ders, inclu­ding the Euro­pean Cyber­se­cu­ri­ty Cer­ti­fi­ca­ti­on Group estab­lished by Regu­la­ti­on (EU) 2019/881. The assess­ment shall take into account the rea­di­ness and capa­ci­ty of Mem­ber Sta­tes to imple­ment the rele­vant Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­me. Whe­re no dele­ga­ted acts have been adopted pur­su­ant to the first sub­pa­ra­graph, devices incor­po­ra­ting digi­tal ele­ments and having core func­tion­a­li­ty of a device cate­go­ry set out in Annex IV shall be sub­ject to the con­for­mi­ty assess­ment pro­ce­du­res refer­red to in Artic­le 32(3). The dele­ga­ted acts refer­red to in the first sub­pa­ra­graph shall pro­vi­de for a tran­si­tio­nal peri­od of at least six months, unless a shorter tran­si­tio­nal peri­od is justi­fi­ed on impe­ra­ti­ve grounds of urgen­cy.
(2) The Com­mis­si­on shall be empowered to adopt dele­ga­ted acts in accordance with Artic­le 61 to amend Annex IV in order to add or remo­ve cate­go­ries of cri­ti­cal pro­ducts incor­po­ra­ting digi­tal ele­ments. When deter­mi­ning such cate­go­ries of cri­ti­cal pro­ducts with digi­tal ele­ments and the requi­red assu­rance level refer­red to in para­graph 1, the Com­mis­si­on shall take into account the cri­te­ria refer­red to in Artic­le 7(2) and shall ensu­re that the cate­go­ry of pro­ducts with digi­tal ele­ments com­plies with at least one of the fol­lo­wing criteria:
a) The­re is a cri­ti­cal depen­den­cy of essen­ti­al faci­li­ties accor­ding to Artic­le 3 of Direc­ti­ve (EU) 2022/2555 on the cate­go­ry of pro­ducts with digi­tal elements;
b) Secu­ri­ty inci­dents and exploi­ted vul­nerabi­li­ties rela­ting to the cate­go­ry of pro­ducts with digi­tal ele­ments could lead to serious dis­rup­ti­ons to cri­ti­cal sup­p­ly chains across the sin­gle market.
Befo­re adop­ting such dele­ga­ted acts, the Com­mis­si­on shall car­ry out an eva­lua­ti­on of the type refer­red to in para­graph 1. The dele­ga­ted acts refer­red to in the first sub­pa­ra­graph shall pro­vi­de for a tran­si­tio­nal peri­od of at least six months, unless a shorter tran­si­tio­nal peri­od is justi­fi­ed on impe­ra­ti­ve grounds of urgency. 
Artic­le 9 Con­sul­ta­ti­on of stakeholders
(1) When pre­pa­ring mea­su­res for the imple­men­ta­ti­on of this Regu­la­ti­on, the Com­mis­si­on shall con­sult and take into account the views of rele­vant stake­hol­ders, such as rele­vant Mem­ber Sta­te aut­ho­ri­ties, pri­va­te sec­tor enti­ties, inclu­ding micro, small and medi­um-sized enter­pri­ses, the open source soft­ware com­mu­ni­ty, con­su­mer asso­cia­ti­ons, aca­de­mia and rele­vant Uni­on agen­ci­es and bodies, as well as expert groups estab­lished at Uni­on level. In par­ti­cu­lar, the Com­mis­si­on shall, whe­re appro­pria­te, con­sult tho­se stake­hol­ders and seek their views in the fol­lo­wing struc­tu­red manner:
a) in dra­wing up the gui­de­lines refer­red to in Artic­le 26;
b) wit­hout pre­ju­di­ce to Artic­le 61, when pre­pa­ring the tech­ni­cal descrip­ti­ons of the pro­duct cate­go­ries listed in Annex III in accordance with Artic­le 7(4), when asses­sing the need to update the list of pro­duct cate­go­ries in accordance with Artic­le 7(3) and Artic­le 8(2), or when car­ry­ing out the assess­ment of the poten­ti­al impact on the mar­ket in accordance with Artic­le 8(1);
c) in car­ry­ing out pre­pa­ra­to­ry work for the eva­lua­ti­on and review of this Regulation.
(2) The Com­mis­si­on shall orga­ni­ze regu­lar con­sul­ta­ti­on and infor­ma­ti­on mee­tings, at least once a year, to obtain the views of the stake­hol­ders refer­red to in para­graph 1 on the imple­men­ta­ti­on of this Regulation.
Artic­le 10 Enhan­cing skills in a digi­tal envi­ron­ment with cyber defen­se capability
For the pur­po­ses of this Regu­la­ti­on and in order to meet the needs of pro­fes­sio­nals in sup­port­ing the imple­men­ta­ti­on of this Regu­la­ti­on, Mem­ber Sta­tes, with the sup­port of the Com­mis­si­on, the Euro­pean Cyber­se­cu­ri­ty Com­pe­tence Cen­ter and ENISA, as appro­pria­te, shall pro­mo­te actions and poli­ci­es aimed at the fol­lo­wing, in full respect of the respon­si­bi­li­ties of the Mem­ber Sta­tes in the field of edu­ca­ti­on:
a) Deve­lop cyber­se­cu­ri­ty skills and crea­te orga­nizatio­nal and tech­no­lo­gi­cal tools to ensu­re suf­fi­ci­ent avai­la­bi­li­ty of qua­li­fi­ed pro­fes­sio­nals to sup­port the acti­vi­ties of mar­ket sur­veil­lan­ce aut­ho­ri­ties and con­for­mi­ty assess­ment bodies;
b) Streng­then coope­ra­ti­on bet­ween the pri­va­te sec­tor and eco­no­mic actors, inclu­ding through retrai­ning or ups­kil­ling of employees of manu­fac­tu­r­ers, con­su­mers, trai­ning insti­tu­ti­ons and public admi­ni­stra­ti­ons, in order to pro­vi­de more oppor­tu­ni­ties for young peo­p­le to access jobs in the cyber­se­cu­ri­ty sector.
Artic­le 11 Gene­ral pro­duct safety
By way of dero­ga­ti­on from point (b) of the third sub­pa­ra­graph of Artic­le 2(1) of Regu­la­ti­on (EU) 2023/988, Sec­tion 1 of Chap­ter III, Chap­ters V and VII and Chap­ters IX to XI of that Regu­la­ti­on shall app­ly to devices with digi­tal ele­ments rela­ting to aspects and risks or risk cate­go­ries not cover­ed by this Regu­la­ti­on, pro­vi­ded that tho­se devices are not sub­ject to spe­ci­fic safe­ty requi­re­ments laid down in other ‘Uni­on har­mo­nizati­on legis­la­ti­on’ within the mea­ning of point (27) of Artic­le 3 of Regu­la­ti­on (EU) 2023/988.
Artic­le 12 High-risk AI systems
(1) Wit­hout pre­ju­di­ce to the accu­ra­cy and robust­ness requi­re­ments laid down in Artic­le 15 of Regu­la­ti­on (EU) 2024/1689, pro­ducts with digi­tal ele­ments that fall within the scope of this Regu­la­ti­on and that are clas­si­fi­ed as high-risk AI-systems in accordance with Artic­le 6 of that Regu­la­ti­on shall be dee­med to com­ply with the cyber­se­cu­ri­ty requi­re­ments laid down in Artic­le 15 of that Regu­la­ti­on if
a) the­se pro­ducts meet the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I, Part I;
b) the pro­ce­du­res defi­ned by the manu­fac­tu­rer com­ply with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part II of Annex I, and
c) the achie­ve­ment of the cyber­se­cu­ri­ty level requi­red under Artic­le 15 of Regu­la­ti­on (EU) 2024/1689 is demon­stra­ted in the EU decla­ra­ti­on of con­for­mi­ty issued in accordance with this Regulation.
(2) The rele­vant con­for­mi­ty assess­ment pro­ce­du­re pro­vi­ded for in Artic­le 43 of Regu­la­ti­on (EU) 2024/1689 shall app­ly to the devices with digi­tal ele­ments and cyber­se­cu­ri­ty requi­re­ments refer­red to in para­graph 1. For the pur­po­ses of this assess­ment, the noti­fi­ed bodies respon­si­ble for checking the con­for­mi­ty of high-risk AI-systems under Regu­la­ti­on (EU) 2024/1689 shall also be respon­si­ble for checking, under this Regu­la­ti­on, the con­for­mi­ty of high-risk AI-systems with the requi­re­ments set out in Annex I to this Regu­la­ti­on, pro­vi­ded that the noti­fi­ca­ti­on pro­ce­du­re car­ri­ed out under Regu­la­ti­on (EU) 2024/1689 has veri­fi­ed that tho­se noti­fi­ed bodies meet the requi­re­ments set out in Artic­le 39 of this Regulation.
(3) By way of dero­ga­ti­on from para­graph 2 of this Artic­le, cri­ti­cal devices with digi­tal ele­ments listed in Annex III to this Regu­la­ti­on that are sub­ject to the con­for­mi­ty assess­ment pro­ce­du­res refer­red to in points (a) and (b) of Artic­le 32(2) and Artic­le 32(3) of this Regu­la­ti­on and cri­ti­cal devices with digi­tal ele­ments listed in Annex IV to this Regu­la­ti­on that are requi­red to obtain a Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­te in accordance with Artic­le 8(1) of this Regu­la­ti­on or, in the absence of such a cer­ti­fi­ca­te, that are sub­ject to the con­for­mi­ty assess­ment pro­ce­du­res refer­red to in Artic­le 32(3) of this Regu­la­ti­on shall be sub­ject to the con­for­mi­ty assess­ment pro­ce­du­res refer­red to in Artic­le 32(3) of this Regu­la­ti­on, and are also clas­si­fi­ed as high-risk AI-systems in accordance with Artic­le 6 of Regu­la­ti­on (EU) 2024/1689 and to which the con­for­mi­ty assess­ment pro­ce­du­re based on inter­nal con­trol set out in Annex VI to Regu­la­ti­on (EU) 2024/1689 applies, are sub­ject to the con­for­mi­ty assess­ment pro­ce­du­res pro­vi­ded for in this Regu­la­ti­on as far as the essen­ti­al cyber­se­cu­ri­ty requi­re­ments laid down in this Regu­la­ti­on are concerned.
(4) Manu­fac­tu­r­ers of pro­ducts with digi­tal ele­ments refer­red to in para­graph 1 may par­ti­ci­pa­te in the AI labo­ra­to­ries refer­red to in Artic­le 57 of Regu­la­ti­on (EU) 2024/1689.

Chap­ter II Obli­ga­ti­ons of eco­no­mic ope­ra­tors and pro­vi­si­ons rela­ting to free and open source software 

Artic­le 13 Obli­ga­ti­ons of producers
(1) When pla­cing a device with digi­tal ele­ments on the mar­ket, manu­fac­tu­r­ers shall ensu­re that the device has been desi­gned, deve­lo­ped and manu­fac­tu­red in accordance with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part I of Annex I.
(2) For the pur­po­ses of com­ply­ing with para­graph 1, manu­fac­tu­r­ers shall car­ry out an assess­ment of the cyber­se­cu­ri­ty risks posed by a device with digi­tal ele­ments and shall take the out­co­me of that assess­ment into account in the plan­ning, design, deve­lo­p­ment, manu­fac­tu­ring, sup­p­ly and main­ten­an­ce pha­ses of the device with digi­tal ele­ments in order to mini­mi­ze cyber­se­cu­ri­ty risks, pre­vent secu­ri­ty inci­dents and mini­mi­ze the impact of such inci­dents, inclu­ding on the health and safe­ty of users.
(3) The cyber­se­cu­ri­ty risk assess­ment shall be docu­men­ted and, whe­re appro­pria­te, updated during a sup­port peri­od to be deter­mi­ned in accordance with para­graph 8. That cyber­se­cu­ri­ty risk assess­ment shall include at least a cyber­se­cu­ri­ty risk ana­ly­sis based on the inten­ded pur­po­se and rea­son­ab­ly fore­seeable use of the device with digi­tal ele­ments, such as the ope­ra­ting envi­ron­ment or the assets to be pro­tec­ted, taking into account the expec­ted life­time of the device. The cyber­se­cu­ri­ty risk assess­ment shall indi­ca­te whe­ther and, if so, how the secu­ri­ty requi­re­ments set out in point 2 of Part I of Annex I are appli­ca­ble to the rele­vant device with digi­tal ele­ments and how tho­se requi­re­ments are imple­men­ted on the basis of the cyber­se­cu­ri­ty risk assess­ment. It shall also indi­ca­te how the manu­fac­tu­rer shall app­ly point 1 of Part I of Annex I and the requi­re­ments for the manage­ment of vul­nerabi­li­ties set out in Part II of Annex I.
(4) When pla­cing a device with digi­tal ele­ments on the mar­ket, the manu­fac­tu­rer shall include the cyber­se­cu­ri­ty risk assess­ment refer­red to in para­graph 3 in the tech­ni­cal docu­men­ta­ti­on requi­red pur­su­ant to Artic­le 31 and Annex VII. For devices with digi­tal ele­ments refer­red to in Artic­le 12 that are also sub­ject to other Uni­on legis­la­ti­on, the cyber­se­cu­ri­ty risk assess­ment may also be part of the risk assess­ments requi­red by that Uni­on legis­la­ti­on. Whe­re cer­tain essen­ti­al cyber­se­cu­ri­ty requi­re­ments are not appli­ca­ble to the device with digi­tal ele­ments, the manu­fac­tu­rer shall include a clear justi­fi­ca­ti­on in that tech­ni­cal documentation.
(5) For the pur­po­ses of ful­fil­ling the obli­ga­ti­on laid down in para­graph 1, manu­fac­tu­r­ers shall exer­cise due care when inte­gra­ting com­pon­ents obtai­ned from third par­ties into their devices incor­po­ra­ting digi­tal items, so that such com­pon­ents do not com­pro­mi­se the cyber­se­cu­ri­ty of the device incor­po­ra­ting digi­tal items, inclu­ding when inte­gra­ting free and open source soft­ware that has not been made available on the mar­ket in the cour­se of a com­mer­cial activity.
(6) As soon as the manu­fac­tu­rer iden­ti­fi­es a vul­nerabi­li­ty in a com­po­nent, inclu­ding an open source com­po­nent, incor­po­ra­ted in the device with digi­tal ele­ments, it shall noti­fy the vul­nerabi­li­ty to the per­son or enti­ty that manu­fac­tures or main­ta­ins that com­po­nent and shall address and reme­dia­te the vul­nerabi­li­ty in accordance with the vul­nerabi­li­ty manage­ment requi­re­ments set out in Part II of Annex I. Whe­re manu­fac­tu­r­ers have deve­lo­ped a soft­ware or hard­ware modi­fi­ca­ti­on to address the vul­nerabi­li­ty in that com­po­nent, they shall com­mu­ni­ca­te the rele­vant code or docu­men­ta­ti­on to the per­son or enti­ty that manu­fac­tures or main­ta­ins the com­po­nent in a machi­ne-rea­da­ble for­mat, as appropriate.
(7) The manu­fac­tu­rer shall syste­ma­ti­cal­ly docu­ment, in a man­ner appro­pria­te to the natu­re of the cyber­se­cu­ri­ty risks, all rele­vant cyber­se­cu­ri­ty aspects of the device with digi­tal ele­ments, inclu­ding vul­nerabi­li­ties of which it beco­mes awa­re and any rele­vant infor­ma­ti­on pro­vi­ded by third par­ties, and update the cyber­se­cu­ri­ty risk assess­ment of the device as appropriate.
(8) When pla­cing a device with digi­tal ele­ments on the mar­ket and during the expec­ted life­time of the device and the sup­port peri­od, manu­fac­tu­r­ers shall ensu­re that vul­nerabi­li­ties of that device, inclu­ding its com­pon­ents, are effec­tively addres­sed in accordance with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part II of Annex I.
Manu­fac­tu­r­ers shall set the sup­port peri­od to reflect the expec­ted dura­ti­on of use of the device, taking into account, in par­ti­cu­lar, rea­sonable expec­ta­ti­ons of users, the natu­re of the device, inclu­ding its inten­ded pur­po­se, and rele­vant Uni­on legis­la­ti­on defi­ning the life­time of devices with digi­tal ele­ments. When deter­mi­ning the sup­port peri­od, manu­fac­tu­r­ers may also take into account the sup­port peri­ods for pro­ducts with digi­tal ele­ments with a simi­lar func­tion pla­ced on the mar­ket by other manu­fac­tu­r­ers, the avai­la­bi­li­ty of the ope­ra­ting envi­ron­ment, the sup­port peri­ods for inte­gra­ted com­pon­ents pro­vi­ding core func­tion­a­li­ty and purcha­sed from third par­ties, and the rele­vant gui­dance of the spe­cial admi­ni­stra­ti­ve coope­ra­ti­on group (ADCO) estab­lished under Artic­le 52(15) and of the Com­mis­si­on. The ele­ments to be taken into account for deter­mi­ning the sup­port peri­od shall be taken into account in a man­ner that ensu­res pro­por­tio­na­li­ty. Wit­hout pre­ju­di­ce to the second sub­pa­ra­graph, the sup­port peri­od shall be at least five years. If the pro­duct with digi­tal ele­ments is expec­ted to be in ser­vice for less than five years, the sup­port peri­od shall cor­re­spond to the expec­ted useful life. Taking into account the ADCO recom­men­da­ti­ons refer­red to in Artic­le 52(16), the Com­mis­si­on may adopt dele­ga­ted acts in accordance with Artic­le 61 to sup­ple­ment this Regu­la­ti­on by spe­ci­fy­ing the mini­mum sup­port peri­od for cer­tain cate­go­ries of devices whe­re mar­ket sur­veil­lan­ce data indi­ca­te ina­de­qua­te sup­port peri­ods. Manu­fac­tu­r­ers shall include the infor­ma­ti­on taken into account when deter­mi­ning the sup­port peri­od of a device with digi­tal ele­ments in the tech­ni­cal docu­men­ta­ti­on refer­red to in Annex VII. Manu­fac­tu­r­ers shall have in place appro­pria­te poli­ci­es and pro­ce­du­res, inclu­ding a coor­di­na­ted vul­nerabi­li­ty dis­clo­sure poli­cy in accordance with point 5 of Part II of Annex I, to address and cor­rect poten­ti­al vul­nerabi­li­ties in the device with digi­tal ele­ments repor­ted by inter­nal or exter­nal sources.
(9) Manu­fac­tu­r­ers shall ensu­re that any secu­ri­ty update refer­red to in point 8 of Part II of Annex I made available to users during the sup­port peri­od remains available for at least 10 years after its deployment or for the rema­in­der of the sup­port peri­od, whi­che­ver is the longer.
(10) Whe­re a manu­fac­tu­rer has pla­ced sub­se­quent sub­stan­ti­al­ly dif­fe­rent ver­si­ons of a soft­ware pro­duct on the mar­ket, it may limit the assu­rance of com­pli­ance with the essen­ti­al cyber­se­cu­ri­ty requi­re­ment set out in point 2 of Part II of Annex I to the ver­si­on last pla­ced on the mar­ket by the manu­fac­tu­rer, pro­vi­ded that users of the pre­vious­ly pla­ced ver­si­on have access to the last ver­si­on pla­ced on the mar­ket free of char­ge and do not incur addi­tio­nal costs for adap­ting the hard­ware and soft­ware envi­ron­ment in which they use the ori­gi­nal ver­si­on of that product.
(11) Manu­fac­tu­r­ers may main­tain public soft­ware archi­ves that make it easier for users to access histo­ri­cal ver­si­ons. In the­se cases, users are infor­med cle­ar­ly and in an easi­ly acce­s­si­ble form about the risks asso­cia­ted with the use of unsup­port­ed software.
(12) Befo­re pla­cing a device with digi­tal ele­ments on the mar­ket, manu­fac­tu­r­ers shall draw up the tech­ni­cal docu­men­ta­ti­on refer­red to in Artic­le 31.
They shall car­ry out the cho­sen con­for­mi­ty assess­ment pro­ce­du­res refer­red to in Artic­le 32 or have them car­ri­ed out. Whe­re it has been demon­stra­ted through that con­for­mi­ty assess­ment pro­ce­du­re that the device with digi­tal ele­ments satis­fies the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part I of Annex I and the pro­ce­du­res adopted by the manu­fac­tu­rer satis­fy the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part II of Annex I, manu­fac­tu­r­ers shall draw up the EU decla­ra­ti­on of con­for­mi­ty refer­red to in Artic­le 28 and affix the CE mar­king refer­red to in Artic­le 30.
(13) Manu­fac­tu­r­ers shall keep the tech­ni­cal docu­men­ta­ti­on and the EU decla­ra­ti­on of con­for­mi­ty for the mar­ket sur­veil­lan­ce aut­ho­ri­ties for at least 10 years after the pro­duct with digi­tal ele­ments has been pla­ced on the mar­ket or for the dura­ti­on of the sup­port peri­od, whi­che­ver is the longer.
(14) Manu­fac­tu­r­ers shall ensu­re that pro­ce­du­res are in place to ensu­re that devices incor­po­ra­ting digi­tal ele­ments remain in con­for­mi­ty with this Regu­la­ti­on when manu­fac­tu­red in series. Manu­fac­tu­r­ers shall take due account of any chan­ges in the design and manu­fac­tu­ring pro­cess or in the design or cha­rac­te­ri­stics of the device incor­po­ra­ting digi­tal ele­ments, as well as of chan­ges in the har­mo­ni­zed stan­dards, Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­mes or com­mon spe­ci­fi­ca­ti­ons refer­red to in Artic­le 27 that were used as a basis for the decla­ra­ti­on of con­for­mi­ty of the device incor­po­ra­ting digi­tal ele­ments or for the veri­fi­ca­ti­on of its conformity.
(15) Manu­fac­tu­r­ers shall ensu­re that their devices incor­po­ra­ting digi­tal ele­ments bear a type, batch or seri­al num­ber or other ele­ment allo­wing their iden­ti­fi­ca­ti­on, or, whe­re that is not pos­si­ble, that infor­ma­ti­on is pro­vi­ded on the pack­a­ging or in a docu­ment accom­pany­ing the device incor­po­ra­ting digi­tal elements.
(16) Manu­fac­tu­r­ers shall indi­ca­te the name, regi­stered trade name or regi­stered trade mark of the manu­fac­tu­rer, the postal address, e‑mail address or other digi­tal cont­act details and, whe­re available, the web­site whe­re the manu­fac­tu­rer can be cont­ac­ted, eit­her on the device with digi­tal ele­ments its­elf or, whe­re that is not pos­si­ble, on its pack­a­ging or in a docu­ment accom­pany­ing the device with digi­tal ele­ments. This infor­ma­ti­on shall also be inclu­ded in the infor­ma­ti­on and ins­truc­tions for users set out in Annex II. The cont­act details shall be in a lan­guage which can be easi­ly under­s­tood by users and mar­ket sur­veil­lan­ce authorities.
(17) For the pur­po­ses of this Regu­la­ti­on, manu­fac­tu­r­ers shall desi­gna­te a sin­gle point of cont­act that allo­ws users to com­mu­ni­ca­te direct­ly and quick­ly with them, inclu­ding to faci­li­ta­te the report­ing of vul­nerabi­li­ties of the pro­duct with digi­tal elements.
Manu­fac­tu­r­ers shall ensu­re that the sin­gle point of cont­act can be easi­ly iden­ti­fi­ed by users. They shall also include the one-stop shop in the infor­ma­ti­on and ins­truc­tions to users set out in Annex II. The one-stop shop shall allow users to choo­se their pre­fer­red means of com­mu­ni­ca­ti­on, which shall not be limi­t­ed to auto­ma­ted means.
(18) Manu­fac­tu­r­ers shall ensu­re that devices incor­po­ra­ting digi­tal ele­ments are accom­pa­nied by the infor­ma­ti­on and ins­truc­tions for users set out in Annex II in paper or elec­tro­nic form. Such infor­ma­ti­on and ins­truc­tions shall be pro­vi­ded in a lan­guage which can be easi­ly under­s­tood by users and mar­ket sur­veil­lan­ce aut­ho­ri­ties. They must be clear, under­stan­da­ble, unam­bi­guous and legi­ble. They shall enable the safe instal­la­ti­on, ope­ra­ti­on and use of pro­ducts incor­po­ra­ting digi­tal ele­ments. Manu­fac­tu­r­ers shall make the infor­ma­ti­on and ins­truc­tions for users refer­red to in Annex II available to users for at least 10 years after the device with digi­tal ele­ments has been pla­ced on the mar­ket or for the dura­ti­on of the sup­port peri­od, whi­che­ver is the lon­ger. Whe­re such infor­ma­ti­on and ins­truc­tions are pro­vi­ded online, manu­fac­tu­r­ers shall ensu­re that they are acce­s­si­ble, user-fri­end­ly and available online for at least 10 years after the device with digi­tal ele­ments has been pla­ced on the mar­ket or for the dura­ti­on of the sup­port peri­od, whi­che­ver is the longer.
(19) Manu­fac­tu­r­ers shall ensu­re that the end date of the peri­od of sup­port refer­red to in para­graph 8 is cle­ar­ly and com­pre­hen­si­bly indi­ca­ted at the time of purcha­se in an easi­ly acce­s­si­ble man­ner and, whe­re appli­ca­ble, on the device with digi­tal ele­ments, its pack­a­ging or by digi­tal means, indi­ca­ting at least the month and the year.
Whe­re tech­ni­cal­ly fea­si­ble given the natu­re of the pro­duct with digi­tal ele­ments, manu­fac­tu­r­ers shall dis­play a mes­sa­ge to users to inform them that the end of the sup­port peri­od of their pro­duct with digi­tal ele­ments has been rea­ched.
(20) Manu­fac­tu­r­ers shall enc­lo­se with the pro­duct with digi­tal ele­ments eit­her a copy of the EU decla­ra­ti­on of con­for­mi­ty or a sim­pli­fi­ed EU decla­ra­ti­on of con­for­mi­ty. Whe­re only a sim­pli­fi­ed EU decla­ra­ti­on of con­for­mi­ty is pro­vi­ded, it shall indi­ca­te the exact inter­net address whe­re the full EU decla­ra­ti­on of con­for­mi­ty can be found.
(21) From the pla­cing on the mar­ket and during the sup­port peri­od, manu­fac­tu­r­ers who know or have rea­son to belie­ve that the device with digi­tal ele­ments or the pro­ce­s­ses estab­lished by the manu­fac­tu­rer do not com­ply with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I shall imme­dia­te­ly take the neces­sa­ry cor­rec­ti­ve action to bring that device with digi­tal ele­ments or the manufacturer’s pro­ce­s­ses into com­pli­ance or, if appro­pria­te, to with­draw the device from the mar­ket or recall it.
(22) Manu­fac­tu­r­ers shall, fur­ther to a rea­so­ned request from a mar­ket sur­veil­lan­ce aut­ho­ri­ty, pro­vi­de it with all the infor­ma­ti­on and docu­men­ta­ti­on in paper or elec­tro­nic form, in a lan­guage which can be easi­ly under­s­tood by that aut­ho­ri­ty, neces­sa­ry to demon­stra­te the con­for­mi­ty of the device with digi­tal ele­ments and the pro­ce­du­res estab­lished by the manu­fac­tu­rer with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I. Manu­fac­tu­r­ers shall coope­ra­te with that aut­ho­ri­ty, at its request, on any action taken to address the cyber­se­cu­ri­ty risks posed by the device with digi­tal ele­ments that they have pla­ced on the market.
(23) A manu­fac­tu­rer who cea­ses to ope­ra­te and, as a con­se­quence, is unable to com­ply with this Regu­la­ti­on shall, befo­re the ces­sa­ti­on takes effect, inform the rele­vant mar­ket sur­veil­lan­ce aut­ho­ri­ties and, by any available means and as far as pos­si­ble, users of the rele­vant devices pla­ced on the mar­ket through digi­tal means, of the impen­ding cessation.
(24) The Com­mis­si­on may, by means of imple­men­ting acts, spe­ci­fy the for­mat and ele­ments of the soft­ware BOM refer­red to in point 1 of Part II of Annex I, taking into account Euro­pean or inter­na­tio­nal stan­dards and best prac­ti­ces. Tho­se imple­men­ting acts shall be adopted in accordance with the exami­na­ti­on pro­ce­du­re refer­red to in Artic­le 62(2).
(25) In order to assess the depen­dence of Mem­ber Sta­tes and the Uni­on as a who­le on soft­ware com­pon­ents, and in par­ti­cu­lar on com­pon­ents con­side­red as free and open source soft­ware, ADCO may deci­de to car­ry out a Uni­on-wide depen­dence assess­ment for cer­tain cate­go­ries of devices with digi­tal ele­ments. For this pur­po­se, mar­ket sur­veil­lan­ce aut­ho­ri­ties may request manu­fac­tu­r­ers of such cate­go­ries of pro­ducts with digi­tal ele­ments to sub­mit the rele­vant soft­ware BOMs in accordance with Annex I, Part II, point 1. On the basis of this infor­ma­ti­on, mar­ket sur­veil­lan­ce aut­ho­ri­ties may pro­vi­de ADCO with anony­mi­zed and aggre­ga­ted infor­ma­ti­on on soft­ware depen­den­ci­es. ADCO shall sub­mit a report on the results of the depen­den­cy assess­ment to the Coope­ra­ti­on Group estab­lished under Artic­le 14 of Direc­ti­ve (EU) 2022/2555.
Artic­le 14 Report­ing obli­ga­ti­ons of manufacturers
(1) A manu­fac­tu­rer shall report any actively exploi­ted vul­nerabi­li­ty con­tai­ned in the device with digi­tal ele­ments of which it beco­mes awa­re simul­ta­neous­ly to the CSIRT desi­gna­ted as coor­di­na­tor in accordance with para­graph 7 and to ENISA. The manu­fac­tu­rer shall report that actively exploi­ted vul­nerabi­li­ty through the sin­gle report­ing plat­form estab­lished in accordance with Artic­le 16.
(2) For the pur­po­ses of the noti­fi­ca­ti­on refer­red to in para­graph 1, the manu­fac­tu­rer shall sub­mit the following:
a) wit­hout undue delay and in any event within 24 hours after the manu­fac­tu­rer has beco­me awa­re of it, an ear­ly war­ning of an actively exploi­ted vul­nerabi­li­ty, indi­ca­ting the Mem­ber Sta­tes in the ter­ri­to­ry of which the pro­duct con­tai­ning digi­tal ele­ments of the manu­fac­tu­rer has been made available to its knowledge;
b) unless the rele­vant infor­ma­ti­on has alre­a­dy been pro­vi­ded, wit­hout undue delay and in any event within 72 hours of the manu­fac­tu­rer beco­ming awa­re of the actively exploi­ted vul­nerabi­li­ty, a vul­nerabi­li­ty report con­tai­ning gene­ral infor­ma­ti­on, whe­re available, on the digi­tal item pro­duct con­cer­ned, on the gene­ral natu­re of the explo­ita­ti­on and of the vul­nerabi­li­ty con­cer­ned, and on any cor­rec­ti­ve or miti­ga­ting action taken and any cor­rec­ti­ve or reme­di­al action that users may take, inclu­ding, whe­re appro­pria­te, an indi­ca­ti­on of how sen­si­ti­ve the manu­fac­tu­rer con­siders the repor­ted infor­ma­ti­on to be;
c) unless the rele­vant infor­ma­ti­on has alre­a­dy been sub­mit­ted, a final report con­tai­ning at least the fol­lo­wing no later than 14 days after a cor­rec­ti­ve or miti­ga­ting action is available:
i) a descrip­ti­on of the vul­nerabi­li­ty, inclu­ding its seve­ri­ty and impact,
ii) if available, infor­ma­ti­on about any mali­cious actor who has exploi­ted or is exploi­ting the vulnerability,
iii) Infor­ma­ti­on about the secu­ri­ty update or other cor­rec­ti­ve mea­su­res pro­vi­ded to address the vulnerability.
(3) A manu­fac­tu­rer shall report any serious secu­ri­ty inci­dent affec­ting the secu­ri­ty of the device with digi­tal ele­ments of which it beco­mes awa­re simul­ta­neous­ly to the CSIRT desi­gna­ted as coor­di­na­tor in accordance with para­graph 7 and to ENISA. The manu­fac­tu­rer shall report that secu­ri­ty inci­dent through the sin­gle report­ing plat­form estab­lished in accordance with Artic­le 16.
(4) For the pur­po­ses of the noti­fi­ca­ti­on refer­red to in para­graph 3, the manu­fac­tu­rer shall sub­mit the following:
a) wit­hout undue delay and in any event within 24 hours of the manu­fac­tu­rer beco­ming awa­re of it, an ear­ly war­ning of a serious secu­ri­ty inci­dent affec­ting the secu­ri­ty of the pro­duct with digi­tal ele­ments, indi­ca­ting at least whe­ther the secu­ri­ty inci­dent is suspec­ted to be the result of ille­gal or mali­cious acts and, whe­re appli­ca­ble, the Mem­ber Sta­tes on who­se ter­ri­to­ry the pro­duct with digi­tal ele­ments of the manu­fac­tu­rer is known to have been made available;
b) unless the rele­vant infor­ma­ti­on has alre­a­dy been pro­vi­ded, wit­hout undue delay and in any event within 72 hours of the manu­fac­tu­rer beco­ming awa­re of the secu­ri­ty inci­dent, a noti­fi­ca­ti­on of the secu­ri­ty inci­dent con­tai­ning gene­ral infor­ma­ti­on, whe­re available, on the natu­re of the secu­ri­ty inci­dent, an initi­al assess­ment of the secu­ri­ty inci­dent, cor­rec­ti­ve or miti­ga­ting actions taken and cor­rec­ti­ve or reme­di­al actions that users may take, inclu­ding, whe­re appro­pria­te, an indi­ca­ti­on of how sen­si­ti­ve the manu­fac­tu­rer con­siders the repor­ted infor­ma­ti­on to be;
c) unless the rele­vant infor­ma­ti­on has alre­a­dy been pro­vi­ded, a final report con­tai­ning at least the fol­lo­wing within one month of the sub­mis­si­on of the inci­dent report refer­red to in point (b):
i) a detail­ed descrip­ti­on of the secu­ri­ty inci­dent, inclu­ding its seve­ri­ty and impact;
ii) Infor­ma­ti­on on the type of thre­at or under­ly­ing cau­se that likely trig­ge­red the secu­ri­ty incident;
iii) Details of reme­di­al action taken and ongoing.
(5) For the pur­po­ses of para­graph 3, a secu­ri­ty inci­dent that has an impact on the secu­ri­ty of the pro­duct with digi­tal ele­ments shall be con­side­red serious if
a) it adver­se­ly affects or may adver­se­ly affect the abili­ty of a pro­duct with digi­tal ele­ments to pro­tect the avai­la­bi­li­ty, authen­ti­ci­ty, inte­gri­ty or con­fi­den­tia­li­ty of sen­si­ti­ve or cri­ti­cal data or func­tions, or
b) it has led or may lead to the intro­duc­tion or exe­cu­ti­on of mali­cious code in a pro­duct with digi­tal ele­ments or in the net­work and infor­ma­ti­on system of a user of the pro­duct with digi­tal elements.
(6) If neces­sa­ry, the CSIRT desi­gna­ted as coor­di­na­tor that initi­al­ly recei­ves the noti­fi­ca­ti­on may request the manu­fac­tu­r­ers to pro­vi­de an inte­rim report on rele­vant sta­tus updates on the actively exploi­ted vul­nerabi­li­ty or serious secu­ri­ty inci­dent affec­ting the secu­ri­ty of the pro­duct with digi­tal elements.
(7) The noti­fi­ca­ti­ons refer­red to in para­graphs 1 and 3 of this Artic­le shall be sub­mit­ted through the sin­gle report­ing plat­form refer­red to in Artic­le 16 using one of the elec­tro­nic report­ing end­points refer­red to in Artic­le 16(1). The noti­fi­ca­ti­on shall be sub­mit­ted via the elec­tro­nic noti­fi­ca­ti­on end­point of the CSIRT desi­gna­ted as coor­di­na­tor of the Mem­ber Sta­te whe­re the manu­fac­tu­r­ers have their main estab­lish­ment in the Uni­on and shall be acce­s­si­ble to ENISA at the same time.
For the pur­po­ses of this Regu­la­ti­on, a manu­fac­tu­rer shall be dee­med to have its main estab­lish­ment in the Uni­on in the Mem­ber Sta­te whe­re the decis­i­ons rela­ting to the cyber­se­cu­ri­ty of its pro­ducts with digi­tal ele­ments are pre­do­mi­nant­ly taken. Whe­re such a Mem­ber Sta­te can­not be deter­mi­ned, the Mem­ber Sta­te of main estab­lish­ment shall be dee­med to be the Mem­ber Sta­te whe­re the manu­fac­tu­rer con­cer­ned has the estab­lish­ment with the hig­hest num­ber of employees in the Uni­on. Whe­re a manu­fac­tu­rer does not have a main estab­lish­ment in the Uni­on, it shall sub­mit the noti­fi­ca­ti­ons refer­red to in para­graphs 1 and 3 using the elec­tro­nic noti­fi­ca­ti­on end­point of the CSIRT desi­gna­ted as coor­di­na­tor in the Mem­ber Sta­te deter­mi­ned in accordance with the fol­lo­wing order and on the basis of the infor­ma­ti­on available to the manu­fac­tu­rer:
a) the Mem­ber Sta­te in which the aut­ho­ri­zed repre­sen­ta­ti­ve is estab­lished who acts on behalf of the manu­fac­tu­rer for most pro­ducts with digi­tal ele­ments of the manufacturer;
b) the Mem­ber Sta­te in which the importer is estab­lished who places on the mar­ket most of the pro­ducts con­tai­ning digi­tal ele­ments from that manufacturer;
c) the Mem­ber Sta­te in which the dis­tri­bu­tor is estab­lished that makes most of the pro­ducts with digi­tal ele­ments of that manu­fac­tu­rer available on the market;
d) the Mem­ber Sta­te in which most users of pro­ducts with digi­tal ele­ments from this manu­fac­tu­rer are located.
With regard to point (d) of the third sub­pa­ra­graph, a manu­fac­tu­rer may sub­mit noti­fi­ca­ti­ons rela­ted to sub­se­quent actively exploi­ted vul­nerabi­li­ties or serious secu­ri­ty inci­dents affec­ting the secu­ri­ty of the pro­duct with digi­tal ele­ments to the same CSIRT that has been desi­gna­ted as coor­di­na­tor and to which it has first repor­ted.
(8) After beco­ming awa­re of an actively exploi­ted vul­nerabi­li­ty or a serious secu­ri­ty inci­dent affec­ting the secu­ri­ty of the device with digi­tal ele­ments, the manu­fac­tu­rer shall inform the affec­ted users of the device with digi­tal ele­ments and, whe­re appli­ca­ble, all users of that vul­nerabi­li­ty or serious secu­ri­ty inci­dent and, whe­re neces­sa­ry, of any risk miti­ga­ti­on mea­su­res and cor­rec­ti­ve actions that users can take to miti­ga­te the impact of tho­se vul­nerabi­li­ties or secu­ri­ty inci­dents, whe­re appro­pria­te in a struc­tu­red, machi­ne-rea­da­ble for­mat that can be easi­ly pro­ce­s­sed auto­ma­ti­cal­ly. Whe­re the manu­fac­tu­rer fails to inform the users of the pro­duct with digi­tal ele­ments in a time­ly man­ner, the CSIRTs desi­gna­ted as coor­di­na­tors may make this infor­ma­ti­on available to the users if they con­sider it pro­por­tio­na­te and neces­sa­ry to pre­vent or miti­ga­te the impact of the­se vul­nerabi­li­ties or secu­ri­ty incidents.
(9) By 11 Decem­ber 2025, the Com­mis­si­on shall adopt a dele­ga­ted act in accordance with Artic­le 61 of this Regu­la­ti­on sup­ple­men­ting this Regu­la­ti­on by spe­ci­fy­ing the moda­li­ties and con­di­ti­ons for the appli­ca­ti­on of the cyber­se­cu­ri­ty grounds rela­ted to the delay in dis­se­mi­na­ti­on of noti­fi­ca­ti­ons refer­red to in Artic­le 16(2) of this Regu­la­ti­on. The Com­mis­si­on shall coope­ra­te with the CSIRTs net­work estab­lished under Artic­le 15 of Direc­ti­ve (EU) 2022/2555 and ENISA in the pre­pa­ra­ti­on of the draft dele­ga­ted act.
(10) The Com­mis­si­on may, by means of imple­men­ting acts, spe­ci­fy the for­mat and pro­ce­du­res for the noti­fi­ca­ti­ons refer­red to in this Artic­le and in Artic­les 15 and 16. Tho­se imple­men­ting acts shall be adopted in accordance with the exami­na­ti­on pro­ce­du­re refer­red to in Artic­le 62(2). The Com­mis­si­on shall coope­ra­te with the CSIRTs net­work and ENISA in the pre­pa­ra­ti­on of draft imple­men­ting acts.
Artic­le 15 Vol­un­t­a­ry declarations
(1) Manu­fac­tu­r­ers and other natu­ral or legal per­sons may vol­un­t­a­ri­ly report any vul­nerabi­li­ty con­tai­ned in a pro­duct with digi­tal ele­ments, as well as cyber thre­ats that could impact the risk pro­fi­le of a pro­duct with digi­tal ele­ments, to a CSIRT desi­gna­ted as coor­di­na­tor or to ENISA.
(2) Manu­fac­tu­r­ers and other natu­ral or legal per­sons may report, on a vol­un­t­a­ry basis, any secu­ri­ty inci­dent affec­ting the secu­ri­ty of the pro­duct with digi­tal ele­ments, as well as near-miss inci­dents that could have led to such a secu­ri­ty inci­dent, to a CSIRT desi­gna­ted as coor­di­na­tor or to ENISA.
(3) The CSIRT desi­gna­ted as coor­di­na­tor or ENISA shall pro­cess the noti­fi­ca­ti­ons refer­red to in para­graphs 1 and 2 in accordance with the pro­ce­du­re laid down in Artic­le 16.
The CSIRT appoin­ted as coor­di­na­tor can pro­cess man­da­to­ry noti­fi­ca­ti­ons with prio­ri­ty over vol­un­t­a­ry noti­fi­ca­ti­ons.
(4) Whe­re a natu­ral or legal per­son other than the manu­fac­tu­rer refer­red to in para­graph 1 or 2 reports an actively exploi­ted vul­nerabi­li­ty or a serious secu­ri­ty inci­dent affec­ting the secu­ri­ty of a pro­duct with digi­tal ele­ments, the CSIRT desi­gna­ted as coor­di­na­tor shall inform the manu­fac­tu­rer wit­hout delay.
(5) The CSIRTs desi­gna­ted as coor­di­na­tors and ENISA shall ensu­re the con­fi­den­tia­li­ty and ade­qua­te pro­tec­tion of the infor­ma­ti­on sub­mit­ted by a report­ing natu­ral or legal per­son. Wit­hout pre­ju­di­ce to the pre­ven­ti­on, inve­sti­ga­ti­on, detec­tion and pro­se­cu­ti­on of cri­mi­nal offen­ses, vol­un­t­a­ry report­ing shall not result in the impo­si­ti­on of addi­tio­nal obli­ga­ti­ons on the report­ing natu­ral or legal per­son that would not have applied to it if it had not sub­mit­ted the report.
Artic­le 16 Estab­lish­ment of a sin­gle report­ing platform
(1) For the pur­po­ses of the noti­fi­ca­ti­ons refer­red to in Artic­le 14(1) and (3) and Artic­le 15(1) and (2) and in order to sim­pli­fy the report­ing obli­ga­ti­ons of manu­fac­tu­r­ers, ENISA shall set up a sin­gle report­ing plat­form. The day-to-day ope­ra­ti­on of that sin­gle report­ing plat­form shall be mana­ged and main­tai­ned by ENISA. The archi­tec­tu­re of the sin­gle report­ing plat­form shall allow Mem­ber Sta­tes and ENISA to set up their own end­points for elec­tro­nic reporting.
(2) Upon rece­ipt of a noti­fi­ca­ti­on, the CSIRT desi­gna­ted as coor­di­na­tor that initi­al­ly recei­ves the noti­fi­ca­ti­on shall imme­dia­te­ly for­ward the noti­fi­ca­ti­on via the sin­gle noti­fi­ca­ti­on plat­form to the CSIRTs desi­gna­ted as coor­di­na­tors in who­se ter­ri­to­ry the pro­duct with digi­tal items was made available accor­ding to the manufacturer’s specifications.
In excep­tio­nal cir­cum­stances, and in par­ti­cu­lar at the request of the manu­fac­tu­rer and given the level of sen­si­ti­vi­ty of the repor­ted infor­ma­ti­on indi­ca­ted by the manu­fac­tu­rer in accordance with point (a) of Artic­le 14(2) of this Regu­la­ti­on, the dis­se­mi­na­ti­on of the noti­fi­ca­ti­on may be delay­ed for as long as strict­ly neces­sa­ry for legi­ti­ma­te rea­sons rela­ted to cyber­se­cu­ri­ty, inclu­ding whe­re a vul­nerabi­li­ty is sub­ject to a coor­di­na­ted vul­nerabi­li­ty dis­clo­sure pro­cess in accordance with Artic­le 12(1) of Direc­ti­ve (EU) 2022/2555. Whe­re a CSIRT deci­des to with­hold a noti­fi­ca­ti­on, it shall inform ENISA of the decis­i­on wit­hout undue delay and pro­vi­de both a justi­fi­ca­ti­on for with­hol­ding the noti­fi­ca­ti­on and an indi­ca­ti­on of when it will dis­se­mi­na­te the noti­fi­ca­ti­on in accordance with the pro­ce­du­re set out in this para­graph. ENISA may assist the CSIRT in the appli­ca­ti­on of cyber­se­cu­ri­ty grounds rela­ted to the delay of the dis­se­mi­na­ti­on of the noti­fi­ca­ti­on. In spe­ci­fic excep­tio­nal cir­cum­stances, whe­re the manu­fac­tu­rer indi­ca­tes the fol­lo­wing in the noti­fi­ca­ti­on refer­red to in point (b) of Artic­le 14(2):
a) that the repor­ted vul­nerabi­li­ty was actively exploi­ted by a mali­cious actor and, accor­ding to the available infor­ma­ti­on, was not exploi­ted in any Mem­ber Sta­te other than that of the CSIRT desi­gna­ted as coor­di­na­tor to which the manu­fac­tu­rer repor­ted the vulnerability;
b) that imme­dia­te fur­ther dis­clo­sure of the repor­ted vul­nerabi­li­ty would be likely to result in the pro­vi­si­on of infor­ma­ti­on the dis­clo­sure of which would be con­tra­ry to the essen­ti­al inte­rests of the Mem­ber Sta­te con­cer­ned; or
c) that the repor­ted vul­nerabi­li­ty poses an imme­dia­te high cyber­se­cu­ri­ty risk resul­ting from fur­ther propagation,
only the infor­ma­ti­on that the manu­fac­tu­rer has made a noti­fi­ca­ti­on, the gene­ral infor­ma­ti­on on the pro­duct, the infor­ma­ti­on on the gene­ral natu­re of the explo­ita­ti­on and the infor­ma­ti­on that secu­ri­ty rea­sons have been invo­ked shall be pro­vi­ded simul­ta­neous­ly to ENISA until the full noti­fi­ca­ti­on is for­ward­ed to the CSIRTs con­cer­ned and to ENISA. If, on the basis of this infor­ma­ti­on, ENISA con­siders that the­re is a syste­mic risk to the secu­ri­ty of the inter­nal mar­ket, it shall recom­mend that the CSIRT that recei­ved the noti­fi­ca­ti­on for­wards the com­ple­te noti­fi­ca­ti­on to the other CSIRTs desi­gna­ted as coor­di­na­tors and to ENISA its­elf.
(3) Upon rece­ipt of a noti­fi­ca­ti­on of an actively exploi­ted vul­nerabi­li­ty in a pro­duct with digi­tal ele­ments or of a serious secu­ri­ty inci­dent affec­ting the secu­ri­ty of a pro­duct with digi­tal ele­ments, the CSIRTs desi­gna­ted as coor­di­na­tors shall pro­vi­de the mar­ket sur­veil­lan­ce aut­ho­ri­ties of their respec­ti­ve Mem­ber Sta­te with the noti­fi­ed infor­ma­ti­on neces­sa­ry to enable them to com­ply with their obli­ga­ti­ons under this Regulation.
(4) ENISA shall take appro­pria­te and pro­por­tio­na­te tech­ni­cal, ope­ra­tio­nal and orga­nizatio­nal mea­su­res to mana­ge the risks to the secu­ri­ty of the sin­gle report­ing plat­form and the infor­ma­ti­on trans­mit­ted or dis­se­mi­na­ted through the sin­gle report­ing plat­form. It shall noti­fy the CSIRTs net­work and the Com­mis­si­on wit­hout delay of any secu­ri­ty inci­dent affec­ting the sin­gle report­ing platform.
(5) ENISA shall, in coope­ra­ti­on with the CSIRTs net­work, prepa­re and imple­ment spe­ci­fi­ca­ti­ons for the tech­ni­cal, ope­ra­tio­nal and orga­nizatio­nal mea­su­res for the estab­lish­ment, main­ten­an­ce and secu­re ope­ra­ti­on of the sin­gle report­ing plat­form refer­red to in para­graph 1, inclu­ding at least the secu­ri­ty mea­su­res rela­ted to the estab­lish­ment ope­ra­ti­on and main­ten­an­ce of the sin­gle report­ing plat­form and the elec­tro­nic report­ing end­points estab­lished by the CSIRTs desi­gna­ted as coor­di­na­tors at natio­nal level and by ENISA at Uni­on level, inclu­ding pro­ce­du­ral aspects to ensu­re that infor­ma­ti­on on tho­se vul­nerabi­li­ties is shared in accordance with strict secu­ri­ty pro­to­cols and on a need-to-know basis when cor­rec­ti­ve or miti­ga­ting mea­su­res are not available for a repor­ted vulnerability.
(6) Whe­re a CSIRT desi­gna­ted as coor­di­na­tor has been made awa­re of an actively exploi­ted vul­nerabi­li­ty in the con­text of a coor­di­na­ted vul­nerabi­li­ty dis­clo­sure pro­cess in accordance with Artic­le 12(1) of Direc­ti­ve (EU) 2022/2555, the CSIRT desi­gna­ted as coor­di­na­tor that initi­al­ly recei­ved the noti­fi­ca­ti­on may, for legi­ti­ma­te rea­sons rela­ted to cyber­se­cu­ri­ty, post­po­ne the dis­se­mi­na­ti­on of the noti­fi­ca­ti­on con­cer­ned through the sin­gle noti­fi­ca­ti­on plat­form for a peri­od no lon­ger than strict­ly neces­sa­ry until the par­ties invol­ved in the coor­di­na­ted vul­nerabi­li­ty dis­clo­sure have given their con­sent to the dis­clo­sure. This requi­re­ment shall not pre­vent manu­fac­tu­r­ers from vol­un­t­a­ri­ly report­ing such a vul­nerabi­li­ty in accordance with the pro­ce­du­re set out in this Article.
Artic­le 17 Other pro­vi­si­ons rela­ting to reporting
(1) ENISA may share with the Euro­pean Cyber Cri­sis Liai­son Orga­nizati­ons Net­work (EU-CyCLO­Ne) estab­lished by Artic­le 16 of Direc­ti­ve (EU) 2022/2555 the infor­ma­ti­on repor­ted in accordance with Artic­le 14(1) and (3) and Artic­le 15(1) and (2) of this Regu­la­ti­on, whe­re such infor­ma­ti­on is rele­vant for the coor­di­na­ted manage­ment of mas­si­ve cyber­se­cu­ri­ty inci­dents and cri­ses at ope­ra­tio­nal level. For the pur­po­ses of deter­mi­ning such rele­van­ce, ENISA may take into account tech­ni­cal ana­ly­sis of the CSIRTs net­work, whe­re appropriate.
(2) Whe­re public awa­re­ness is neces­sa­ry to pre­vent or miti­ga­te a serious secu­ri­ty inci­dent affec­ting the secu­ri­ty of the device with digi­tal ele­ments or to mana­ge an ongo­ing secu­ri­ty inci­dent, or whe­re dis­clo­sure of the secu­ri­ty inci­dent is other­wi­se in the public inte­rest, the CSIRT desi­gna­ted as coor­di­na­tor of the Mem­ber Sta­te con­cer­ned may, after con­sul­ting the manu­fac­tu­rer con­cer­ned and, whe­re appro­pria­te, in coope­ra­ti­on with ENISA, inform the public about the secu­ri­ty inci­dent or request the manu­fac­tu­rer to do so.
(3) ENISA shall, on the basis of the noti­fi­ca­ti­ons recei­ved in accordance with Artic­le 14(1) and (3) and Artic­le 15(1) and (2) of this Regu­la­ti­on, prepa­re a tech­ni­cal report every 24 months on emer­ging trends in cyber­se­cu­ri­ty risks of pro­ducts with digi­tal ele­ments and sub­mit it to the Coope­ra­ti­on Group estab­lished in accordance with Artic­le 14 of Direc­ti­ve (EU) 2022/2555. The first such report shall be sub­mit­ted within 24 months of the date of appli­ca­ti­on of the obli­ga­ti­ons laid down in Artic­le 14(1) and (3). ENISA shall include rele­vant infor­ma­ti­on from its tech­ni­cal reports in its report on the sta­te of cyber­se­cu­ri­ty in the Uni­on pur­su­ant to Artic­le 18 of Direc­ti­ve (EU) 2022/2555.
(4) The mere noti­fi­ca­ti­on pur­su­ant to Artic­le 14(1) and (3) and Artic­le 15(1) and (2) shall not increa­se the lia­bi­li­ty of the noti­fy­ing natu­ral or legal person.
(5) As soon as a secu­ri­ty update or other form of cor­rec­ti­ve or miti­ga­ting action is available, ENISA shall, in agree­ment with the manu­fac­tu­rer of the digi­tal device con­cer­ned, include the publicly known vul­nerabi­li­ty repor­ted in accordance with Artic­le 14(1) or Artic­le 15(1) of this Regu­la­ti­on in the Euro­pean vul­nerabi­li­ty data­ba­se estab­lished in accordance with Artic­le 12(2) of Direc­ti­ve (EU) 2022/2555.
(6) The CSIRTs desi­gna­ted as coor­di­na­tors shall pro­vi­de help­desk sup­port to manu­fac­tu­r­ers, and in par­ti­cu­lar manu­fac­tu­r­ers that are con­side­red to be micro, small or medi­um-sized enter­pri­ses, in rela­ti­on to the report­ing obli­ga­ti­ons under Artic­le 14.
Artic­le 18 Aut­ho­ri­zed representatives
(1) A manu­fac­tu­rer may appoint an aut­ho­ri­zed repre­sen­ta­ti­ve in writing.
(2) The obli­ga­ti­ons laid down in Artic­le 13(1) to (11), the first sub­pa­ra­graph of Artic­le 13(12) and Artic­le 13(14) shall not form part of the aut­ho­ri­zed representative’s mandate.
(3) An aut­ho­ri­zed repre­sen­ta­ti­ve shall per­form the tasks spe­ci­fi­ed in the man­da­te issued by the manu­fac­tu­rer. The aut­ho­ri­zed repre­sen­ta­ti­ve shall pro­vi­de a copy of the man­da­te to the mar­ket sur­veil­lan­ce aut­ho­ri­ties upon request. The man­da­te shall enable the aut­ho­ri­zed repre­sen­ta­ti­ve to per­form at least the fol­lo­wing tasks:
a) Keep the EU decla­ra­ti­on of con­for­mi­ty refer­red to in Artic­le 28 and the tech­ni­cal docu­men­ta­ti­on refer­red to in Artic­le 31 at the dis­po­sal of mar­ket sur­veil­lan­ce aut­ho­ri­ties for at least 10 years from the date on which the pro­duct with digi­tal ele­ments is pla­ced on the mar­ket or for the sup­port peri­od, whi­che­ver is the longer;
b) Trans­mis­si­on of all infor­ma­ti­on and docu­ments neces­sa­ry to demon­stra­te the con­for­mi­ty of the pro­duct with digi­tal ele­ments to a mar­ket sur­veil­lan­ce aut­ho­ri­ty upon its rea­so­ned request;
c) Coope­ra­te with mar­ket sur­veil­lan­ce aut­ho­ri­ties, at their request, on any action taken to eli­mi­na­te the risks posed by a pro­duct with digi­tal ele­ments fal­ling within the scope of the aut­ho­ri­zed representative’s tasks.
Artic­le 19 Obli­ga­ti­ons of importers
(1) Importers shall only place on the mar­ket devices incor­po­ra­ting digi­tal ele­ments which meet the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part I of Annex I and for which the pro­ce­du­res defi­ned by the manu­fac­tu­rer meet the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part II of Annex I.
(2) Befo­re pla­cing a pro­duct with digi­tal ele­ments on the mar­ket, importers shall ensu­re that
a) the manu­fac­tu­rer has car­ri­ed out the appro­pria­te con­for­mi­ty assess­ment pro­ce­du­res refer­red to in Artic­le 32;
b) the manu­fac­tu­rer has pre­pared the tech­ni­cal documentation;
c) the pro­duct with digi­tal ele­ments bears the CE mar­king refer­red to in Artic­le 30 and is accom­pa­nied by the EU decla­ra­ti­on of con­for­mi­ty refer­red to in Artic­le 13(20) and by the infor­ma­ti­on and ins­truc­tions for users set out in Annex II in a lan­guage which can be easi­ly under­s­tood by users and mar­ket sur­veil­lan­ce authorities;
d) the manu­fac­tu­rer com­plies with the requi­re­ments set out in Artic­le 13(15), (16) and (19).
For the pur­po­ses of this para­graph, importers shall be able to pro­vi­de the docu­men­ta­ti­on neces­sa­ry to demon­stra­te com­pli­ance with the requi­re­ments laid down in this Artic­le.
(3) Whe­re an importer con­siders or has rea­son to belie­ve that a device incor­po­ra­ting digi­tal ele­ments or the pro­ce­du­res laid down by the manu­fac­tu­rer are not in con­for­mi­ty with this Regu­la­ti­on, he shall not place the device on the mar­ket until it and the pro­ce­du­res laid down by the manu­fac­tu­rer have been brought into con­for­mi­ty with this Regu­la­ti­on. Fur­ther­mo­re, whe­re the device incor­po­ra­ting digi­tal ele­ments pres­ents a signi­fi­cant cyber­se­cu­ri­ty risk, the importer shall inform the manu­fac­tu­rer and the mar­ket sur­veil­lan­ce aut­ho­ri­ties to that effect.
Whe­re an importer has rea­son to belie­ve that a pro­duct with digi­tal ele­ments could pose a signi­fi­cant cyber­se­cu­ri­ty risk due to non-tech­ni­cal risk fac­tors, he shall inform the mar­ket sur­veil­lan­ce aut­ho­ri­ties. Upon rece­ipt of this infor­ma­ti­on, the mar­ket sur­veil­lan­ce aut­ho­ri­ties shall fol­low the pro­ce­du­res refer­red to in Artic­le 54(2).
(4) Importers shall indi­ca­te their name, regi­stered trade name or regi­stered trade mark, postal address, e‑mail address or other means of digi­tal cont­act and, whe­re appli­ca­ble, the web­site whe­re they can be cont­ac­ted, eit­her on the pro­duct with digi­tal ele­ments its­elf or on its pack­a­ging, or in a docu­ment accom­pany­ing the pro­duct with digi­tal ele­ments. The cont­act details shall be in a lan­guage that can be easi­ly under­s­tood by users and mar­ket sur­veil­lan­ce authorities.
(5) Importers who know or have rea­son to belie­ve that a pro­duct with digi­tal ele­ments which they have pla­ced on the mar­ket is not in con­for­mi­ty with this Regu­la­ti­on shall imme­dia­te­ly take the neces­sa­ry cor­rec­ti­ve action to bring that pro­duct with digi­tal ele­ments into con­for­mi­ty with this Regu­la­ti­on or, if appro­pria­te, to with­draw the pro­duct from the mar­ket or recall it.
Importers shall, as soon as they beco­me awa­re of a vul­nerabi­li­ty in the pro­duct with digi­tal ele­ments, imme­dia­te­ly inform the manu­fac­tu­rer of that vul­nerabi­li­ty. Fur­ther­mo­re, whe­re the pro­duct with digi­tal ele­ments pres­ents a signi­fi­cant cyber­se­cu­ri­ty risk, importers shall imme­dia­te­ly inform the mar­ket sur­veil­lan­ce aut­ho­ri­ties of the Mem­ber Sta­tes in which they made the pro­duct with digi­tal ele­ments available on the mar­ket, giving details, in par­ti­cu­lar, of the non-com­pli­ance and of any cor­rec­ti­ve action taken.
(6) Importers shall, for a peri­od ending at least 10 years after the pro­duct with digi­tal ele­ments has been pla­ced on the mar­ket or for the sup­port peri­od, whi­che­ver is the lon­ger, keep a copy of the EU decla­ra­ti­on of con­for­mi­ty at the dis­po­sal of the mar­ket sur­veil­lan­ce aut­ho­ri­ties and ensu­re that they are able to pre­sent the tech­ni­cal docu­men­ta­ti­on to tho­se aut­ho­ri­ties, upon request.
(7) Importers shall, fur­ther to a rea­so­ned request from a mar­ket sur­veil­lan­ce aut­ho­ri­ty, pro­vi­de it with all the infor­ma­ti­on and docu­men­ta­ti­on in paper or elec­tro­nic form in a lan­guage which can be easi­ly under­s­tood by that aut­ho­ri­ty, neces­sa­ry to demon­stra­te the con­for­mi­ty of the pro­duct with digi­tal ele­ments with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part I of Annex I and of the pro­ce­du­res set out by the manu­fac­tu­rer with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part II of Annex I. They shall coope­ra­te with that aut­ho­ri­ty, at its request, on any action taken to address the cyber­se­cu­ri­ty risks posed by a device with digi­tal ele­ments that they have pla­ced on the market.
(8) Whe­re the importer of a device incor­po­ra­ting digi­tal ele­ments beco­mes awa­re that the manu­fac­tu­rer of that device has cea­sed its busi­ness acti­vi­ties and is con­se­quent­ly unable to ful­fil the obli­ga­ti­ons laid down in this Regu­la­ti­on, he shall inform the rele­vant mar­ket sur­veil­lan­ce aut­ho­ri­ties and, by any available means and as far as pos­si­ble, the users of the devices incor­po­ra­ting digi­tal ele­ments pla­ced on the mar­ket to that effect.
Artic­le 20 Obli­ga­ti­ons of traders
(1) When making a pro­duct with digi­tal ele­ments available on the mar­ket, trad­ers shall com­ply with the pro­vi­si­ons of this Regu­la­ti­on with due care.
(2) Befo­re making a pro­duct with digi­tal ele­ments available on the mar­ket, retail­ers check whether
a) the pro­duct is pro­vi­ded with digi­tal ele­ments with the CE marking;
b) the manu­fac­tu­rer and the importer have com­plied with the requi­re­ments of Artic­le 13(15), (16), (18), (19) and (20) and Artic­le 19(4) and have pro­vi­ded the dis­tri­bu­tor with all neces­sa­ry documents.
(3) Whe­re a dis­tri­bu­tor con­siders or has rea­son to belie­ve, on the basis of the infor­ma­ti­on available to it, that a device incor­po­ra­ting digi­tal ele­ments or the pro­ce­du­res estab­lished by the manu­fac­tu­rer do not com­ply with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I, it shall not make the device incor­po­ra­ting digi­tal ele­ments available on the mar­ket until that device and the pro­ce­du­res estab­lished by the manu­fac­tu­rer have been brought into con­for­mi­ty with this Regu­la­ti­on. Fur­ther­mo­re, whe­re the pro­duct with digi­tal ele­ments pres­ents a signi­fi­cant cyber­se­cu­ri­ty risk, the dis­tri­bu­tor shall imme­dia­te­ly inform the manu­fac­tu­rer and the mar­ket sur­veil­lan­ce aut­ho­ri­ties thereof.
(4) Dis­tri­bu­tors who know or have rea­son to belie­ve, on the basis of infor­ma­ti­on available to them, that a pro­duct with digi­tal ele­ments which they have made available on the mar­ket or the pro­ce­du­res estab­lished by its manu­fac­tu­rer are not in con­for­mi­ty with this Regu­la­ti­on shall ensu­re that the neces­sa­ry cor­rec­ti­ve action is taken to bring that pro­duct with digi­tal ele­ments into con­for­mi­ty with the pro­ce­du­res estab­lished by the manu­fac­tu­rer or, if appro­pria­te, to with­draw the pro­duct from the mar­ket or recall it.
As soon as dis­tri­bu­tors beco­me awa­re of a vul­nerabi­li­ty in the pro­duct with digi­tal ele­ments, they shall imme­dia­te­ly inform the manu­fac­tu­rer of that vul­nerabi­li­ty. Whe­re the pro­duct with digi­tal ele­ments pres­ents a signi­fi­cant cyber­se­cu­ri­ty risk, dis­tri­bu­tors shall also imme­dia­te­ly inform the mar­ket sur­veil­lan­ce aut­ho­ri­ties of the Mem­ber Sta­tes in which they made the pro­duct with digi­tal ele­ments available on the mar­ket, giving details, in par­ti­cu­lar, of the non-com­pli­ance and of any cor­rec­ti­ve action taken.
(5) Dis­tri­bu­tors shall, fur­ther to a rea­so­ned request from a mar­ket sur­veil­lan­ce aut­ho­ri­ty, pro­vi­de it with all the infor­ma­ti­on and docu­men­ta­ti­on neces­sa­ry to demon­stra­te the con­for­mi­ty of the pro­duct with digi­tal ele­ments and with the pro­ce­du­res laid down in this Regu­la­ti­on by the manu­fac­tu­rer, in paper or elec­tro­nic form in a lan­guage which can be easi­ly under­s­tood by that aut­ho­ri­ty. They shall coope­ra­te with that aut­ho­ri­ty, at its request, on any action taken to address the cyber­se­cu­ri­ty risks posed by a device with digi­tal ele­ments which they have made available on the market.
(6) Whe­re the dis­tri­bu­tor of a device incor­po­ra­ting digi­tal ele­ments beco­mes awa­re, on the basis of the infor­ma­ti­on available to him, that the manu­fac­tu­rer of that device has cea­sed its busi­ness acti­vi­ties and is con­se­quent­ly unable to ful­fil the obli­ga­ti­ons laid down in this Regu­la­ti­on, he shall imme­dia­te­ly inform the rele­vant mar­ket sur­veil­lan­ce aut­ho­ri­ties and, by any available means and as far as pos­si­ble, the users of the devices incor­po­ra­ting digi­tal ele­ments pla­ced on the mar­ket to that effect.
Artic­le 21 Cases whe­re the obli­ga­ti­ons of pro­du­cers also app­ly to importers and distributors
An importer or dis­tri­bu­tor shall be con­side­red a manu­fac­tu­rer for the pur­po­ses of this Regu­la­ti­on and shall be sub­ject to the obli­ga­ti­ons set out in Artic­les 13 and 14 whe­re that importer or dis­tri­bu­tor places a pro­duct incor­po­ra­ting digi­tal ele­ments on the mar­ket under his own name or trade­mark or makes a sub­stan­ti­al modi­fi­ca­ti­on to a pro­duct incor­po­ra­ting digi­tal ele­ments that has alre­a­dy been pla­ced on the market. 
Artic­le 22 Other cases whe­re pro­du­cers’ obli­ga­ti­ons apply
(1) A natu­ral or legal per­son, other than the manu­fac­tu­rer, importer or dis­tri­bu­tor, who makes a sub­stan­ti­al modi­fi­ca­ti­on to the pro­duct incor­po­ra­ting digi­tal ele­ments and makes that pro­duct available on the mar­ket shall be con­side­red a manu­fac­tu­rer for the pur­po­ses of this Regulation.
(2) The per­son refer­red to in para­graph 1 of this Artic­le shall be sub­ject to the obli­ga­ti­ons laid down in Artic­les 13 and 14 for the part of the pro­duct with digi­tal ele­ments affec­ted by the sub­stan­ti­al modi­fi­ca­ti­on or, whe­re the sub­stan­ti­al modi­fi­ca­ti­on affects the cyber­se­cu­ri­ty of the pro­duct with digi­tal ele­ments as a who­le, for the enti­re product.
Artic­le 23 Iden­ti­fi­ca­ti­on of eco­no­mic operators
(1) Eco­no­mic ope­ra­tors shall pro­vi­de the mar­ket sur­veil­lan­ce aut­ho­ri­ties with the fol­lo­wing infor­ma­ti­on on request:
a) Name and address of all eco­no­mic ope­ra­tors from whom they have purcha­sed pro­ducts with digi­tal elements,
b) whe­re available, the name and address of all eco­no­mic ope­ra­tors to whom they have sup­plied pro­ducts with digi­tal elements.
(2) Eco­no­mic ope­ra­tors shall be able to pro­vi­de the infor­ma­ti­on refer­red to in para­graph 1 ten years after the purcha­se of the pro­duct with digi­tal ele­ments and ten years after the sup­p­ly of the pro­duct with digi­tal elements.
Artic­le 24 Obli­ga­ti­ons of admi­ni­stra­tors of open source software
(1) Mana­gers of open source soft­ware shall deve­lop and docu­ment in a veri­fia­ble man­ner a cyber­se­cu­ri­ty poli­cy to pro­mo­te the deve­lo­p­ment of a secu­re pro­duct with digi­tal ele­ments and the effec­ti­ve manage­ment of vul­nerabi­li­ties by the deve­lo­pers of that pro­duct. That poli­cy shall also encou­ra­ge the vol­un­t­a­ry report­ing of vul­nerabi­li­ties by the deve­lo­pers of that pro­duct in accordance with Artic­le 15 and shall take into account the spe­ci­fi­ci­ties of the mana­ger of open source soft­ware and the legal and orga­nizatio­nal arran­ge­ments to which it is sub­ject. In par­ti­cu­lar, this poli­cy shall cover aspects rela­ted to the docu­men­ta­ti­on, reme­dia­ti­on and eli­mi­na­ti­on of vul­nerabi­li­ties and shall encou­ra­ge the sha­ring of infor­ma­ti­on on vul­nerabi­li­ties dis­co­ver­ed within the open source community.
(2) Admi­ni­stra­tors of open source soft­ware will work with mar­ket sur­veil­lan­ce aut­ho­ri­ties, at their request, to miti­ga­te the cyber­se­cu­ri­ty risks posed by a pro­duct with digi­tal ele­ments that qua­li­fi­es as free and open source software.
At the rea­so­ned request of a mar­ket sur­veil­lan­ce aut­ho­ri­ty, admi­ni­stra­tors of open source soft­ware shall sub­mit to that aut­ho­ri­ty, in a lan­guage easi­ly under­s­tood by that aut­ho­ri­ty, the docu­men­ta­ti­on refer­red to in para­graph 1 in paper or elec­tro­nic form.
(3) The obli­ga­ti­ons set out in Artic­le 14(1) shall app­ly to mana­gers of open source soft­ware to the ext­ent that they are invol­ved in the deve­lo­p­ment of the pro­ducts incor­po­ra­ting digi­tal items. The obli­ga­ti­ons laid down in Artic­le 14(3) and (8) shall app­ly to mana­gers of open source soft­ware to the ext­ent that serious secu­ri­ty inci­dents affec­ting the secu­ri­ty of pro­ducts incor­po­ra­ting digi­tal items affect net­work and infor­ma­ti­on systems pro­vi­ded by the mana­gers of open source soft­ware for the deve­lo­p­ment of such products.
Artic­le 25 Secu­ri­ty cer­ti­fi­ca­ti­on for free and open source software
In order to faci­li­ta­te the due dili­gence obli­ga­ti­on set out in Artic­le 13(5), in par­ti­cu­lar with regard to manu­fac­tu­r­ers that incor­po­ra­te free and open source soft­ware com­pon­ents into their digi­tal-enab­led pro­ducts, the Com­mis­si­on shall be empowered to adopt dele­ga­ted acts in accordance with Artic­le 61 to sup­ple­ment this Regu­la­ti­on by intro­du­cing vol­un­t­a­ry secu­ri­ty atte­sta­ti­on sche­mes that allow deve­lo­pers or users of digi­tal-enab­led pro­ducts that qua­li­fy as free and open source soft­ware, and other third par­ties, to assess the com­pli­ance of tho­se pro­ducts with all or cer­tain essen­ti­al cyber­se­cu­ri­ty requi­re­ments or other obli­ga­ti­ons laid down in this Regulation. 
Artic­le 26 Guidelines
(1) In order to faci­li­ta­te imple­men­ta­ti­on and ensu­re con­si­sten­cy, the Com­mis­si­on shall publish gui­de­lines to assist eco­no­mic ope­ra­tors in the appli­ca­ti­on of this Regu­la­ti­on, with a par­ti­cu­lar focus on faci­li­ta­ting com­pli­ance by micro, small and medi­um-sized enterprises.
(2) Whe­re the Com­mis­si­on intends to pro­vi­de gui­dance in accordance with para­graph 1, it shall address at least the fol­lo­wing aspects:
a) the scope of this Regu­la­ti­on, with a par­ti­cu­lar focus on remo­te com­pu­ting solu­ti­ons and free and open source software,
b) the appli­ca­ti­on of sup­port peri­ods in rela­ti­on to cer­tain cate­go­ries of pro­ducts with digi­tal elements;
c) Gui­de­lines for manu­fac­tu­r­ers sub­ject to this Regu­la­ti­on who are also sub­ject to Uni­on har­mo­nizati­on legis­la­ti­on other than this Regu­la­ti­on or other rela­ted Uni­on acts;
d) the term “mate­ri­al change”.
The Com­mis­si­on shall also keep an easi­ly acce­s­si­ble list of dele­ga­ted and imple­men­ting acts adopted pur­su­ant to this Regu­la­ti­on.
(3) The Com­mis­si­on shall con­sult the rele­vant stake­hol­ders when dra­wing up the gui­de­lines refer­red to in this Article.

Chap­ter III Con­for­mi­ty of the pro­duct with digi­tal elements 

Artic­le 27 Pre­sump­ti­on of conformity
(1) Devices incor­po­ra­ting digi­tal ele­ments and pro­ce­du­res defi­ned by the manu­fac­tu­rer which are in con­for­mi­ty with har­mo­ni­zed stan­dards or parts the­reof the refe­ren­ces of which have been published in the Offi­ci­al Jour­nal of the Euro­pean Uni­on shall be pre­su­med to be in con­for­mi­ty with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I in so far as tho­se requi­re­ments are cover­ed by tho­se stan­dards or parts thereof.
The Com­mis­si­on shall, in accordance with Artic­le 10(1) of Regu­la­ti­on (EU) No 1025/2012, request one or more Euro­pean stan­dar­dizati­on orga­ni­sa­ti­ons to deve­lop har­mo­ni­zed stan­dards for the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I to this Regu­la­ti­on. When pre­pa­ring stan­dar­dizati­on requests for this Regu­la­ti­on, the Com­mis­si­on shall endea­vour to take into account exi­sting Euro­pean and inter­na­tio­nal cyber­se­cu­ri­ty stan­dards that are in force or under deve­lo­p­ment in order to faci­li­ta­te the deve­lo­p­ment of har­mo­ni­zed stan­dards in accordance with Regu­la­ti­on (EU) No 1025/2012.
(2) The Com­mis­si­on may adopt imple­men­ting acts lay­ing down com­mon spe­ci­fi­ca­ti­ons of tech­ni­cal requi­re­ments, com­pli­ance with which shall enable the ful­film­ent of the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I for pro­ducts with digi­tal ele­ments within the scope of this Regulation.
The­se imple­men­ting acts may only be adopted if the fol­lo­wing con­di­ti­ons are met:
a) the Com­mis­si­on has reque­sted, in accordance with Artic­le 10(1) of Regu­la­ti­on (EU) No 1025/2012, one or more Euro­pean stan­dar­dizati­on orga­nizati­ons to deve­lop a har­mo­ni­zed stan­dard for the essen­ti­al cyber­se­cu­ri­ty requi­re­ments listed in Annex I; and:
i) the order was not accepted,
ii) the har­mo­ni­zed stan­dards to which this request rela­tes are not deli­ver­ed within the time limit set in accordance with Artic­le 10(1) of Regu­la­ti­on (EU) No 1025/2012, or
iii) the har­mo­ni­zed stan­dards do not com­ply with the man­da­te, and
b) no refe­rence has been published in the Offi­ci­al Jour­nal of the Euro­pean Uni­on in accordance with Regu­la­ti­on (EU) No 1025/2012 to har­mo­ni­zed stan­dards that meet the rele­vant essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I to this Regu­la­ti­on, and no such refe­rence is expec­ted to be published within a rea­sonable peri­od of time.
Tho­se imple­men­ting acts shall be adopted in accordance with the exami­na­ti­on pro­ce­du­re refer­red to in Artic­le 62(2).
(3) Befo­re pre­pa­ring a draft imple­men­ting act refer­red to in para­graph 2 of this Artic­le, the Com­mis­si­on shall noti­fy the Com­mit­tee refer­red to in Artic­le 22 of Regu­la­ti­on (EU) No 1025/2012 that it con­siders the con­di­ti­ons refer­red to in para­graph 2 of this Artic­le to be met.
(4) When pre­pa­ring a draft imple­men­ting act refer­red to in para­graph 2, the Com­mis­si­on shall take into account the views of the rele­vant bodies and duly con­sult all rele­vant stakeholders.
(5) Devices with digi­tal ele­ments and pro­ce­du­res defi­ned by the manu­fac­tu­rer that com­ply with the com­mon spe­ci­fi­ca­ti­ons estab­lished by the imple­men­ting act refer­red to in para­graph 2 of this Artic­le shall be pre­su­med to com­ply with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I to the ext­ent that the com­mon spe­ci­fi­ca­ti­ons or parts the­reof cover tho­se requirements.
(6) Whe­re a har­mo­ni­zed stan­dard is adopted by a Euro­pean stan­dar­dizati­on orga­ni­sa­ti­on and pro­po­sed to the Com­mis­si­on for publi­ca­ti­on of its refe­rence in the Offi­ci­al Jour­nal of the Euro­pean Uni­on, the Com­mis­si­on shall assess that har­mo­ni­zed stan­dard in accordance with Regu­la­ti­on (EU) No 1025/2012. When a refe­rence of a har­mo­ni­zed stan­dard is published in the Offi­ci­al Jour­nal of the Euro­pean Uni­on, the Com­mis­si­on shall repeal the imple­men­ting acts refer­red to in para­graph 2 of this Artic­le, or parts the­reof, which regu­la­te the same essen­ti­al cyber­se­cu­ri­ty requi­re­ments as the har­mo­ni­zed standard.
(7) Whe­re a Mem­ber Sta­te con­siders that a com­mon spe­ci­fi­ca­ti­on does not ful­ly meet the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I, it shall inform the Com­mis­si­on the­reof by means of a detail­ed expl­ana­ti­on. The Com­mis­si­on shall assess the detail­ed expl­ana­ti­on and may, whe­re appro­pria­te, amend the imple­men­ting act that estab­lished the com­mon spe­ci­fi­ca­ti­on concerned.
(8) Devices with digi­tal ele­ments and pro­ce­du­res defi­ned by the manu­fac­tu­rer for which an EU decla­ra­ti­on of con­for­mi­ty or a cyber­se­cu­ri­ty cer­ti­fi­ca­te has been issued under a Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­me adopted in accordance with Regu­la­ti­on (EU) 2019/881 shall be pre­su­med to be in con­for­mi­ty with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I, pro­vi­ded that the EU decla­ra­ti­on of con­for­mi­ty or the Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­te or parts the­reof cover tho­se requirements.
(9) The Com­mis­si­on shall be empowered to adopt dele­ga­ted acts in accordance with Artic­le 61 to sup­ple­ment this Regu­la­ti­on by desi­gna­ting the Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­mes adopted pur­su­ant to Regu­la­ti­on (EU) 2019/881 that may be used to demon­stra­te the com­pli­ance of devices with digi­tal ele­ments with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I or parts the­reof. In addi­ti­on, the issu­an­ce of a Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­te issued under such a sche­me at a level of assu­rance of at least ‘medi­um’ shall remo­ve the obli­ga­ti­on for the manu­fac­tu­rer to have a third par­ty con­for­mi­ty assess­ment car­ri­ed out for the requi­re­ments con­cer­ned, as pro­vi­ded for in Artic­le 32(2)(a) and (b) and Artic­le 32(3)(a) and (b).
Artic­le 28 EU Decla­ra­ti­on of Conformity
(1) The EU decla­ra­ti­on of con­for­mi­ty shall be drawn up by the manu­fac­tu­rer in accordance with Artic­le 13(12) and shall sta­te that com­pli­ance with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I has been demonstrated.
(2) The EU decla­ra­ti­on of con­for­mi­ty shall have the model struc­tu­re set out in Annex V and shall con­tain the ele­ments spe­ci­fi­ed in the rele­vant con­for­mi­ty assess­ment pro­ce­du­res set out in Annex VIII. Such a decla­ra­ti­on shall be updated as neces­sa­ry. It shall be drawn up in the lan­guages requi­red by the Mem­ber Sta­te in which the pro­duct with digi­tal ele­ments is pla­ced or made available on the market.
The sim­pli­fi­ed EU decla­ra­ti­on of con­for­mi­ty refer­red to in Artic­le 13(20) shall have the same struc­tu­re as the model set out in Annex VI and shall be drawn up in the lan­guages requi­red by the Mem­ber Sta­te in which the device with digi­tal ele­ments is pla­ced or made available on the mar­ket.
(3) Whe­re a pro­duct with digi­tal ele­ments is sub­ject to more than one Uni­on act requi­ring an EU decla­ra­ti­on of con­for­mi­ty, a sin­gle EU decla­ra­ti­on of con­for­mi­ty shall be drawn up in respect of all such Uni­on acts. This decla­ra­ti­on shall indi­ca­te the rele­vant Uni­on acts and their refe­ren­ces in the Offi­ci­al Journal.
(4) By issuing the EU Decla­ra­ti­on of Con­for­mi­ty, the manu­fac­tu­rer assu­mes respon­si­bi­li­ty for the con­for­mi­ty of the pro­duct with digi­tal elements.
(5) The Com­mis­si­on shall be empowered to adopt dele­ga­ted acts in accordance with Artic­le 61 to sup­ple­ment this Regu­la­ti­on in order to add new ele­ments to the mini­mum con­tent of the EU decla­ra­ti­on of con­for­mi­ty set out in Annex V in the light of tech­ni­cal developments.
Artic­le 29 Gene­ral prin­ci­ples of the CE marking
The gene­ral prin­ci­ples set out in Artic­le 30 of Regu­la­ti­on (EC) No 765/2008 app­ly to the CE marking. 
Artic­le 30 Rules and con­di­ti­ons for affixing the CE marking
(1) The CE mar­king shall be affi­xed visi­bly, legi­bly and inde­li­bly to the device with digi­tal ele­ments. Whe­re the natu­re of the device incor­po­ra­ting digi­tal ele­ments does not allow or does not justi­fy it, the CE mar­king shall be affi­xed to the pack­a­ging and to the EU decla­ra­ti­on of con­for­mi­ty refer­red to in Artic­le 28 accom­pany­ing the device incor­po­ra­ting digi­tal ele­ments. For pro­ducts with digi­tal ele­ments in the form of soft­ware, the CE mar­king shall be affi­xed eit­her on the EU decla­ra­ti­on of con­for­mi­ty refer­red to in Artic­le 28 or on the web­site accom­pany­ing the soft­ware pro­duct. In the lat­ter case, the rele­vant sec­tion of the web­site shall be easi­ly and direct­ly acce­s­si­ble to consumers.
(2) Due to the natu­re of the pro­duct with digi­tal ele­ments, the height of the CE mar­king affi­xed to it may be less than 5 mm, pro­vi­ded that it is still visi­ble and legible.
(3) The CE mar­king shall be affi­xed with digi­tal ele­ments befo­re the pro­duct is pla­ced on the mar­ket. It may be fol­lo­wed by a pic­to­gram or any other mark indi­ca­ting a spe­ci­fic cyber­se­cu­ri­ty risk or use to be spe­ci­fi­ed in the imple­men­ting acts refer­red to in para­graph 6.
(4) The CE mar­king shall be fol­lo­wed by the iden­ti­fi­ca­ti­on num­ber of the noti­fi­ed body whe­re the noti­fi­ed body is invol­ved in the con­for­mi­ty assess­ment pro­ce­du­re based on full qua­li­ty assu­rance (based on modu­le H) in accordance with Artic­le 32.
The iden­ti­fi­ca­ti­on num­ber of the noti­fi­ed body shall be affi­xed eit­her by the body its­elf or, under its ins­truc­tions, by the manu­fac­tu­rer or his aut­ho­ri­zed repre­sen­ta­ti­ve.
(5) Mem­ber Sta­tes shall build upon exi­sting mecha­nisms to ensu­re pro­per imple­men­ta­ti­on of the CE mar­king system and shall take appro­pria­te action in the event of impro­per use of that mar­king. Whe­re the pro­duct with digi­tal ele­ments is also cover­ed by Uni­on har­mo­nizati­on legis­la­ti­on other than this Regu­la­ti­on which also pro­vi­des for the CE mar­king, the CE mar­king shall indi­ca­te that the pro­duct also com­plies with the requi­re­ments of such other Uni­on har­mo­nizati­on legislation.
(6) The Com­mis­si­on may, by means of imple­men­ting acts, lay down tech­ni­cal spe­ci­fi­ca­ti­ons for labels, pic­to­grams or other marks rela­ting to the safe­ty of pro­ducts with digi­tal ele­ments, their sup­port peri­ods and mecha­nisms to pro­mo­te their use and to rai­se public awa­re­ness of the safe­ty of pro­ducts with digi­tal ele­ments. When pre­pa­ring the draft imple­men­ting acts, the Com­mis­si­on shall con­sult the rele­vant stake­hol­ders and, whe­re it has alre­a­dy been estab­lished in accordance with Artic­le 52(15), ADCO. Tho­se imple­men­ting acts shall be adopted in accordance with the exami­na­ti­on pro­ce­du­re refer­red to in Artic­le 62(2).
Artic­le 31 Tech­ni­cal documentation
(1) The tech­ni­cal docu­men­ta­ti­on shall con­tain all rele­vant data or details on how the manu­fac­tu­rer ensu­res that the device with digi­tal ele­ments and the pro­ce­du­res defi­ned by the manu­fac­tu­rer meet the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I. It shall con­tain at least the infor­ma­ti­on set out in Annex VII.
(2) The tech­ni­cal docu­men­ta­ti­on is crea­ted with digi­tal ele­ments befo­re the pro­duct is pla­ced on the mar­ket and, if neces­sa­ry, updated con­ti­nuous­ly, at least during the sup­port period.
(3) For devices with digi­tal ele­ments refer­red to in Artic­le 12 which are also sub­ject to other Uni­on acts pro­vi­ding for tech­ni­cal docu­men­ta­ti­on, a sin­gle tech­ni­cal docu­men­ta­ti­on shall be drawn up con­tai­ning the infor­ma­ti­on refer­red to in Annex VII and the infor­ma­ti­on requi­red by the other Uni­on acts.
(4) The tech­ni­cal docu­men­ta­ti­on and cor­re­spon­dence rela­ting to the con­for­mi­ty assess­ment pro­ce­du­res shall be drawn up in an offi­ci­al lan­guage of the Mem­ber Sta­te in which the noti­fi­ed body is estab­lished or in a lan­guage accept­ed by that body.
(5) The Com­mis­si­on shall be empowered to adopt dele­ga­ted acts in accordance with Artic­le 61 sup­ple­men­ting this Regu­la­ti­on by adding ele­ments to be inclu­ded in the tech­ni­cal docu­men­ta­ti­on refer­red to in Annex VII in order to take account of tech­ni­cal deve­lo­p­ments and deve­lo­p­ments in the imple­men­ta­ti­on of this Regu­la­ti­on. To that end, the Com­mis­si­on shall endea­vor to ensu­re that the admi­ni­stra­ti­ve bur­den on micro, small and medi­um-sized enter­pri­ses is proportionate.
Artic­le 32 Con­for­mi­ty assess­ment pro­ce­du­res for devices incor­po­ra­ting digi­tal elements
(1) The manu­fac­tu­rer shall car­ry out an assess­ment of con­for­mi­ty of the device with digi­tal ele­ments and the pro­ce­du­res spe­ci­fi­ed by the manu­fac­tu­rer to deter­mi­ne whe­ther the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I are met. The manu­fac­tu­rer shall demon­stra­te con­for­mi­ty with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments using one of the fol­lo­wing procedures:
a) inter­nal con­trol pro­ce­du­re (based on Modu­le A) in accordance with Annex VIII
b) EU-type exami­na­ti­on pro­ce­du­re (based on modu­le B) accor­ding to Annex VIII and then con­for­mi­ty to EU-type based on inter­nal pro­duc­tion con­trol (based on modu­le C) accor­ding to Annex VIII
c) Con­for­mi­ty assess­ment based on full qua­li­ty assu­rance (based on Modu­le H) in accordance with Annex VIII; or
d) whe­re available and appli­ca­ble, a Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­me in accordance with Artic­le 27(9).
(2) Whe­re the manu­fac­tu­rer has not applied or has only par­ti­al­ly applied har­mo­ni­zed stan­dards, com­mon spe­ci­fi­ca­ti­ons or Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­mes at least at assu­rance level ‘medi­um’ in accordance with Artic­le 27 when asses­sing the con­for­mi­ty of a cri­ti­cal device with digi­tal ele­ments fal­ling within class I as set out in Annex III and the pro­ce­du­res estab­lished by the manu­fac­tu­rer with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I, or whe­re such har­mo­ni­zed stan­dards, com­mon spe­ci­fi­ca­ti­ons or Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­mes are not available, the devices with digi­tal ele­ments and the pro­ce­du­res estab­lished by the manu­fac­tu­rer shall be sub­ject to one of the fol­lo­wing pro­ce­du­res com­mon spe­ci­fi­ca­ti­ons or Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­mes do not exist, the devices with digi­tal ele­ments and the pro­ce­du­res defi­ned by the manu­fac­tu­rer with regard to the essen­ti­al cyber­se­cu­ri­ty requi­re­ments shall be sub­ject to one of the fol­lo­wing procedures:
a) EU-type exami­na­ti­on pro­ce­du­re (based on modu­le B) accor­ding to Annex VIII and then con­for­mi­ty to EU-type based on inter­nal pro­duc­tion con­trol (based on modu­le C) accor­ding to Annex VIII or
b) a con­for­mi­ty assess­ment based on full qua­li­ty assu­rance (based on Modu­le H) in accordance with Annex VIII.
(3) Whe­re the device is a cri­ti­cal device with digi­tal ele­ments fal­ling within Class II as set out in Annex III, the manu­fac­tu­rer shall demon­stra­te con­for­mi­ty with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I using one of the fol­lo­wing procedures:
a) EU-type exami­na­ti­on pro­ce­du­re (based on modu­le B) accor­ding to Annex VIII and sub­se­quent­ly con­for­mi­ty to EU-type based on inter­nal pro­duc­tion con­trol (based on modu­le C) accor­ding to Annex VIII;
b) a con­for­mi­ty assess­ment based on full qua­li­ty assu­rance (based on Modu­le H) in accordance with Annex VIII, or
c) whe­re available and appli­ca­ble, a Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­me in accordance with Artic­le 27(9) of this Regu­la­ti­on at least at the assu­rance level ‘medi­um’ in accordance with Regu­la­ti­on (EU) 2019/881.
(4) For cri­ti­cal devices with digi­tal ele­ments listed in Annex IV, com­pli­ance with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I shall be demon­stra­ted by one of the fol­lo­wing methods:
a) a Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­me in accordance with Artic­le 8(1); or
b) if the con­di­ti­ons laid down in Artic­le 8(1) are not met, one of the pro­ce­du­res refer­red to in para­graph 3.
(5) Manu­fac­tu­r­ers of devices incor­po­ra­ting digi­tal items that are con­side­red free and open source soft­ware and fall within the cate­go­ries set out in Annex III may demon­stra­te com­pli­ance with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I by means of one of the pro­ce­du­res refer­red to in para­graph 1 of this Artic­le, pro­vi­ded that the tech­ni­cal docu­men­ta­ti­on refer­red to in Artic­le 31 is made available to the public at the time of pla­cing tho­se devices on the market.
(6) When set­ting the fees for con­for­mi­ty assess­ment, the spe­ci­fic inte­rests and needs of micro, small and medi­um-sized enter­pri­ses, inclu­ding start-ups, shall be taken into account and tho­se fees shall be redu­ced in pro­por­ti­on to their spe­ci­fic inte­rests and needs.
Artic­le 33 Sup­port mea­su­res for micro, small and medi­um-sized enter­pri­ses, inclu­ding start-ups
(1) Mem­ber Sta­tes shall, whe­re appro­pria­te, take the fol­lo­wing mea­su­res tail­o­red to the needs of micro and small enterprises:
a) Orga­nizati­on of spe­ci­fic awa­re­ness-rai­sing and trai­ning mea­su­res for the appli­ca­ti­on of this regulation,
b) Estab­lish a dedi­ca­ted com­mu­ni­ca­ti­on chan­nel for micro and small enter­pri­ses and, whe­re appro­pria­te, local aut­ho­ri­ties to pro­vi­de advice on the imple­men­ta­ti­on of this Regu­la­ti­on and to cla­ri­fy queries,
c) Sup­port of test­ing and con­for­mi­ty assess­ment acti­vi­ties, if requi­red also with the sup­port of the Euro­pean Cyber­se­cu­ri­ty Com­pe­tence Center.
(2) Mem­ber Sta­tes may, whe­re neces­sa­ry, estab­lish cyber resi­li­ence real-world labo­ra­to­ries. Such real-world labo­ra­to­ries shall pro­vi­de for con­trol­led test envi­ron­ments for inno­va­ti­ve devices with digi­tal ele­ments to faci­li­ta­te their deve­lo­p­ment, design, vali­da­ti­on and test­ing for the pur­po­se of com­pli­ance with this Regu­la­ti­on for a limi­t­ed peri­od of time befo­re they are pla­ced on the mar­ket. The Com­mis­si­on and, whe­re appro­pria­te, ENISA may pro­vi­de tech­ni­cal sup­port, advice and tools for the estab­lish­ment and ope­ra­ti­on of real-world labo­ra­to­ries. The real labo­ra­to­ries shall be set up under the direct super­vi­si­on, gui­dance and sup­port of the mar­ket sur­veil­lan­ce aut­ho­ri­ties. Mem­ber Sta­tes shall inform the Com­mis­si­on and the other mar­ket sur­veil­lan­ce aut­ho­ri­ties of the estab­lish­ment of a real-world labo­ra­to­ry through ADCO. The real­la­bo­ra­to­ries shall be wit­hout pre­ju­di­ce to the super­vi­so­ry and cor­rec­ti­ve powers of the com­pe­tent aut­ho­ri­ties. Mem­ber Sta­tes shall ensu­re open, fair and trans­pa­rent access to real labo­ra­to­ries and faci­li­ta­te access in par­ti­cu­lar for micro and small enter­pri­ses, inclu­ding start-ups.
(3) In accordance with Artic­le 26, the Com­mis­si­on shall pro­vi­de gui­dance to micro, small and medi­um-sized enter­pri­ses on the imple­men­ta­ti­on of this Regulation.
(4) The Com­mis­si­on shall pro­vi­de infor­ma­ti­on on available finan­cial sup­port within the legal frame­work of exi­sting Uni­on pro­grams, in par­ti­cu­lar to pro­vi­de finan­cial reli­ef to micro and small enterprises.
(5) Micro and small enter­pri­ses may sub­mit all ele­ments of the tech­ni­cal docu­men­ta­ti­on listed in Annex VII in a sim­pli­fi­ed for­mat. To that end, the Com­mis­si­on shall, by means of imple­men­ting acts, estab­lish the sim­pli­fi­ed tech­ni­cal docu­men­ta­ti­on form tail­o­red to the needs of micro and small enter­pri­ses, inclu­ding the way in which the ele­ments listed in Annex VII are to be pro­vi­ded. Whe­re a microen­ter­pri­se or a small enter­pri­se choo­ses to pro­vi­de the infor­ma­ti­on requi­red in Annex VII in a sim­pli­fi­ed man­ner, it shall use the form refer­red to in this para­graph. Noti­fi­ed bodies shall accept that form for the pur­po­ses of con­for­mi­ty assessment.
Tho­se imple­men­ting acts shall be adopted in accordance with the exami­na­ti­on pro­ce­du­re refer­red to in Artic­le 62(2).
Artic­le 34 Mutu­al reco­gni­ti­on agreement
Taking into account the level of tech­ni­cal deve­lo­p­ment and the approach to con­for­mi­ty assess­ment of a third coun­try, the Uni­on may con­clude mutu­al reco­gni­ti­on agree­ments with third count­ries in order to pro­mo­te and faci­li­ta­te inter­na­tio­nal trade, in accordance with Artic­le 218 TFEU. 

Chap­ter IV Noti­fi­ca­ti­on of con­for­mi­ty assess­ment bodies 

Artic­le 35 Notification
(1) Mem­ber Sta­tes shall noti­fy the Com­mis­si­on and the other Mem­ber Sta­tes of the bodies aut­ho­ri­zed to car­ry out con­for­mi­ty assess­ments under this Regulation.
(2) By Decem­ber 11, 2026, Mem­ber Sta­tes shall ensu­re that the­re is a suf­fi­ci­ent num­ber of noti­fi­ed bodies in the Uni­on that can car­ry out con­for­mi­ty assess­ments in order to pre­vent bot­t­len­ecks and bar­riers to mar­ket access.
Artic­le 36 Noti­fy­ing authorities
(1) Each Mem­ber Sta­te shall desi­gna­te a noti­fy­ing aut­ho­ri­ty that shall be respon­si­ble for set­ting up, car­ry­ing out and moni­to­ring the neces­sa­ry pro­ce­du­res for the assess­ment, desi­gna­ti­on and noti­fi­ca­ti­on of con­for­mi­ty assess­ment bodies, inclu­ding com­pli­ance with Artic­le 41.
(2) Mem­ber Sta­tes may deci­de that the assess­ment and moni­to­ring refer­red to in para­graph 1 of this Artic­le shall be car­ri­ed out by a natio­nal accre­di­ta­ti­on body within the mea­ning of and in accordance with Regu­la­ti­on (EC) No 765/2008.
(3) Whe­re the noti­fy­ing aut­ho­ri­ty dele­ga­tes or other­wi­se ent­rusts the assess­ment, noti­fi­ca­ti­on or moni­to­ring refer­red to in para­graph 1 of this Artic­le to a non-govern­men­tal body, that body shall be a legal enti­ty and shall com­ply with Artic­le 37 accor­din­gly. That body shall also make pro­vi­si­ons to cover any lia­bi­li­ty ari­sing from its activities.
(4) The noti­fy­ing aut­ho­ri­ty shall take full respon­si­bi­li­ty for the acti­vi­ties car­ri­ed out by the body refer­red to in para­graph 3.
Artic­le 37 Requi­re­ments for noti­fy­ing authorities
(1) Noti­fy­ing aut­ho­ri­ties are set up in such a way that the­re is no con­flict of inte­rest with the con­for­mi­ty assess­ment bodies.
(2) Noti­fy­ing aut­ho­ri­ties shall ensu­re, through their orga­nizati­on and working methods, that objec­ti­vi­ty and impar­tia­li­ty are main­tai­ned in the exer­cise of their activities.
(3) Noti­fy­ing aut­ho­ri­ties shall be struc­tu­red in such a way that each decis­i­on on the noti­fi­ca­ti­on of a con­for­mi­ty assess­ment body is taken by com­pe­tent per­sons who are not the same as the per­sons who car­ri­ed out the assessment.
(4) Noti­fy­ing aut­ho­ri­ties may not offer or pro­vi­de acti­vi­ties car­ri­ed out by con­for­mi­ty assess­ment bodies or con­sul­tan­cy ser­vices on a com­mer­cial or com­pe­ti­ti­ve basis.
(5) Noti­fy­ing aut­ho­ri­ties gua­ran­tee the con­fi­den­tia­li­ty of the infor­ma­ti­on they obtain.
(6) A noti­fy­ing aut­ho­ri­ty has a suf­fi­ci­ent num­ber of com­pe­tent employees at its dis­po­sal so that it can per­form its tasks properly.
Artic­le 38 Infor­ma­ti­on obli­ga­ti­ons of noti­fy­ing authorities
(1) Mem­ber Sta­tes shall inform the Com­mis­si­on of their pro­ce­du­res for the assess­ment and noti­fi­ca­ti­on of con­for­mi­ty assess­ment bodies and for the moni­to­ring of noti­fi­ed bodies and of any chan­ges thereto.
(2) The Com­mis­si­on shall make the infor­ma­ti­on refer­red to in para­graph 1 available to the public.
Artic­le 39 Requi­re­ments for noti­fi­ed bodies
(1) Con­for­mi­ty assess­ment bodies shall meet the requi­re­ments set out in para­graphs 2 to 12 for the pur­po­ses of notification.
(2) A con­for­mi­ty assess­ment body is estab­lished under natio­nal law and has legal personality.
(3) A con­for­mi­ty assess­ment body is an inde­pen­dent third par­ty that is inde­pen­dent of the orga­nizati­on or the pro­duct with digi­tal ele­ments that is being assessed.
A body belon­ging to a trade asso­cia­ti­on or pro­fes­sio­nal orga­nizati­on that asses­ses pro­ducts with digi­tal ele­ments who­se design, deve­lo­p­ment, manu­fac­tu­re, pro­vi­si­on, assem­bly, use or main­ten­an­ce invol­ves com­pa­nies repre­sen­ted by that asso­cia­ti­on may be con­side­red as such an inde­pen­dent third par­ty, pro­vi­ded that its inde­pen­dence and the absence of any con­flict of inte­rest are demon­stra­ted.
(4) A con­for­mi­ty assess­ment body, its top level manage­ment and the per­son­nel respon­si­ble for car­ry­ing out the con­for­mi­ty assess­ment tasks shall not be the desi­gner, deve­lo­per, manu­fac­tu­rer, sup­plier, importer, dis­tri­bu­tor, instal­ler, purcha­ser, owner, user or main­tai­ner of the pro­ducts incor­po­ra­ting digi­tal ele­ments which they assess, nor the aut­ho­ri­zed repre­sen­ta­ti­ve of any of tho­se par­ties. This does not exclude the use of pro­ducts that have alre­a­dy under­go­ne con­for­mi­ty assess­ment and are requi­red for the acti­vi­ties of the con­for­mi­ty assess­ment body or the use of such pro­ducts for per­so­nal use.
A con­for­mi­ty assess­ment body, its top level manage­ment and the per­son­nel respon­si­ble for car­ry­ing out the con­for­mi­ty assess­ment tasks shall not be direct­ly invol­ved in the design, deve­lo­p­ment, manu­fac­tu­re, import, dis­tri­bu­ti­on, mar­ke­ting, instal­la­ti­on, use or main­ten­an­ce of tho­se pro­ducts with digi­tal ele­ments which they assess, or repre­sent the par­ties enga­ged in tho­se acti­vi­ties. They shall not enga­ge in any acti­vi­ty that may con­flict with their inde­pen­dence of judgment or inte­gri­ty in rela­ti­on to the con­for­mi­ty assess­ment acti­vi­ties for which they are noti­fi­ed. This applies in par­ti­cu­lar to con­sul­tan­cy ser­vices. Con­for­mi­ty assess­ment bodies shall ensu­re that the acti­vi­ties of their sub­si­dia­ries or sub­con­trac­tors do not affect the con­fi­den­tia­li­ty, objec­ti­vi­ty or impar­tia­li­ty of their con­for­mi­ty assess­ment acti­vi­ties.
(5) Con­for­mi­ty assess­ment bodies and their per­son­nel shall car­ry out the con­for­mi­ty assess­ment acti­vi­ties with the hig­hest degree of pro­fes­sio­nal inte­gri­ty and the requi­si­te tech­ni­cal com­pe­tence in the spe­ci­fic field and shall be free from all pres­su­res and indu­ce­ments, par­ti­cu­lar­ly finan­cial, which might influence their judgment or the results of their con­for­mi­ty assess­ment acti­vi­ties, espe­ci­al­ly as regards per­sons or groups of per­sons with an inte­rest in the results of tho­se activities.
(6) A con­for­mi­ty assess­ment body shall be capa­ble of car­ry­ing out all the con­for­mi­ty assess­ment tasks assi­gned to it by Annex VIII and in rela­ti­on to which it has been noti­fi­ed, whe­ther tho­se tasks are car­ri­ed out by the con­for­mi­ty assess­ment body its­elf or on its behalf and under its responsibility.
At all times and for each con­for­mi­ty assess­ment pro­ce­du­re and each kind and cate­go­ry of devices with digi­tal ele­ments for which it has been noti­fi­ed, a con­for­mi­ty assess­ment body shall have at its dis­po­sal
a) the neces­sa­ry per­son­nel with spe­cia­list know­ledge and suf­fi­ci­ent rele­vant expe­ri­ence to per­form the tasks invol­ved in con­for­mi­ty assessment;
b) descrip­ti­ons of pro­ce­du­res accor­ding to which con­for­mi­ty assess­ment shall be car­ri­ed out in order to ensu­re the trans­pa­ren­cy and repea­ta­bi­li­ty of tho­se pro­ce­du­res. It shall have appro­pria­te poli­ci­es and pro­ce­du­res in place that distin­gu­ish bet­ween the tasks it per­forms as a noti­fi­ed body and other activities;
c) Pro­ce­du­res for car­ry­ing out acti­vi­ties with due regard to the size of a com­pa­ny, the sec­tor in which it ope­ra­tes, its struc­tu­re, the degree of com­ple­xi­ty of the pro­duct tech­no­lo­gy in que­sti­on and the mass pro­duc­tion or series natu­re of the manu­fac­tu­ring process.
A con­for­mi­ty assess­ment body shall have the means neces­sa­ry to per­form the tech­ni­cal and admi­ni­stra­ti­ve tasks con­nec­ted with the con­for­mi­ty assess­ment acti­vi­ties in an appro­pria­te man­ner and shall have access to all neces­sa­ry equip­ment or faci­li­ties.
(7) The staff respon­si­ble for car­ry­ing out the con­for­mi­ty assess­ment acti­vi­ties must have the following:
a) sound tech­ni­cal and voca­tio­nal trai­ning cove­ring all con­for­mi­ty assess­ment acti­vi­ties in the field for which the con­for­mi­ty assess­ment body has been notified;
b) suf­fi­ci­ent know­ledge of the requi­re­ments asso­cia­ted with the assess­ments to be car­ri­ed out and the cor­re­spon­ding aut­ho­rizati­on to car­ry out such assessments;
c) appro­pria­te know­ledge and under­stan­ding of the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I, the appli­ca­ble har­mo­ni­zed stan­dards and com­mon spe­ci­fi­ca­ti­ons and the rele­vant Uni­on har­mo­nizati­on legis­la­ti­on and its imple­men­ting legislation;
d) the abili­ty to draw up cer­ti­fi­ca­tes, pro­to­cols and reports as pro­of of assess­ments car­ri­ed out.
(8) The impar­tia­li­ty of the con­for­mi­ty assess­ment bodies, their top-level manage­ment and their asses­sing per­son­nel must be guaranteed.
The remu­ne­ra­ti­on of the top manage­ment level and the asses­sing per­son­nel of the con­for­mi­ty assess­ment body must not be based on the num­ber of assess­ments car­ri­ed out or their results.
(9) Con­for­mi­ty assess­ment bodies shall take out lia­bi­li­ty insu­rance unless lia­bi­li­ty is assu­med under the natio­nal law of their Mem­ber Sta­te or the Mem­ber Sta­te its­elf is direct­ly respon­si­ble for the con­for­mi­ty assessment.
(10) Infor­ma­ti­on obtai­ned by the per­son­nel of a con­for­mi­ty assess­ment body in car­ry­ing out their tasks under Annex VIII or any pro­vi­si­on of natio­nal law giving effect to it shall be cover­ed by the obli­ga­ti­on of pro­fes­sio­nal sec­re­cy, except in rela­ti­on to the mar­ket sur­veil­lan­ce aut­ho­ri­ties of the Mem­ber Sta­te in which its acti­vi­ties are car­ri­ed out. Pro­prie­ta­ry rights shall be pro­tec­ted. The con­for­mi­ty assess­ment body shall have docu­men­ted pro­ce­du­res in place to ensu­re com­pli­ance with this paragraph.
(11) Con­for­mi­ty assess­ment bodies shall par­ti­ci­pa­te in, or ensu­re that their assess­ment per­son­nel are infor­med of, the rele­vant stan­dar­dizati­on acti­vi­ties and the acti­vi­ties of the noti­fi­ed body coor­di­na­ti­on group estab­lished under Artic­le 51 and shall app­ly as gene­ral gui­dance the admi­ni­stra­ti­ve decis­i­ons and docu­ments pro­du­ced by that group.
(12) Con­for­mi­ty assess­ment bodies shall car­ry out their acti­vi­ties in accordance with a set of con­si­stent, fair, pro­por­tio­na­te and rea­sonable com­mer­cial con­di­ti­ons, avo­i­ding unneces­sa­ry bur­dens on eco­no­mic ope­ra­tors and taking into account the inte­rests of micro, small and medi­um-sized enter­pri­ses, in par­ti­cu­lar with regard to fees.
Artic­le 40 Pre­sump­ti­on of con­for­mi­ty of noti­fi­ed bodies
Whe­re a con­for­mi­ty assess­ment body demon­stra­tes its con­for­mi­ty with the cri­te­ria laid down in the rele­vant har­mo­ni­zed stan­dards the refe­ren­ces of which have been published in the Offi­ci­al Jour­nal of the Euro­pean Uni­on, or parts the­reof, it shall be pre­su­med to com­ply with the requi­re­ments set out in Artic­le 39 in so far as the appli­ca­ble stan­dards cover tho­se requirements. 
Artic­le 41 Bran­ches of noti­fi­ed bodies and sub­con­trac­ting by noti­fi­ed bodies
(1) Whe­re a noti­fi­ed body sub­con­tracts spe­ci­fic tasks con­nec­ted with con­for­mi­ty assess­ment or has recour­se to a sub­si­dia­ry, it shall ensu­re that the sub­con­trac­tor or the sub­si­dia­ry meets the requi­re­ments laid down in Artic­le 39 and shall inform the noti­fy­ing aut­ho­ri­ty accordingly.
(2) Noti­fi­ed bodies bear full respon­si­bi­li­ty for the work car­ri­ed out by sub­con­trac­tors or sub­si­dia­ries, regard­less of whe­re they are established.
(3) Work may only be sub­con­trac­ted or assi­gned to a branch office with the manufacturer’s consent.
(4) Noti­fi­ed bodies shall keep at the dis­po­sal of the noti­fy­ing aut­ho­ri­ty the rele­vant docu­ments con­cer­ning the assess­ment of the qua­li­fi­ca­ti­ons of the sub­con­trac­tor or the sub­si­dia­ry and the work car­ri­ed out by them under this Regulation.
Artic­le 42 Appli­ca­ti­on for notification
(1) A con­for­mi­ty assess­ment body shall sub­mit an appli­ca­ti­on for noti­fi­ca­ti­on to the noti­fy­ing aut­ho­ri­ty of the Mem­ber Sta­te in which it is established.
(2) The appli­ca­ti­on shall be accom­pa­nied by a descrip­ti­on of the con­for­mi­ty assess­ment acti­vi­ties, the con­for­mi­ty assess­ment pro­ce­du­re or pro­ce­du­res and the pro­duct or pro­ducts with digi­tal ele­ments for which that body claims to be com­pe­tent, as well as by an accre­di­ta­ti­on cer­ti­fi­ca­te, whe­re appli­ca­ble, issued by a natio­nal accre­di­ta­ti­on body attest­ing that the con­for­mi­ty assess­ment body ful­fills the requi­re­ments laid down in Artic­le 39.
(3) Whe­re the con­for­mi­ty assess­ment body con­cer­ned can­not pro­vi­de an accre­di­ta­ti­on cer­ti­fi­ca­te, it shall pro­vi­de the noti­fy­ing aut­ho­ri­ty with all the docu­men­ta­ry evi­dence neces­sa­ry for the veri­fi­ca­ti­on, reco­gni­ti­on and regu­lar moni­to­ring of its com­pli­ance with the requi­re­ments laid down in Artic­le 39.
Artic­le 43 Noti­fi­ca­ti­on procedure
(1) Noti­fy­ing aut­ho­ri­ties shall noti­fy only con­for­mi­ty assess­ment bodies which have satis­fied the requi­re­ments laid down in Artic­le 39.
(2) The noti­fy­ing aut­ho­ri­ty shall inform the Com­mis­si­on and the other Mem­ber Sta­tes by means of the infor­ma­ti­on system for New Approach noti­fi­ed and desi­gna­ted orga­nizati­ons deve­lo­ped and mana­ged by the Commission.
(3) The noti­fi­ca­ti­on shall con­tain full details of the con­for­mi­ty assess­ment acti­vi­ties, the con­for­mi­ty assess­ment modu­le or modu­les and pro­ducts with digi­tal ele­ments con­cer­ned and the rele­vant atte­sta­ti­on of competence.
(4) Whe­re a noti­fi­ca­ti­on is not based on an accre­di­ta­ti­on cer­ti­fi­ca­te as refer­red to in Artic­le 42(2), the noti­fy­ing aut­ho­ri­ty shall pro­vi­de the Com­mis­si­on and the other Mem­ber Sta­tes with docu­men­ta­ry evi­dence which attests to the con­for­mi­ty assess­ment body’s com­pe­tence and the arran­ge­ments in place to ensu­re that the body will be moni­to­red regu­lar­ly and will con­ti­n­ue to satis­fy the requi­re­ments laid down in Artic­le 39.
(5) The body con­cer­ned may per­form the tasks of a noti­fi­ed body only if neither the Com­mis­si­on nor the other Mem­ber Sta­tes have rai­sed objec­tions within two weeks of the noti­fi­ca­ti­on, if an accre­di­ta­ti­on cer­ti­fi­ca­te is available, or within two months of the noti­fi­ca­ti­on, if no accre­di­ta­ti­on is available.
Only such a body shall be con­side­red a noti­fi­ed body for the pur­po­ses of this Regu­la­ti­on.
(6) The Com­mis­si­on and the other Mem­ber Sta­tes shall be infor­med of any sub­se­quent rele­vant chan­ges to the notification.
Artic­le 44 Iden­ti­fi­ca­ti­on num­bers and lists of noti­fi­ed bodies
(1) The Com­mis­si­on shall assign an iden­ti­fi­ca­ti­on num­ber to each noti­fi­ed body.
Even if a body is noti­fi­ed under seve­ral Uni­on acts, it will only recei­ve a sin­gle iden­ti­fi­ca­ti­on num­ber.
(2) The Com­mis­si­on shall publish the list of bodies noti­fi­ed under this Regu­la­ti­on, tog­e­ther with the iden­ti­fi­ca­ti­on num­bers assi­gned to them and the acti­vi­ties for which they have been notified.
The Com­mis­si­on shall ensu­re that this list is always kept up to date. 
Artic­le 45 Amend­ments to notifications
(1) Whe­re a noti­fy­ing aut­ho­ri­ty has ascer­tai­ned or has been infor­med that a noti­fi­ed body no lon­ger meets the requi­re­ments laid down in Artic­le 39, or that it is fai­ling to ful­fil its obli­ga­ti­ons, the noti­fy­ing aut­ho­ri­ty shall rest­rict, sus­pend or with­draw noti­fi­ca­ti­on as appro­pria­te, depen­ding on the ext­ent to which tho­se requi­re­ments have not been met or tho­se obli­ga­ti­ons have not been ful­fil­led. It shall imme­dia­te­ly inform the Com­mis­si­on and the other Mem­ber Sta­tes thereof.
(2) In the event of rest­ric­tion, sus­pen­si­on or with­dra­wal of noti­fi­ca­ti­on, or whe­re the noti­fi­ed body has cea­sed its acti­vi­ty, the noti­fy­ing Mem­ber Sta­te shall take appro­pria­te steps to ensu­re that the files of that body are eit­her pro­ce­s­sed by ano­ther noti­fi­ed body or kept available for the respon­si­ble noti­fy­ing and mar­ket sur­veil­lan­ce aut­ho­ri­ties at their request.
Artic­le 46 Con­te­sta­ti­on of the com­pe­tence of noti­fi­ed bodies
(1) The Com­mis­si­on shall inve­sti­ga­te all cases whe­re it doubts, or doubt is brought to its atten­ti­on regar­ding, the com­pe­tence of a noti­fi­ed body or the con­tin­ued ful­fill­ment by a noti­fi­ed body of the requi­re­ments and respon­si­bi­li­ties to which it is subject.
(2) The noti­fy­ing Mem­ber Sta­te shall pro­vi­de the Com­mis­si­on, on request, with all infor­ma­ti­on rela­ting to the basis of the noti­fi­ca­ti­on or the main­ten­an­ce of the com­pe­tence of the body concerned.
(3) The Com­mis­si­on ensu­res that all sen­si­ti­ve infor­ma­ti­on obtai­ned in the cour­se of its inve­sti­ga­ti­ons is trea­ted confidentially.
(4) Whe­re the Com­mis­si­on ascer­ta­ins that a noti­fi­ed body does not meet or no lon­ger meets the requi­re­ments for its noti­fi­ca­ti­on, it shall inform the noti­fy­ing Mem­ber Sta­te accor­din­gly and request it to take the neces­sa­ry cor­rec­ti­ve mea­su­res, inclu­ding with­dra­wal of noti­fi­ca­ti­on if necessary.
Artic­le 47 Ope­ra­tio­nal obli­ga­ti­ons of noti­fi­ed bodies
(1) Noti­fi­ed bodies shall car­ry out con­for­mi­ty assess­ments in accordance with the con­for­mi­ty assess­ment pro­ce­du­res set out in Artic­le 32 and Annex VIII.
(2) Con­for­mi­ty assess­ments shall be car­ri­ed out in a pro­por­tio­na­te man­ner, avo­i­ding unneces­sa­ry bur­dens on eco­no­mic ope­ra­tors. Con­for­mi­ty assess­ment bodies shall per­form their acti­vi­ties taking due account of the size of the under­ta­kings, in par­ti­cu­lar as regards micro, small and medi­um-sized enter­pri­ses, the sec­tor in which they ope­ra­te, their struc­tu­re, the degree of com­ple­xi­ty and cyber­se­cu­ri­ty risk of the pro­ducts incor­po­ra­ting digi­tal ele­ments and tech­no­lo­gies con­cer­ned and the mass or seri­al natu­re of the manu­fac­tu­ring process.
(3) Howe­ver, noti­fi­ed bodies shall be as strin­gent and main­tain such a level of pro­tec­tion as is neces­sa­ry for the com­pli­ance of pro­ducts incor­po­ra­ting digi­tal ele­ments with this Regulation.
(4) Whe­re a noti­fi­ed body finds that the requi­re­ments set out in Annex I or in the cor­re­spon­ding har­mo­ni­zed stan­dards or com­mon spe­ci­fi­ca­ti­ons refer­red to in Artic­le 27 have not been met by a manu­fac­tu­rer, it shall requi­re that manu­fac­tu­rer to take appro­pria­te cor­rec­ti­ve mea­su­res and shall not issue a cer­ti­fi­ca­te of conformity.
(5) Whe­re, in the cour­se of the moni­to­ring of con­for­mi­ty fol­lo­wing the issue of a cer­ti­fi­ca­te, a noti­fi­ed body finds that a device with digi­tal ele­ments no lon­ger com­plies with the requi­re­ments laid down in this Regu­la­ti­on, it shall requi­re the manu­fac­tu­rer to take appro­pria­te cor­rec­ti­ve mea­su­res and shall sus­pend or with­draw the cer­ti­fi­ca­te if necessary.
(6) If cor­rec­ti­ve actions are not taken or do not have the neces­sa­ry effect, the noti­fi­ed body shall rest­rict, sus­pend or revo­ke the cer­ti­fi­ca­tes, as appropriate.
Artic­le 48 Appeal against decis­i­ons of noti­fi­ed bodies
Mem­ber Sta­tes shall ensu­re that an appeal pro­ce­du­re against the decis­i­ons of the noti­fi­ed bodies is pro­vi­ded for. 
Artic­le 49 Noti­fi­ca­ti­on obli­ga­ti­ons of noti­fi­ed bodies
(1) Noti­fi­ed bodies shall noti­fy the noti­fy­ing aut­ho­ri­ty of
a) all refu­sals, rest­ric­tions, sus­pen­si­ons and revo­ca­ti­ons of a certificate,
b) any cir­cum­stances affec­ting the scope and con­di­ti­ons of the notification,
c) all requests for infor­ma­ti­on on con­for­mi­ty assess­ment acti­vi­ties recei­ved from the mar­ket sur­veil­lan­ce authorities,
d) on request, the con­for­mi­ty assess­ment acti­vi­ties they have car­ri­ed out within the scope of their noti­fi­ca­ti­on and other acti­vi­ties, inclu­ding cross-bor­der acti­vi­ties and sub­con­trac­ting, which they have car­ri­ed out.
(2) Noti­fi­ed bodies shall pro­vi­de the other bodies noti­fi­ed under this Regu­la­ti­on car­ry­ing out simi­lar con­for­mi­ty assess­ment acti­vi­ties for the same devices incor­po­ra­ting digi­tal ele­ments with rele­vant infor­ma­ti­on on nega­ti­ve and, on request, posi­ti­ve con­for­mi­ty assess­ment results.
Artic­le 50 Exch­an­ge of experience
The Com­mis­si­on shall orga­ni­ze the exch­an­ge of expe­ri­ence bet­ween the natio­nal aut­ho­ri­ties of the Mem­ber Sta­tes respon­si­ble for noti­fi­ca­ti­on policy. 
Artic­le 51 Coor­di­na­ti­on of noti­fi­ed bodies
(1) The Com­mis­si­on shall ensu­re that appro­pria­te coor­di­na­ti­on and coope­ra­ti­on bet­ween noti­fi­ed bodies is estab­lished and pro­per­ly main­tai­ned in the form of a cross-sec­to­ral group of noti­fi­ed bodies.
(2) Mem­ber Sta­tes shall ensu­re that the bodies noti­fi­ed by them par­ti­ci­pa­te in the work of this group direct­ly or through desi­gna­ted representatives.

Chap­ter V Mar­ket sur­veil­lan­ce and enforcement 

Artic­le 52 Mar­ket sur­veil­lan­ce and con­trol of pro­ducts with digi­tal ele­ments on the Uni­on market
(1) Regu­la­ti­on (EU) 2019/1020 applies to the pro­ducts with digi­tal ele­ments that fall within the scope of this Regulation.
(2) Each Mem­ber Sta­te shall desi­gna­te one or more mar­ket sur­veil­lan­ce aut­ho­ri­ties for the pur­po­se of ensu­ring the effec­ti­ve imple­men­ta­ti­on of this Regu­la­ti­on. Mem­ber Sta­tes may desi­gna­te an exi­sting or a new aut­ho­ri­ty to act as mar­ket sur­veil­lan­ce aut­ho­ri­ty under this Regulation.
(3) The mar­ket sur­veil­lan­ce aut­ho­ri­ties desi­gna­ted pur­su­ant to para­graph 2 of this Artic­le shall also be respon­si­ble for car­ry­ing out mar­ket sur­veil­lan­ce acti­vi­ties in rela­ti­on to the obli­ga­ti­ons for open source soft­ware mana­gers set out in Artic­le 24. Whe­re a mar­ket sur­veil­lan­ce aut­ho­ri­ty finds that an open source soft­ware mana­ger does not com­ply with the obli­ga­ti­ons laid down in that Artic­le, it shall requi­re the open source soft­ware mana­ger to ensu­re that all appro­pria­te cor­rec­ti­ve action is taken. Admi­ni­stra­tors of open source soft­ware shall, as part of their obli­ga­ti­ons under this Regu­la­ti­on, ensu­re that all appro­pria­te cor­rec­ti­ve action is taken.
(4) Mar­ket sur­veil­lan­ce aut­ho­ri­ties shall, whe­re appro­pria­te, coope­ra­te and regu­lar­ly exch­an­ge infor­ma­ti­on with the natio­nal cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on aut­ho­ri­ties desi­gna­ted in accordance with Artic­le 58 of Regu­la­ti­on (EU) 2019/881. When over­see­ing the imple­men­ta­ti­on of the report­ing obli­ga­ti­ons under Artic­le 14 of this Regu­la­ti­on, the desi­gna­ted mar­ket sur­veil­lan­ce aut­ho­ri­ties shall coope­ra­te and regu­lar­ly exch­an­ge infor­ma­ti­on with the CSIRTs desi­gna­ted as coor­di­na­tors and ENISA.
(5) Mar­ket sur­veil­lan­ce aut­ho­ri­ties may request tech­ni­cal advice from the CSIRT desi­gna­ted as coor­di­na­tor or ENISA on the imple­men­ta­ti­on and enforce­ment of this Regu­la­ti­on. When car­ry­ing out an inve­sti­ga­ti­on pur­su­ant to Artic­le 54, mar­ket sur­veil­lan­ce aut­ho­ri­ties may request the CSIRT desi­gna­ted as coor­di­na­tor or ENISA to car­ry out an ana­ly­sis to sub­stan­tia­te the con­for­mi­ty assess­ment of pro­ducts incor­po­ra­ting digi­tal elements.
(6) Mar­ket sur­veil­lan­ce aut­ho­ri­ties shall, whe­re appro­pria­te, coope­ra­te and regu­lar­ly exch­an­ge infor­ma­ti­on with other mar­ket sur­veil­lan­ce aut­ho­ri­ties desi­gna­ted on the basis of Uni­on har­mo­nizati­on legis­la­ti­on other than this Regu­la­ti­on for other products.
(7) Mar­ket sur­veil­lan­ce aut­ho­ri­ties shall, whe­re appro­pria­te, coope­ra­te with the aut­ho­ri­ties super­vi­sing the appli­ca­ti­on of Uni­on data pro­tec­tion law. Such coope­ra­ti­on shall include informing tho­se aut­ho­ri­ties of any fin­dings rele­vant to the exer­cise of their respon­si­bi­li­ties, inclu­ding on the issu­an­ce of gui­de­lines and advice refer­red to in para­graph 10, whe­re such gui­de­lines and advice con­cern the pro­ce­s­sing of per­so­nal data.
The aut­ho­ri­ties super­vi­sing the appli­ca­ti­on of Uni­on data pro­tec­tion law shall have the power to requi­re and access all docu­ments crea­ted or main­tai­ned under this Regu­la­ti­on to the ext­ent that access to tho­se docu­ments is neces­sa­ry for the per­for­mance of their tasks. They shall inform the desi­gna­ted mar­ket sur­veil­lan­ce aut­ho­ri­ties of the Mem­ber Sta­te con­cer­ned of any such request.
(8) Mem­ber Sta­tes shall ensu­re that desi­gna­ted mar­ket sur­veil­lan­ce aut­ho­ri­ties are pro­vi­ded with ade­qua­te finan­cial and tech­ni­cal resour­ces, inclu­ding pro­cess auto­ma­ti­on tools whe­re appro­pria­te, and human resour­ces with the neces­sa­ry cyber­se­cu­ri­ty skills to car­ry out their tasks under this Regulation.
(9) The Com­mis­si­on pro­mo­tes and faci­li­ta­tes the exch­an­ge of expe­ri­ence bet­ween the desi­gna­ted mar­ket sur­veil­lan­ce authorities.
(10) Mar­ket sur­veil­lan­ce aut­ho­ri­ties, assi­sted by the Com­mis­si­on and, whe­re appro­pria­te, the CSIRTs and ENISA, may pro­vi­de gui­dance and advice to eco­no­mic ope­ra­tors on the imple­men­ta­ti­on of this Regulation.
(11) Mar­ket sur­veil­lan­ce aut­ho­ri­ties shall, in accordance with Artic­le 11 of Regu­la­ti­on (EU) 2019/1020, inform con­su­mers whe­re to sub­mit com­plaints that may indi­ca­te non-com­pli­ance with this Regu­la­ti­on and pro­vi­de con­su­mers with infor­ma­ti­on on whe­re and how to access mecha­nisms to faci­li­ta­te the report­ing of vul­nerabi­li­ties, secu­ri­ty inci­dents and cyber thre­ats that may affect pro­ducts with digi­tal elements.
(12) Mar­ket sur­veil­lan­ce aut­ho­ri­ties shall, whe­re appro­pria­te, faci­li­ta­te coope­ra­ti­on with rele­vant stake­hol­ders, inclu­ding sci­en­ti­fic, rese­arch and con­su­mer organizations.
(13) Mar­ket sur­veil­lan­ce aut­ho­ri­ties shall report annu­al­ly to the Com­mis­si­on on the results of their respec­ti­ve mar­ket sur­veil­lan­ce acti­vi­ties. Desi­gna­ted mar­ket sur­veil­lan­ce aut­ho­ri­ties shall noti­fy the Com­mis­si­on and the rele­vant natio­nal com­pe­ti­ti­on aut­ho­ri­ties wit­hout delay of any infor­ma­ti­on obtai­ned in the cour­se of their mar­ket sur­veil­lan­ce acti­vi­ties that may be of inte­rest for the appli­ca­ti­on of Uni­on com­pe­ti­ti­on law.
(14) For devices with digi­tal ele­ments fal­ling within the scope of this Regu­la­ti­on and clas­si­fi­ed as high-risk AI-systems in accordance with Artic­le 6 of Regu­la­ti­on (EU) 2024/1689, the mar­ket sur­veil­lan­ce aut­ho­ri­ties desi­gna­ted for the pur­po­ses of that Regu­la­ti­on shall also be respon­si­ble for the mar­ket sur­veil­lan­ce acti­vi­ties requi­red under this Regu­la­ti­on. The mar­ket sur­veil­lan­ce aut­ho­ri­ties desi­gna­ted under Regu­la­ti­on (EU) 2024/1689 shall coope­ra­te, as appro­pria­te, with the mar­ket sur­veil­lan­ce aut­ho­ri­ties desi­gna­ted under this Regu­la­ti­on and, with regard to the super­vi­si­on of the imple­men­ta­ti­on of the noti­fi­ca­ti­on obli­ga­ti­ons under Artic­le 14 of this Regu­la­ti­on, with the CSIRTs desi­gna­ted as coor­di­na­tors and ENISA. In par­ti­cu­lar, the mar­ket sur­veil­lan­ce aut­ho­ri­ties desi­gna­ted under Regu­la­ti­on (EU) 2024/1689 shall inform the mar­ket sur­veil­lan­ce aut­ho­ri­ties desi­gna­ted under this Regu­la­ti­on of any fin­dings rele­vant to the per­for­mance of their tasks in rela­ti­on to the imple­men­ta­ti­on of this Regulation.
(15) In order to ensu­re the uni­form appli­ca­ti­on of this Regu­la­ti­on, the ADCO shall be set up in accordance with Artic­le 30(2) of Regu­la­ti­on (EU) 2019/1020. The ADCO shall be com­po­sed of repre­sen­ta­ti­ves of the desi­gna­ted mar­ket sur­veil­lan­ce aut­ho­ri­ties and, whe­re appro­pria­te, repre­sen­ta­ti­ves of the sin­gle liai­son offices. The ADCO shall also address spe­ci­fic que­sti­ons on mar­ket sur­veil­lan­ce acti­vi­ties rela­ted to the obli­ga­ti­ons for open source soft­ware administrators.
(16) Mar­ket sur­veil­lan­ce aut­ho­ri­ties shall moni­tor how manu­fac­tu­r­ers have applied the cri­te­ria refer­red to in Artic­le 13(8) when deter­mi­ning the peri­od of sup­port for their pro­ducts with digi­tal elements.
ADCO shall publish, in a publicly acce­s­si­ble and user-fri­end­ly form, rele­vant sta­tis­tics on cate­go­ries of pro­ducts incor­po­ra­ting digi­tal ele­ments, inclu­ding the avera­ge sup­port peri­ods estab­lished by the manu­fac­tu­rer in accordance with Artic­le 13(8), and pro­vi­de gui­dance con­tai­ning indi­ca­ti­ve sup­port peri­ods for cate­go­ries of pro­ducts incor­po­ra­ting digi­tal ele­ments. Whe­re the data indi­ca­te insuf­fi­ci­ent sup­port peri­ods for cer­tain cate­go­ries of devices incor­po­ra­ting digi­tal ele­ments, ADCO may recom­mend to mar­ket sur­veil­lan­ce aut­ho­ri­ties to focus their acti­vi­ties on such cate­go­ries of devices incor­po­ra­ting digi­tal elements. 
Artic­le 53 Access to data and documentation
To the ext­ent neces­sa­ry to assess the com­pli­ance of pro­ducts incor­po­ra­ting digi­tal ele­ments and the pro­ce­du­res estab­lished by their manu­fac­tu­r­ers with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I, mar­ket sur­veil­lan­ce aut­ho­ri­ties shall have access, on rea­so­ned request and in a lan­guage which they easi­ly under­stand, to the data neces­sa­ry to assess the design, deve­lo­p­ment, manu­fac­tu­ring and vul­nerabi­li­ty tre­at­ment of such pro­ducts, inclu­ding the rele­vant inter­nal docu­men­ta­ti­on of the eco­no­mic ope­ra­tor concerned. 
Artic­le 54 Natio­nal pro­ce­du­res for pro­ducts with digi­tal ele­ments that pose a signi­fi­cant cyber­se­cu­ri­ty risk
(1) Whe­re the mar­ket sur­veil­lan­ce aut­ho­ri­ty of a Mem­ber Sta­te has suf­fi­ci­ent rea­son to belie­ve that a pro­duct incor­po­ra­ting digi­tal ele­ments, inclu­ding vul­nerabi­li­ty hand­ling, pres­ents a signi­fi­cant cyber­se­cu­ri­ty risk, it shall imme­dia­te­ly car­ry out a con­for­mi­ty assess­ment of the pro­duct con­cer­ned against the requi­re­ments laid down in this Regu­la­ti­on, whe­re appro­pria­te in coope­ra­ti­on with the rele­vant CSIRT. The rele­vant eco­no­mic ope­ra­tors shall coope­ra­te as neces­sa­ry with the mar­ket sur­veil­lan­ce authority.
Whe­re, in the cour­se of that eva­lua­ti­on, the mar­ket sur­veil­lan­ce aut­ho­ri­ty finds that the device with digi­tal ele­ments does not com­ply with the requi­re­ments laid down in this Regu­la­ti­on, it shall wit­hout delay requi­re the rele­vant eco­no­mic ope­ra­tor to take all appro­pria­te cor­rec­ti­ve actions to bring the device with digi­tal ele­ments into com­pli­ance with tho­se requi­re­ments, to with­draw the device from the mar­ket or to recall it within a rea­sonable peri­od, com­men­su­ra­te with the natu­re of the cyber­se­cu­ri­ty risk, as it may pre­scri­be. The mar­ket sur­veil­lan­ce aut­ho­ri­ty shall inform the rele­vant noti­fi­ed body the­reof. Artic­le 18 of Regu­la­ti­on (EU) 2019/1020 shall app­ly to the cor­rec­ti­ve action.
(2) When deter­mi­ning the signi­fi­can­ce of a cyber­se­cu­ri­ty risk in accordance with para­graph 1, mar­ket sur­veil­lan­ce aut­ho­ri­ties shall also take into account non-tech­ni­cal risk fac­tors, in par­ti­cu­lar tho­se iden­ti­fi­ed as a result of coor­di­na­ted sup­p­ly chain secu­ri­ty risk assess­ments at Uni­on level in accordance with Artic­le 22 of Direc­ti­ve (EU) 2022/2555. Whe­re a mar­ket sur­veil­lan­ce aut­ho­ri­ty has rea­sonable grounds to belie­ve that a pro­duct with digi­tal ele­ments poses a signi­fi­cant cyber­se­cu­ri­ty risk in light of non-tech­ni­cal risk fac­tors, it shall inform the com­pe­tent aut­ho­ri­ties desi­gna­ted or estab­lished in accordance with Artic­le 8 of Direc­ti­ve (EU) 2022/2555 and coope­ra­te with tho­se aut­ho­ri­ties as necessary.
(3) Whe­re the mar­ket sur­veil­lan­ce aut­ho­ri­ty con­siders that the non-com­pli­ance is not rest­ric­ted to its natio­nal ter­ri­to­ry, it shall inform the Com­mis­si­on and the other Mem­ber Sta­tes of the results of the inve­sti­ga­ti­on and of the actions it has requi­red the eco­no­mic ope­ra­tor to take.
(4) The eco­no­mic ope­ra­tor shall ensu­re that all appro­pria­te cor­rec­ti­ve action is taken in respect of all the pro­ducts with digi­tal ele­ments con­cer­ned that it has made available on the mar­ket throug­hout the Union.
(5) Whe­re the eco­no­mic ope­ra­tor does not take ade­qua­te cor­rec­ti­ve action within the peri­od refer­red to in the second sub­pa­ra­graph of para­graph 1, the mar­ket sur­veil­lan­ce aut­ho­ri­ties shall take all appro­pria­te pro­vi­sio­nal mea­su­res to pro­hi­bit or rest­rict the pro­duct with digi­tal ele­ments being made available on their natio­nal mar­ket, to with­draw the pro­duct from that mar­ket or to recall it.
That aut­ho­ri­ty shall noti­fy the Com­mis­si­on and the other Mem­ber Sta­tes of tho­se mea­su­res wit­hout delay.
(6) The infor­ma­ti­on refer­red to in para­graph 5 shall include all available details, in par­ti­cu­lar the data neces­sa­ry for the iden­ti­fi­ca­ti­on of the non-com­pli­ant pro­duct with digi­tal ele­ments, the ori­gin of that pro­duct with digi­tal ele­ments, the natu­re of the non-com­pli­ance alle­ged and the risk invol­ved, the natu­re and dura­ti­on of the natio­nal mea­su­res taken and the argu­ments put for­ward by the rele­vant eco­no­mic ope­ra­tor. The mar­ket sur­veil­lan­ce aut­ho­ri­ty shall indi­ca­te in par­ti­cu­lar whe­ther the non-com­pli­ance is due to one or more of the following:
a) The device with digi­tal ele­ments or the pro­ce­du­res defi­ned by the manu­fac­tu­rer do not meet the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I;
b) short­co­mings in the har­mo­ni­zed stan­dards, the Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­mes or the com­mon spe­ci­fi­ca­ti­ons refer­red to in Artic­le 27.
(7) The mar­ket sur­veil­lan­ce aut­ho­ri­ties of the Mem­ber Sta­tes, other than the one that initia­ted the pro­ce­du­re, shall imme­dia­te­ly inform the Com­mis­si­on and the other Mem­ber Sta­tes of any mea­su­res taken and of any addi­tio­nal infor­ma­ti­on at their dis­po­sal rela­ting to the non-com­pli­ance of the pro­duct con­cer­ned with digi­tal ele­ments, as well as of their objec­tions in the event of dis­agree­ment with the natio­nal mea­su­re noti­fi­ed to them.
(8) Whe­re neither a Mem­ber Sta­te nor the Com­mis­si­on rai­ses an objec­tion to a pro­vi­sio­nal mea­su­re taken by a Mem­ber Sta­te within three months of rece­ipt of the noti­fi­ca­ti­on refer­red to in para­graph 5 of this Artic­le, that mea­su­re shall be dee­med justi­fi­ed. This shall be wit­hout pre­ju­di­ce to the pro­ce­du­ral rights of the eco­no­mic ope­ra­tor con­cer­ned under Artic­le 18 of Regu­la­ti­on (EU) 2019/1020.
(9) The mar­ket sur­veil­lan­ce aut­ho­ri­ties of all Mem­ber Sta­tes shall ensu­re that appro­pria­te rest­ric­ti­ve mea­su­res are taken wit­hout delay in respect of the pro­duct with digi­tal ele­ments con­cer­ned, for exam­p­le by with­dra­wing that pro­duct from their market.
Artic­le 55 Uni­on safe­guard clau­se procedure
(1) Whe­re, within three months of rece­ipt of the noti­fi­ca­ti­on refer­red to in Artic­le 54(5), a Mem­ber Sta­te objects to a mea­su­re taken by ano­ther Mem­ber Sta­te or whe­re the Com­mis­si­on con­siders a mea­su­re to be incom­pa­ti­ble with Uni­on law, the Com­mis­si­on shall enter into con­sul­ta­ti­ons with the Mem­ber Sta­te or eco­no­mic ope­ra­tor con­cer­ned wit­hout delay and shall exami­ne the natio­nal mea­su­re. On the basis of the results of that exami­na­ti­on, the Com­mis­si­on shall, within nine months of rece­ipt of the infor­ma­ti­on refer­red to in Artic­le 54(5), deci­de whe­ther the natio­nal mea­su­re is justi­fi­ed or not and com­mu­ni­ca­te that decis­i­on to the Mem­ber Sta­te concerned.
(2) If the natio­nal mea­su­re is con­side­red justi­fi­ed, all Mem­ber Sta­tes shall take the neces­sa­ry mea­su­res to ensu­re that the non-com­pli­ant pro­duct with digi­tal ele­ments is with­drawn from their mar­ket and shall inform the Com­mis­si­on accor­din­gly. If the natio­nal mea­su­re is con­side­red unju­sti­fi­ed, the Mem­ber Sta­te con­cer­ned shall with­draw it.
(3) If the natio­nal mea­su­re is con­side­red justi­fi­ed and the non-com­pli­ance of the pro­duct with digi­tal ele­ments is attri­bu­ted to short­co­mings in the har­mo­ni­zed stan­dards, the Com­mis­si­on shall initia­te the pro­ce­du­re laid down in Artic­le 11 of Regu­la­ti­on (EU) No 1025/2012.
(4) Whe­re the natio­nal mea­su­re is con­side­red justi­fi­ed and the non-com­pli­ance of the pro­duct with digi­tal ele­ments is attri­bu­ted to short­co­mings in a Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­me refer­red to in Artic­le 27, the Com­mis­si­on shall exami­ne whe­ther a dele­ga­ted act adopted pur­su­ant to Artic­le 27(9) con­fer­ring a pre­sump­ti­on of con­for­mi­ty in rela­ti­on to that cer­ti­fi­ca­ti­on sche­me should be amen­ded or repealed.
(5) Whe­re the natio­nal mea­su­re is con­side­red justi­fi­ed and the non-com­pli­ance of the pro­duct with digi­tal ele­ments is attri­bu­ted to short­co­mings in com­mon spe­ci­fi­ca­ti­ons refer­red to in Artic­le 27, the Com­mis­si­on shall exami­ne whe­ther an imple­men­ting act adopted pur­su­ant to Artic­le 27(2), in which the com­mon spe­ci­fi­ca­ti­ons have been laid down, should be amen­ded or repealed.
Artic­le 56 Uni­on-level pro­ce­du­res for pro­ducts with digi­tal ele­ments posing a signi­fi­cant cyber­se­cu­ri­ty risk
(1) Whe­re the Com­mis­si­on has suf­fi­ci­ent rea­son to belie­ve, inclu­ding on the basis of infor­ma­ti­on pro­vi­ded by ENISA, that a device with digi­tal ele­ments pre­sen­ting a signi­fi­cant cyber­se­cu­ri­ty risk does not com­ply with the requi­re­ments of this Regu­la­ti­on, it shall inform the rele­vant mar­ket sur­veil­lan­ce aut­ho­ri­ties. Whe­re the mar­ket sur­veil­lan­ce aut­ho­ri­ties car­ry out a con­for­mi­ty assess­ment of that device with digi­tal ele­ments which may pre­sent a signi­fi­cant cyber­se­cu­ri­ty risk as regards its com­pli­ance with the requi­re­ments of this Regu­la­ti­on, the pro­ce­du­res refer­red to in Artic­les 54 and 55 shall apply.
(2) Whe­re the Com­mis­si­on has suf­fi­ci­ent rea­son to belie­ve that a pro­duct with digi­tal ele­ments poses a signi­fi­cant cyber­se­cu­ri­ty risk due to non-tech­ni­cal risk fac­tors, it shall inform the rele­vant mar­ket sur­veil­lan­ce aut­ho­ri­ties and, whe­re appro­pria­te, the com­pe­tent aut­ho­ri­ties desi­gna­ted or estab­lished pur­su­ant to Artic­le 8 of Direc­ti­ve (EU) 2022/2555 and coope­ra­te with tho­se aut­ho­ri­ties as neces­sa­ry. The Com­mis­si­on shall also assess the rele­van­ce of the iden­ti­fi­ed risks for that pro­duct with digi­tal ele­ments with regard to its tasks rela­ted to the coor­di­na­ted risk assess­ments on sup­p­ly chain secu­ri­ty at Uni­on level pur­su­ant to Artic­le 22 of Direc­ti­ve (EU) 2022/2555 and, whe­re neces­sa­ry, con­sult the Coope­ra­ti­on Group estab­lished pur­su­ant to Artic­le 14 of Direc­ti­ve (EU) 2022/2555 and ENISA.
(3) In cir­cum­stances justi­fy­ing imme­dia­te inter­ven­ti­on in order to pre­ser­ve the pro­per func­tio­ning of the inter­nal mar­ket, and whe­re the Com­mis­si­on has suf­fi­ci­ent rea­son to belie­ve that the pro­duct with digi­tal ele­ments refer­red to in para­graph 1 con­ti­nues not to com­ply with the requi­re­ments of this Regu­la­ti­on and the rele­vant mar­ket sur­veil­lan­ce aut­ho­ri­ties have not taken effec­ti­ve action, the Com­mis­si­on shall car­ry out a com­pli­ance assess­ment and may request ENISA to car­ry out an ana­ly­sis to sub­stan­tia­te the assess­ment. The Com­mis­si­on shall inform the rele­vant mar­ket sur­veil­lan­ce aut­ho­ri­ties the­reof. The rele­vant eco­no­mic ope­ra­tors shall coope­ra­te with ENISA to the ext­ent necessary.
(4) On the basis of the assess­ment refer­red to in para­graph 3, the Com­mis­si­on may deter­mi­ne that a cor­rec­ti­ve or rest­ric­ti­ve mea­su­re at Uni­on level is neces­sa­ry. For that pur­po­se, it shall imme­dia­te­ly con­sult the Mem­ber Sta­tes and the eco­no­mic ope­ra­tor or ope­ra­tors concerned.
(5) On the basis of the con­sul­ta­ti­on refer­red to in para­graph 4 of this Artic­le, the Com­mis­si­on may adopt imple­men­ting acts con­cer­ning cor­rec­ti­ve or rest­ric­ti­ve mea­su­res at Uni­on level, inclu­ding requi­ring the with­dra­wal from the mar­ket or recall of the digi­tal items con­cer­ned within a peri­od pro­por­tio­na­te to the natu­re of the risk. Tho­se imple­men­ting acts shall be adopted in accordance with the exami­na­ti­on pro­ce­du­re refer­red to in Artic­le 62(2).
(6) The Com­mis­si­on shall inform the rele­vant eco­no­mic ope­ra­tor or ope­ra­tors wit­hout delay of the imple­men­ting acts refer­red to in para­graph 5. Mem­ber Sta­tes shall imple­ment tho­se imple­men­ting acts wit­hout delay and inform the Com­mis­si­on thereof.
(7) Para­graphs 3 to 6 shall app­ly for the dura­ti­on of the excep­tio­nal cir­cum­stances that justi­fi­ed the Commission’s inter­ven­ti­on, as long as the pro­duct con­cer­ned with digi­tal ele­ments has not been brought into con­for­mi­ty with this Regulation.
Artic­le 57 Com­pli­ant pro­ducts with digi­tal ele­ments that pose a signi­fi­cant cyber­se­cu­ri­ty risk
(1) The mar­ket sur­veil­lan­ce aut­ho­ri­ty of a Mem­ber Sta­te shall requi­re an eco­no­mic ope­ra­tor to take all appro­pria­te mea­su­res whe­re, having car­ri­ed out an eva­lua­ti­on in accordance with Artic­le 54, it finds that a device with digi­tal ele­ments and the pro­ce­du­res estab­lished by the manu­fac­tu­rer, alt­hough com­pli­ant with this Regu­la­ti­on, pres­ents a signi­fi­cant cyber­se­cu­ri­ty risk and the fol­lo­wing risks:
a) Risk to the health or safe­ty of persons,
b) Risk to the ful­fill­ment of obli­ga­ti­ons under Uni­on or natio­nal law for the pro­tec­tion of fun­da­men­tal rights,
c) risk to the avai­la­bi­li­ty, authen­ti­ci­ty, inte­gri­ty or con­fi­den­tia­li­ty of ser­vices pro­vi­ded through an elec­tro­nic infor­ma­ti­on system by essen­ti­al enti­ties refer­red to in Artic­le 3(1) of Direc­ti­ve (EU) 2022/2555; or
d) Risk to other aspects of the pro­tec­tion of public interests.
The mea­su­res refer­red to in the first sub­pa­ra­graph may include mea­su­res to ensu­re that the device with digi­tal ele­ments con­cer­ned and the pro­ce­du­res estab­lished by the manu­fac­tu­rer no lon­ger pre­sent the rele­vant risks when the device with digi­tal ele­ments con­cer­ned is made available on the mar­ket, with­drawn from the mar­ket or recal­led, and shall be pro­por­tio­na­te to the natu­re of tho­se risks.
(2) The manu­fac­tu­rer or other rele­vant eco­no­mic ope­ra­tor shall ensu­re that cor­rec­ti­ve action is taken in respect of all the pro­ducts with digi­tal ele­ments con­cer­ned that it has made available on the mar­ket throug­hout the Uni­on within the time limit set by the mar­ket sur­veil­lan­ce aut­ho­ri­ty of the Mem­ber Sta­te refer­red to in para­graph 1.
(3) The Mem­ber Sta­te shall imme­dia­te­ly inform the Com­mis­si­on and the other Mem­ber Sta­tes of any mea­su­res taken pur­su­ant to para­graph 1. That infor­ma­ti­on shall include all available details, in par­ti­cu­lar the data iden­ti­fy­ing the pro­duct with digi­tal ele­ments con­cer­ned, its ori­gin and sup­p­ly chain, the natu­re of the risk invol­ved and the natu­re and dura­ti­on of the natio­nal mea­su­res taken.
(4) The Com­mis­si­on shall wit­hout delay enter into con­sul­ta­ti­on with the Mem­ber Sta­tes and the rele­vant eco­no­mic ope­ra­tor and shall car­ry out an exami­na­ti­on of the natio­nal mea­su­res taken. On the basis of the results of that exami­na­ti­on, the Com­mis­si­on shall deci­de whe­ther the mea­su­re is justi­fi­ed or not and, if neces­sa­ry, pro­po­se appro­pria­te measures.
(5) The Com­mis­si­on shall address the decis­i­on refer­red to in para­graph 4 to the Mem­ber States.
(6) Whe­re the Com­mis­si­on has suf­fi­ci­ent rea­son to belie­ve, inclu­ding on the basis of infor­ma­ti­on from ENISA, that a device incor­po­ra­ting digi­tal ele­ments, alt­hough com­ply­ing with this Regu­la­ti­on, pres­ents the risks refer­red to in para­graph 1 of this Artic­le, it shall inform the rele­vant mar­ket sur­veil­lan­ce aut­ho­ri­ty or aut­ho­ri­ties and may request them to car­ry out an eva­lua­ti­on and app­ly the pro­ce­du­res refer­red to in Artic­le 54 and in para­graphs 1, 2 and 3 of this Article.
(7) In cir­cum­stances justi­fy­ing imme­dia­te inter­ven­ti­on in order to pre­ser­ve the pro­per func­tio­ning of the inter­nal mar­ket, and whe­re the Com­mis­si­on has suf­fi­ci­ent rea­son to belie­ve that the pro­duct with digi­tal ele­ments refer­red to in para­graph 6 con­ti­nues to pre­sent the risks refer­red to in para­graph 1 and the rele­vant mar­ket sur­veil­lan­ce aut­ho­ri­ties have not taken effec­ti­ve action, the Com­mis­si­on shall car­ry out an assess­ment of the risks posed by that pro­duct with digi­tal ele­ments and may request ENISA to car­ry out an ana­ly­sis to sub­stan­tia­te that assess­ment and shall inform the rele­vant mar­ket sur­veil­lan­ce aut­ho­ri­ties the­reof. The rele­vant eco­no­mic ope­ra­tors shall coope­ra­te with ENISA to the ext­ent necessary.
(8) On the basis of the assess­ment refer­red to in para­graph 7, the Com­mis­si­on may deter­mi­ne that a cor­rec­ti­ve or rest­ric­ti­ve mea­su­re at Uni­on level is neces­sa­ry. For that pur­po­se, it shall imme­dia­te­ly con­sult the Mem­ber Sta­tes and the eco­no­mic ope­ra­tor or ope­ra­tors concerned.
(9) On the basis of the con­sul­ta­ti­on refer­red to in para­graph 8 of this Artic­le, the Com­mis­si­on may adopt imple­men­ting acts con­cer­ning cor­rec­ti­ve or rest­ric­ti­ve mea­su­res at Uni­on level, inclu­ding requi­ring the with­dra­wal from the mar­ket or recall of the digi­tal items con­cer­ned within a peri­od pro­por­tio­na­te to the natu­re of the risk. Tho­se imple­men­ting acts shall be adopted in accordance with the exami­na­ti­on pro­ce­du­re refer­red to in Artic­le 62(2).
(10) The Com­mis­si­on shall inform the rele­vant eco­no­mic ope­ra­tor or ope­ra­tors wit­hout delay of the imple­men­ting acts refer­red to in para­graph 9. Mem­ber Sta­tes shall imple­ment tho­se imple­men­ting acts wit­hout delay and inform the Com­mis­si­on thereof.
(11) Para­graphs 6 to 10 shall app­ly for the dura­ti­on of the excep­tio­nal cir­cum­stances that justi­fi­ed the Commission’s inter­ven­ti­on and as long as the pro­duct con­cer­ned with digi­tal ele­ments con­ti­nues to pre­sent the risks refer­red to in para­graph 1.
Artic­le 58 For­mal non-conformity
(1) Whe­re the mar­ket sur­veil­lan­ce aut­ho­ri­ty of a Mem­ber Sta­te makes one of the fol­lo­wing fin­dings, it shall requi­re the manu­fac­tu­rer con­cer­ned to reme­dy the non-com­pli­ance in question:
a) the CE mar­king has been affi­xed in non-com­pli­ance with Artic­les 29 and 30;
b) the CE mar­king has not been affixed;
c) the EU Decla­ra­ti­on of Con­for­mi­ty has not been issued;
d) the EU Decla­ra­ti­on of Con­for­mi­ty has not been pro­per­ly issued;
e) the iden­ti­fi­ca­ti­on num­ber of the noti­fi­ed body invol­ved in the con­for­mi­ty assess­ment pro­ce­du­re, if appli­ca­ble, has not been affixed;
f) the tech­ni­cal docu­men­ta­ti­on is eit­her not available or not complete.
(2) Whe­re the non-com­pli­ance refer­red to in para­graph 1 per­sists, the Mem­ber Sta­te con­cer­ned shall take all appro­pria­te mea­su­res to rest­rict or pro­hi­bit the pro­duct with digi­tal ele­ments being made available on the mar­ket or ensu­re that it is recal­led or with­drawn from the market.
Artic­le 59 Joint acti­vi­ties of mar­ket sur­veil­lan­ce authorities
(1) Mar­ket sur­veil­lan­ce aut­ho­ri­ties may agree with other rele­vant aut­ho­ri­ties to car­ry out joint acti­vi­ties to ensu­re cyber­se­cu­ri­ty and con­su­mer pro­tec­tion in rela­ti­on to spe­ci­fic pro­ducts with digi­tal ele­ments pla­ced or made available on the mar­ket, in par­ti­cu­lar in rela­ti­on to pro­ducts with digi­tal ele­ments whe­re cyber­se­cu­ri­ty risks are fre­quent­ly identified.
(2) The Com­mis­si­on or ENISA shall pro­po­se joint com­pli­ance veri­fi­ca­ti­on acti­vi­ties to be car­ri­ed out by mar­ket sur­veil­lan­ce aut­ho­ri­ties on the basis of indi­ca­ti­ons or infor­ma­ti­on that pro­ducts incor­po­ra­ting digi­tal ele­ments fal­ling within the scope of this Regu­la­ti­on may not com­ply with the requi­re­ments of this Regu­la­ti­on in seve­ral Mem­ber States.
(3) Mar­ket sur­veil­lan­ce aut­ho­ri­ties and, whe­re appro­pria­te, the Com­mis­si­on shall ensu­re that the joint acti­vi­ty agree­ment does not lead to unfair com­pe­ti­ti­on bet­ween eco­no­mic ope­ra­tors and does not affect the objec­ti­vi­ty, inde­pen­dence or impar­tia­li­ty of the par­ties to the agreement.
(4) A mar­ket sur­veil­lan­ce aut­ho­ri­ty may use any infor­ma­ti­on it has obtai­ned in the cour­se of joint acti­vi­ties that were part of an inve­sti­ga­ti­on it car­ri­ed out.
(5) The mar­ket sur­veil­lan­ce aut­ho­ri­ty con­cer­ned and, whe­re appro­pria­te, the Com­mis­si­on shall make the agree­ment on joint acti­vi­ties, inclu­ding the names of the par­ties invol­ved, available to the public.
Artic­le 60 Coor­di­na­ted checks (sweeps)
(1) Mar­ket sur­veil­lan­ce aut­ho­ri­ties shall car­ry out simul­ta­neous coor­di­na­ted inspec­tions (’sweeps’) of cer­tain pro­ducts incor­po­ra­ting digi­tal ele­ments to veri­fy com­pli­ance with this Regu­la­ti­on or to detect inf­rin­ge­ments of this Regu­la­ti­on. The­se sweeps may also include the inspec­tion of pro­ducts with digi­tal ele­ments purcha­sed under a fal­se identity.
(2) Unless other­wi­se agreed by the mar­ket sur­veil­lan­ce aut­ho­ri­ties con­cer­ned, such sweeps shall be coor­di­na­ted by the Com­mis­si­on. The coor­di­na­tor of the sweep shall publish the aggre­ga­ted results as appropriate.
(3) Whe­re ENISA, in the per­for­mance of its tasks, iden­ti­fi­es cate­go­ries of pro­ducts with digi­tal ele­ments for which sweeps may be orga­ni­zed, inclu­ding on the basis of noti­fi­ca­ti­ons recei­ved pur­su­ant to Artic­le 14(1) and (3), it shall sub­mit a pro­po­sal for sweeps to the coor­di­na­tor refer­red to in para­graph 2 of this Artic­le for con­side­ra­ti­on by the mar­ket sur­veil­lan­ce authorities.
(4) When car­ry­ing out sweeps, the mar­ket sur­veil­lan­ce aut­ho­ri­ties invol­ved may use the inve­sti­ga­to­ry powers laid down in Artic­les 52 to 58 and other powers con­fer­red on them by natio­nal law.
(5) Mar­ket sur­veil­lan­ce aut­ho­ri­ties may invi­te Com­mis­si­on offi­ci­als and other accom­pany­ing per­sons aut­ho­ri­zed by the Com­mis­si­on to par­ti­ci­pa­te in sweeps.

Chap­ter VI Dele­ga­ted powers and com­mit­tee procedures

Artic­le 61 Exer­cise of the dele­ga­ti­on of power
(1) The power to adopt dele­ga­ted acts is con­fer­red on the Com­mis­si­on sub­ject to the con­di­ti­ons laid down in this Article.
(2) The power to adopt dele­ga­ted acts refer­red to in the second sub­pa­ra­graph of Artic­le 2(5), Artic­le 7(3), Artic­le 8(1) and (2), the fourth sub­pa­ra­graph of Artic­le 13(8), Artic­le 14(9), Artic­le 25, Artic­le 27(9), Artic­le 28(5) and Artic­le 31(5) shall be con­fer­red on the Com­mis­si­on for a peri­od of five years from 10 Decem­ber 2024. The Com­mis­si­on shall draw up a report in respect of the dele­ga­ti­on of power not later than nine months befo­re the end of the five-year peri­od. The dele­ga­ti­on of power shall be taci­t­ly exten­ded for peri­ods of an iden­ti­cal dura­ti­on, unless the Euro­pean Par­lia­ment or the Coun­cil oppo­ses such exten­si­on not later than three months befo­re the end of each period.
(3) The dele­ga­ti­on of power refer­red to in the second sub­pa­ra­graph of Artic­le 2(5), Artic­le 7(3), Artic­le 8(1) and (2), the fourth sub­pa­ra­graph of Artic­le 13(8), Artic­le 14(9), Artic­le 25, Artic­le 27(9), Artic­le 28(5) and Artic­le 31(5) may be revo­ked at any time by the Euro­pean Par­lia­ment or by the Coun­cil. A decis­i­on of revo­ca­ti­on shall put an end to the dele­ga­ti­on of the power spe­ci­fi­ed in that decis­i­on. It shall take effect the day fol­lo­wing the publi­ca­ti­on of the decis­i­on in the Offi­ci­al Jour­nal of the Euro­pean Uni­on or at a later date spe­ci­fi­ed the­r­ein. The decis­i­on of revo­ca­ti­on shall not affect the vali­di­ty of any dele­ga­ted acts alre­a­dy in force.
(4) Befo­re adop­ting a dele­ga­ted act, the Com­mis­si­on shall con­sult experts desi­gna­ted by each Mem­ber Sta­te in accordance with the prin­ci­ples laid down in the Inter­in­sti­tu­tio­nal Agree­ment of April 13, 2016 on Bet­ter Law-Making.
(5) As soon as it adopts a dele­ga­ted act, the Com­mis­si­on shall noti­fy it simul­ta­neous­ly to the Euro­pean Par­lia­ment and to the Council.
(6) A dele­ga­ted act adopted pur­su­ant to the second sub­pa­ra­graph of Artic­le 2(5), Artic­le 7(3), Artic­le 8(1) or (2), the fourth sub­pa­ra­graph of Artic­le 13(8), Artic­le 14(9), Artic­le 25, Artic­le 27(9), Artic­le 28(5) or Artic­le 31(5) shall enter into force only if no objec­tion has been expres­sed eit­her by the Euro­pean Par­lia­ment or the Coun­cil within a peri­od of two months of noti­fi­ca­ti­on of that act to the Euro­pean Par­lia­ment and the Coun­cil or if, befo­re the expiry of that peri­od, the Euro­pean Par­lia­ment and the Coun­cil have both infor­med the Com­mis­si­on that they will not object. That peri­od shall be exten­ded by two months at the initia­ti­ve of the Euro­pean Par­lia­ment or the Council.
Artic­le 62 Com­mit­tee procedure
(1) The Com­mis­si­on shall be assi­sted by a com­mit­tee. This com­mit­tee shall be a com­mit­tee within the mea­ning of Regu­la­ti­on (EU) No 182/2011.
(2) Whe­re refe­rence is made to this para­graph, Artic­le 5 of Regu­la­ti­on (EU) No 182/2011 shall apply.
(3) If the opi­ni­on of the Com­mit­tee is obtai­ned by writ­ten pro­ce­du­re, the pro­ce­du­re shall be ter­mi­na­ted wit­hout result if the Chair of the Com­mit­tee so deci­des within the time limit for deli­very of the opi­ni­on or if a mem­ber of the Com­mit­tee so requests.

Chap­ter VII Con­fi­den­tia­li­ty and sanctions 

Artic­le 63 Confidentiality
(1) All par­ties invol­ved in the appli­ca­ti­on of this Regu­la­ti­on shall respect the con­fi­den­tia­li­ty of the infor­ma­ti­on and data of which they beco­me awa­re in the cour­se of their duties and acti­vi­ties, and shall in par­ti­cu­lar pro­tect the following:
a) Intellec­tu­al pro­per­ty rights, con­fi­den­ti­al busi­ness infor­ma­ti­on or trade secrets of natu­ral or legal per­sons, inclu­ding source code, with the excep­ti­on of the cases refer­red to in Artic­le 5 of Direc­ti­ve (EU) 2016/943 of the Euro­pean Par­lia­ment and of the Coun­cil (37),
b) the effec­ti­ve imple­men­ta­ti­on of this Regu­la­ti­on, in par­ti­cu­lar for the pur­po­ses of inspec­tions, inve­sti­ga­ti­ons or audits,
c) public and natio­nal secu­ri­ty interests,
d) the inte­gri­ty of cri­mi­nal or admi­ni­stra­ti­ve proceedings.
(2) Wit­hout pre­ju­di­ce to para­graph 1, infor­ma­ti­on exch­an­ged on a con­fi­den­ti­al basis bet­ween mar­ket sur­veil­lan­ce aut­ho­ri­ties or with the Com­mis­si­on shall not be dis­c­lo­sed wit­hout the pri­or con­sent of the mar­ket sur­veil­lan­ce aut­ho­ri­ty from which the infor­ma­ti­on originated.
(3) Para­graphs 1 and 2 shall not affect the rights and obli­ga­ti­ons of the Com­mis­si­on, Mem­ber Sta­tes and noti­fi­ed bodies in rela­ti­on to the exch­an­ge of infor­ma­ti­on and the dis­se­mi­na­ti­on of alerts, nor the obli­ga­ti­ons of data sub­jects to pro­vi­de infor­ma­ti­on on the basis of the cri­mi­nal law of the Mem­ber States.
(4) The Com­mis­si­on and the Mem­ber Sta­tes may, whe­re neces­sa­ry, exch­an­ge sen­si­ti­ve infor­ma­ti­on with rele­vant aut­ho­ri­ties of third count­ries with which they have con­clu­ded bila­te­ral or mul­ti­la­te­ral con­fi­den­tia­li­ty agree­ments and which ensu­re an ade­qua­te level of protection.
Artic­le 64 Sanctions
(1) Mem­ber Sta­tes shall lay down rules on pen­al­ties appli­ca­ble to inf­rin­ge­ments of this Regu­la­ti­on and shall take all mea­su­res neces­sa­ry to ensu­re that they are imple­men­ted. The pen­al­ties pro­vi­ded for must be effec­ti­ve, pro­por­tio­na­te and dissua­si­ve. The Mem­ber Sta­tes shall noti­fy tho­se pro­vi­si­ons and mea­su­res to the Com­mis­si­on wit­hout delay and shall noti­fy it wit­hout delay of any sub­se­quent amend­ment affec­ting them.
(2) Non-com­pli­ance with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I or brea­ches of the obli­ga­ti­ons set out in Artic­les 13 and 14 shall be sub­ject to fines of up to EUR 15 000 000 or, in the case of com­pa­nies, up to 2.5 % of the total world­wi­de annu­al tur­no­ver of the pre­ce­ding finan­cial year, whi­che­ver is higher.
(3) Inf­rin­ge­ments of the obli­ga­ti­ons laid down in Artic­les 18 to 23, Artic­le 28, Artic­le 30(1) to (4), Artic­le 31(1) to (4), Artic­le 32(1), (2) and (3), Artic­le 33(5) and Artic­les 39, 41, 47, 49 and 53 shall be sub­ject to fines of up to EUR 10 000 000 or, in the case of under­ta­kings, up to 2 % of the total world­wi­de annu­al tur­no­ver in the pre­ce­ding busi­ness year, whi­che­ver is the higher.
(4) Whe­re fal­se, incom­ple­te or mis­lea­ding infor­ma­ti­on is pro­vi­ded to noti­fi­ed bodies and mar­ket sur­veil­lan­ce aut­ho­ri­ties in respon­se to their requests for infor­ma­ti­on, fines of up to EUR 5 000 000 or, in the case of com­pa­nies, up to 1 % of the total annu­al world­wi­de tur­no­ver in the pre­ce­ding busi­ness year, whi­che­ver is the hig­her, will be imposed.
(5) When set­ting the fine, all rele­vant cir­cum­stances of the spe­ci­fic situa­ti­on and the fol­lo­wing are duly taken into account in each indi­vi­du­al case:
a) Type, seve­ri­ty and dura­ti­on of the vio­la­ti­on and its consequences,
b) whe­ther the same or other mar­ket sur­veil­lan­ce aut­ho­ri­ties have alre­a­dy impo­sed fines on the same eco­no­mic ope­ra­tor for a simi­lar infringement,
c) Size, in par­ti­cu­lar with regard to micro, small and medi­um-sized enter­pri­ses, inclu­ding start-ups, and mar­ket share of the eco­no­mic ope­ra­tor that com­mit­ted the infringement.
(6) Mar­ket sur­veil­lan­ce aut­ho­ri­ties that impo­se fines shall noti­fy the impo­si­ti­on of a fine to the mar­ket sur­veil­lan­ce aut­ho­ri­ties of the other Mem­ber Sta­tes through the infor­ma­ti­on and com­mu­ni­ca­ti­on system refer­red to in Artic­le 34 of Regu­la­ti­on (EU) 2019/1020.
(7) Each Mem­ber Sta­te shall lay down rules on whe­ther and to what ext­ent admi­ni­stra­ti­ve fines may be impo­sed on public aut­ho­ri­ties and bodies estab­lished in that Mem­ber State.
(8) Depen­ding on the legal system of the Mem­ber Sta­te con­cer­ned, the rules on fines may be applied in such a way that the fines are impo­sed by com­pe­tent natio­nal courts or by other bodies in accordance with the allo­ca­ti­on of juris­dic­tion estab­lished at natio­nal level in the Mem­ber Sta­tes. The appli­ca­ti­on of tho­se rules in tho­se Mem­ber Sta­tes shall have equi­va­lent effect.
(9) Fines may be impo­sed in addi­ti­on to other cor­rec­ti­ve or rest­ric­ti­ve mea­su­res impo­sed by mar­ket sur­veil­lan­ce aut­ho­ri­ties for the same inf­rin­ge­ment, depen­ding on the cir­cum­stances of the indi­vi­du­al case.
(10) By way of dero­ga­ti­on from para­graphs 3 to 9, the fines refer­red to in the­se para­graphs shall not app­ly to
a) pro­du­cers that qua­li­fy as micro or small enter­pri­ses in rela­ti­on to non-com­pli­ance with the time limit refer­red to in Artic­le 14(2)(a) or Artic­le 14(4)(a),
b) admi­ni­stra­tor of open source soft­ware for any vio­la­ti­on of this regulation.
Artic­le 65 Repre­sen­ta­ti­ve actions
Direc­ti­ve (EU) 2020/1828 shall app­ly to repre­sen­ta­ti­ve actions brought against inf­rin­ge­ments by eco­no­mic ope­ra­tors of the pro­vi­si­ons of this Regu­la­ti­on which harm or threa­ten to harm the coll­ec­ti­ve inte­rests of consumers. 

Chap­ter VIII Tran­si­tio­nal and final provisions

Artic­le 66 Amend­ment to Regu­la­ti­on (EU) 2019/1020
In Annex I to Regu­la­ti­on (EU) 2019/1020, the fol­lo­wing point is added: “72. Regu­la­ti­on (EU) 2024/2847 of the Euro­pean Par­lia­ment and of the Coun­cil (*1).
Artic­le 67 Amend­ment to Direc­ti­ve (EU) 2020/1828
In Annex I to Direc­ti­ve (EU) 2020/1828, the fol­lo­wing point is added “(69) Regu­la­ti­on (EU) 2024/2847 of the Euro­pean Par­lia­ment and of the Coun­cil (*2).
Artic­le 68 Amend­ments to Regu­la­ti­on (EU) No 168/2013
In Part C1 of Annex II to Regu­la­ti­on (EU) No 168/2013 of the Euro­pean Par­lia­ment and of the Coun­cil (38), the fol­lo­wing ent­ry is added to the table: “[…]” 
Artic­le 69 Tran­si­tio­nal provisions
(1) EU-type exami­na­ti­on cer­ti­fi­ca­tes and appr­ovals issued in rela­ti­on to cyber­se­cu­ri­ty requi­re­ments for pro­ducts with digi­tal ele­ments that are sub­ject to Uni­on har­mo­nizati­on legis­la­ti­on other than this Regu­la­ti­on shall remain valid until 11 June 2028, unless they expi­re befo­re that date or unless other­wi­se pro­vi­ded for in other Uni­on har­mo­nizati­on legis­la­ti­on, in which case they shall remain valid in accordance with the lat­ter legislation.
(2) Pro­ducts with digi­tal ele­ments pla­ced on the mar­ket befo­re Decem­ber 11, 2027 shall be sub­ject to the requi­re­ments laid down in this Regu­la­ti­on only if tho­se pro­ducts are sub­ject to a sub­stan­ti­al modi­fi­ca­ti­on after that date.
(3) By way of dero­ga­ti­on from para­graph 2 of this Artic­le, the obli­ga­ti­ons laid down in Artic­le 14 shall app­ly to all devices with digi­tal ele­ments that fall within the scope of this Regu­la­ti­on and were pla­ced on the mar­ket befo­re Decem­ber 11, 2027.
Artic­le 70 Assess­ment and verification
(1) By Decem­ber 11, 2030, and every four years the­re­af­ter, the Com­mis­si­on shall sub­mit a report to the Euro­pean Par­lia­ment and the Coun­cil on the eva­lua­ti­on and review of this Regu­la­ti­on. The reports shall be published.
(2) By 11 Sep­tem­ber 2028, the Com­mis­si­on shall, after con­sul­ting ENISA and the CSIRTs net­work, sub­mit a report to the Euro­pean Par­lia­ment and to the Coun­cil asses­sing the effec­ti­ve­ness of the sin­gle noti­fi­ca­ti­on plat­form refer­red to in Artic­le 16 and the impact of the invo­ca­ti­on of the cyber­se­cu­ri­ty grounds refer­red to in Artic­le 16(2) by the CSIRTs desi­gna­ted as coor­di­na­tors on the effec­ti­ve­ness of the sin­gle noti­fi­ca­ti­on plat­form with regard to the time­ly trans­mis­si­on of noti­fi­ca­ti­ons recei­ved to other rele­vant CSIRTs.
Artic­le 71 Ent­ry into force and date of application
(1) This Regu­la­ti­on shall enter into force on the twen­tieth day fol­lo­wing that of its publi­ca­ti­on in the Offi­ci­al Jour­nal of the Euro­pean Union.
(2) This Regu­la­ti­on shall app­ly from Decem­ber 11, 2027, but Artic­le 14 shall app­ly from Sep­tem­ber 11, 2026 and Chap­ter IV (Artic­les 35 to 51) shall app­ly from June 11, 2026. This Regu­la­ti­on shall be bin­ding in its enti­re­ty and direct­ly appli­ca­ble in all Mem­ber States.

Attach­ments

Annex I Basic cyber­se­cu­ri­ty requirements

Part I Cyber­se­cu­ri­ty requi­re­ments rela­ting to the cha­rac­te­ri­stics of pro­ducts with digi­tal elements
(1) Pro­ducts with digi­tal ele­ments are desi­gned, deve­lo­ped and manu­fac­tu­red in such a way that they gua­ran­tee an appro­pria­te level of cyber secu­ri­ty in view of the risks.
(2) On the basis of the cyber­se­cu­ri­ty risk assess­ment refer­red to in Artic­le 13(2), pro­ducts with digi­tal ele­ments shall, whe­re applicable
a) are made available on the mar­ket wit­hout known explo­ita­ble vulnerabilities,
b) be made available on the mar­ket with a secu­re default con­fi­gu­ra­ti­on, unless other­wi­se agreed bet­ween the manu­fac­tu­rer and the pro­fes­sio­nal user in rela­ti­on to a cus­to­mi­zed pro­duct with digi­tal ele­ments, and offer the pos­si­bi­li­ty to resto­re the pro­duct to its ori­gi­nal state,
c) ensu­re that vul­nerabi­li­ties can be addres­sed through secu­ri­ty updates, inclu­ding, whe­re appro­pria­te, through auto­ma­tic secu­ri­ty updates that are instal­led by default within a rea­sonable time­frame and have a clear and user-fri­end­ly opt-out mecha­nism whe­re users are noti­fi­ed of available updates and can tem­po­r­a­ri­ly post­po­ne them;
d) pro­vi­de pro­tec­tion against unaut­ho­ri­zed access through appro­pria­te con­trol mecha­nisms, inclu­ding at least authen­ti­ca­ti­on, iden­ti­ty or access manage­ment systems, and report any unaut­ho­ri­zed access,
e) pro­tect the con­fi­den­tia­li­ty of stored, trans­mit­ted or other­wi­se pro­ce­s­sed per­so­nal or other data, e.g. by encryp­ting rele­vant data that is stored or in the pro­cess of being used or trans­mit­ted, through sta­te-of-the-art mecha­nisms and by using other tech­ni­cal means,
f) pro­tect the inte­gri­ty of stored, trans­mit­ted or other­wi­se pro­ce­s­sed data, whe­ther per­so­nal or other data, com­mands, pro­grams and con­fi­gu­ra­ti­ons from mani­pu­la­ti­on or modi­fi­ca­ti­on not aut­ho­ri­zed by the user and report any damage,
g) limit the pro­ce­s­sing of per­so­nal or other data to that which is appro­pria­te and rele­vant and to the ext­ent neces­sa­ry for the pur­po­se of the pro­duct with digi­tal ele­ments (“data minimization”),
h) ensu­re the avai­la­bi­li­ty of essen­ti­al and basic func­tions, even after a secu­ri­ty inci­dent, inclu­ding via defen­se and con­tain­ment mea­su­res against deni­al-of-ser­vice attacks,
i) mini­mi­ze the nega­ti­ve impact of the pro­ducts them­sel­ves or of net­work­ed devices on the avai­la­bi­li­ty of ser­vices pro­vi­ded by other devices or networks,
j) are desi­gned, deve­lo­ped and manu­fac­tu­red in such a way that they offer as few attack sur­faces as pos­si­ble – even with exter­nal interfaces,
k) are desi­gned, deve­lo­ped and manu­fac­tu­red in such a way that the impact of a secu­ri­ty inci­dent is redu­ced by appro­pria­te mecha­nisms and tech­ni­ques to miti­ga­te the poten­ti­al exploitation,
l) pro­vi­de secu­ri­ty-rela­ted infor­ma­ti­on by recor­ding and/or moni­to­ring rele­vant inter­nal pro­ce­s­ses such as access to and chan­ges to data, ser­vices or func­tions and pro­vi­de users with an opt-out mechanism,
m) Pro­vi­de users with the abili­ty to secu­re­ly and easi­ly dele­te all data and set­tings per­ma­nent­ly and, if this data can be trans­fer­red to other pro­ducts or systems, ensu­re that this is done in a secu­re manner.
Part II Requi­re­ments for the tre­at­ment of vulnerabilities
Manu­fac­tu­r­ers of pro­ducts with digi­tal ele­ments must
(1) Iden­ti­fy and docu­ment weak points and com­pon­ents of the pro­ducts with digi­tal ele­ments, e.g. by crea­ting a soft­ware parts list in a com­mon machi­ne-rea­da­ble for­mat that shows at least the top-level depen­den­ci­es of the products;
(2) with regard to the risks asso­cia­ted with the pro­ducts with digi­tal ele­ments, prompt­ly address and reme­dy vul­nerabi­li­ties, inclu­ding by pro­vi­ding secu­ri­ty updates; whe­re tech­ni­cal­ly fea­si­ble, new secu­ri­ty updates must be pro­vi­ded sepa­ra­te­ly from func­tion­al updates;
(3) regu­lar­ly and effec­tively test and check the safe­ty of the pro­duct with digi­tal elements;
(4) as soon as a secu­ri­ty update has been made available, share and publish infor­ma­ti­on about reme­dia­ted vul­nerabi­li­ties, inclu­ding a descrip­ti­on of the vul­nerabi­li­ties with details that allow users to iden­ti­fy the affec­ted pro­duct with digi­tal ele­ments, the impact of the vul­nerabi­li­ties and their seve­ri­ty, and clear and under­stan­da­ble infor­ma­ti­on to help users to address the vul­nerabi­li­ties; in duly justi­fi­ed cases, whe­re manu­fac­tu­r­ers con­sider that the risks of dis­clo­sure out­weigh the bene­fits in terms of secu­ri­ty, they may delay the dis­clo­sure of infor­ma­ti­on on a fixed vul­nerabi­li­ty until users have been given the oppor­tu­ni­ty to app­ly the rele­vant patch;
(5) Estab­lish and imple­ment a stra­tegy for the coor­di­na­ted dis­clo­sure of vulnerabilities;
(6) take mea­su­res to faci­li­ta­te the exch­an­ge of infor­ma­ti­on on pos­si­ble vul­nerabi­li­ties in their pro­duct with digi­tal ele­ments and third-par­ty com­pon­ents con­tai­ned the­r­ein, inclu­ding by pro­vi­ding a cont­act address for report­ing vul­nerabi­li­ties dis­co­ver­ed in the pro­duct with digi­tal elements;
(7) Pro­vi­de mecha­nisms for the secu­re dis­tri­bu­ti­on of updates for pro­ducts with digi­tal ele­ments so that vul­nerabi­li­ties are addres­sed or miti­ga­ted in a time­ly man­ner and, whe­re appro­pria­te, auto­ma­ti­cal­ly in the case of secu­ri­ty updates;
(8) ensu­re that secu­ri­ty updates available to address iden­ti­fi­ed secu­ri­ty issues are dis­se­mi­na­ted prompt­ly and, unless other­wi­se agreed bet­ween the manu­fac­tu­rer and the pro­fes­sio­nal user in rela­ti­on to a cus­to­mi­zed pro­duct with digi­tal ele­ments, free of char­ge, tog­e­ther with noti­ces and rele­vant infor­ma­ti­on, inclu­ding on pos­si­ble actions to be taken.

Appen­dix II Infor­ma­ti­on and ins­truc­tions for the user

The pro­duct with digi­tal ele­ments must be accom­pa­nied by at least the fol­lo­wing:
1.Name, regi­stered trade name or regi­stered trade mark of the manu­fac­tu­rer, the postal address, e‑mail address or other digi­tal cont­act opti­on and, if available, web­site whe­re the manu­fac­tu­rer can be contacted;
2.the cen­tral cont­act point whe­re infor­ma­ti­on about vul­nerabi­li­ties of the pro­duct with digi­tal ele­ments can be repor­ted and recei­ved and whe­re the con­cept for the coor­di­na­ted dis­clo­sure of vul­nerabi­li­ties can be found;
3.Name and type as well as any addi­tio­nal infor­ma­ti­on that allo­ws the pro­duct to be uni­que­ly iden­ti­fi­ed with digi­tal elements;
4.the inten­ded pur­po­se of the pro­duct with digi­tal ele­ments, inclu­ding the secu­ri­ty envi­ron­ment pro­vi­ded by the manu­fac­tu­rer, as well as the main func­tions of the pro­duct and infor­ma­ti­on on the secu­ri­ty features;
5.any known or fore­seeable cir­cum­stances rela­ted to the inten­ded use of the pro­duct with digi­tal ele­ments or its rea­son­ab­ly fore­seeable misu­se that could lead to signi­fi­cant cyber­se­cu­ri­ty risks;
6.whe­re appli­ca­ble, the Inter­net address at which the EU Decla­ra­ti­on of Con­for­mi­ty is available;
7.the type of tech­ni­cal secu­ri­ty sup­port offe­red by the manu­fac­tu­rer and the end date of the sup­port peri­od during which users can expect to recei­ve vul­nerabi­li­ty fixes and secu­ri­ty updates;
8.detail­ed ins­truc­tions or an Inter­net address that refers to such detail­ed ins­truc­tions and information,
a) the mea­su­res that must be taken when the pro­duct with digi­tal ele­ments is first put into ope­ra­ti­on and throug­hout its ser­vice life to ensu­re its safe use,
b) how chan­ges to the pro­duct with digi­tal ele­ments can affect data security,
c) how secu­ri­ty-rele­vant updates can be installed,
d) how to safe­ly decom­mis­si­on the pro­duct with digi­tal ele­ments and how user data can be safe­ly removed;
e) how to disable the default set­ting that enables the auto­ma­tic instal­la­ti­on of secu­ri­ty updates in accordance with Annex I, Part I(c);
f) how the inte­gra­tor can meet the essen­ti­al cyber­se­cu­ri­ty requi­re­ments in Annex I and the tech­ni­cal docu­men­ta­ti­on requi­re­ments in Annex VII when the pro­duct with digi­tal ele­ments is inten­ded for inte­gra­ti­on with other pro­ducts with digi­tal elements;
9.in the event that the manu­fac­tu­rer makes the soft­ware parts list available to the user, whe­re the soft­ware parts list can be accessed.

Appen­dix III Important pro­ducts with digi­tal elements

Class I

1.Iden­ti­ty manage­ment systems and soft­ware and hard­ware for mana­ging pri­vi­le­ged access, inclu­ding rea­ders for authen­ti­ca­ti­on and access con­trol, inclu­ding bio­me­tric readers
2.Stan­da­lo­ne and embedded browsers
3.Pass­word manager
4.Soft­ware for sear­ching, remo­ving and qua­ran­ti­ning malware
5.Pro­ducts with digi­tal ele­ments with the func­tion of a vir­tu­al pri­va­te net­work (VPN)
6.Net­work manage­ment systems
7.Systems for the manage­ment of secu­ri­ty infor­ma­ti­on and events (SIEM)
8.Boot mana­ger
9.Public key infras­truc­tures and soft­ware for issuing digi­tal certificates
10.Phy­si­cal and vir­tu­al net­work interfaces
11.Ope­ra­ting systems
12.Rou­ters, modems for the Inter­net con­nec­tion and switches
13.Micro­pro­ces­sors with safe­ty-rele­vant functions
14.Micro­con­trol­ler with safe­ty-rele­vant functions
15.Appli­ca­ti­on-spe­ci­fic inte­gra­ted cir­cuits (ASIC) and FPGA (Field Pro­gramma­ble Gate Array) with safe­ty-rele­vant functions
16.Vir­tu­al assi­stants for the intel­li­gent home envi­ron­ment with a gene­ral purpose
17.Pro­ducts for the smart home envi­ron­ment with secu­ri­ty func­tions, inclu­ding smart door locks, secu­ri­ty came­ras, baby moni­to­ring systems and alarm systems
18.Inter­net-con­nec­ted toys cover­ed by Direc­ti­ve 2009/48/EC of the Euro­pean Par­lia­ment and of the Coun­cil (1) with social inter­ac­tion func­tions (e.g. tal­king or film­ing) or posi­tio­ning functions
19.weara­ble devices inten­ded for the pur­po­se of health moni­to­ring (e.g. track­ing) and not cover­ed by Regu­la­ti­ons (EU) 2017/745 or (EU) 2017/746, or weara­ble devices inten­ded for use by and for children

Class II

1.Hyper­vi­sors and con­tai­ner run­time systems that sup­port vir­tua­li­zed exe­cu­ti­on of ope­ra­ting systems and simi­lar environments
2.Fire­walls, intru­si­on detec­tion systems and intru­si­on pre­ven­ti­on systems
3.Tam­per-pro­of microprocessors
4.Tam­per-pro­of microcontroller
(1) Direc­ti­ve 2009/48/EC of the Euro­pean Par­lia­ment and of the Coun­cil of June 18, 2009 on the safe­ty of toys (OJ L 170, 30.6.2009, p. 1).

Annex IV Cri­ti­cal pro­ducts with digi­tal elements

1. hard­ware devices with secu­ri­ty boxes 2. smart meter gate­ways in smart meter­ing systems as defi­ned in point (23) of Artic­le 2 of Direc­ti­ve (EU) 2019/944 of the Euro­pean Par­lia­ment and of the Coun­cil (1) and other devices for advan­ced secu­ri­ty pur­po­ses, inclu­ding secu­re cryp­to pro­ce­s­sing 3. smart cards or simi­lar devices, inclu­ding secu­ri­ty ele­ments
(1) Direc­ti­ve (EU) 2019/944 of the Euro­pean Par­lia­ment and of the Coun­cil of June 5, 2019 con­cer­ning com­mon rules for the inter­nal mar­ket in elec­tri­ci­ty and amen­ding Direc­ti­ve 2012/27/EU (OJ L 158, 14.6.2019, p. 125).

Annex V EU Decla­ra­ti­on of Conformity

The EU decla­ra­ti­on of con­for­mi­ty pur­su­ant to Artic­le 28 shall con­tain all of the fol­lo­wing infor­ma­ti­on:
1.the name and type and any addi­tio­nal infor­ma­ti­on that allo­ws the pro­duct to be uni­que­ly iden­ti­fi­ed with digi­tal elements
2.the name and address of the manu­fac­tu­rer or his aut­ho­ri­zed representative
3.a decla­ra­ti­on that the sup­plier bears sole respon­si­bi­li­ty for issuing the EU decla­ra­ti­on of conformity
4.the object of the decla­ra­ti­on (desi­gna­ti­on of the pro­duct with digi­tal ele­ments for tracea­bi­li­ty, with pho­to if necessary)
5.a decla­ra­ti­on that the object of the decla­ra­ti­on descri­bed abo­ve com­plies with the rele­vant Uni­on har­mo­nizati­on legislation
6.refe­ren­ces to the rele­vant har­mo­ni­zed stan­dards or other com­mon spe­ci­fi­ca­ti­ons used or the cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on for which con­for­mi­ty is declared
7.whe­re appli­ca­ble, the name and iden­ti­fi­ca­ti­on num­ber of the noti­fi­ed body, a descrip­ti­on of the con­for­mi­ty assess­ment pro­ce­du­re car­ri­ed out and the iden­ti­fi­ca­ti­on num­ber of the cer­ti­fi­ca­te issued
8.Fur­ther information:
Signed for and on behalf of: (place and date of issue) (Name, func­tion) (Signa­tu­re):

Annex VI Sim­pli­fi­ed EU Decla­ra­ti­on of Conformity

The sim­pli­fi­ed EU decla­ra­ti­on of con­for­mi­ty refer­red to in Artic­le 13(20) shall be worded as fol­lows: ‘Her­eby, … [name of the manu­fac­tu­rer] decla­res that the type of pro­duct with digi­tal ele­ments … [name of the type of pro­duct with digi­tal ele­ments] is in con­for­mi­ty with Regu­la­ti­on (EU) 2024/2847 (1). The full text of the EU decla­ra­ti­on of con­for­mi­ty can be found at the fol­lo­wing inter­net address …
(1) OJ L, 2024/2847, 20.11.2024, ELI: http://data.europa.eu/eli/reg/2024/2847/oj.

Annex VII Con­tents of the tech­ni­cal documentation

The tech­ni­cal docu­men­ta­ti­on refer­red to in Artic­le 31 shall con­tain at least the fol­lo­wing infor­ma­ti­on, inso­far as it is rele­vant to the digi­tal ele­ment pro­duct con­cer­ned:
1.a gene­ral descrip­ti­on of the pro­duct with digi­tal ele­ments, including
a) its inten­ded purpose,
b) Soft­ware ver­si­ons that affect the ful­fill­ment of basic cyber­se­cu­ri­ty requirements,
c) if the pro­duct with digi­tal ele­ments is a hard­ware pro­duct: Pho­to­graphs or illu­stra­ti­ons show­ing exter­nal fea­tures, mar­kings and inter­nal structure;
d) Infor­ma­ti­on and ins­truc­tions for users in accordance with Annex II;
2.a descrip­ti­on of the design, deve­lo­p­ment and manu­fac­tu­re of the pro­duct with digi­tal ele­ments and the vul­nerabi­li­ty hand­ling pro­ce­du­res, including
a) neces­sa­ry infor­ma­ti­on on the design and deve­lo­p­ment of the pro­duct with digi­tal ele­ments, inclu­ding dra­wings and sche­ma­tics whe­re appro­pria­te and/or a descrip­ti­on of the system archi­tec­tu­re show­ing how soft­ware com­pon­ents build on each other, inter­act with each other and inte­gra­te into the over­all processing;
b) requi­red infor­ma­ti­on and spe­ci­fi­ca­ti­ons regar­ding the vul­nerabi­li­ty hand­ling pro­ce­du­res estab­lished by the manu­fac­tu­rer, inclu­ding the soft­ware bill of mate­ri­als, the approach to coor­di­na­ted vul­nerabi­li­ty dis­clo­sure, evi­dence of the pro­vi­si­on of a cont­act address for vul­nerabi­li­ty report­ing, and a descrip­ti­on of the tech­ni­cal solu­ti­ons cho­sen for the secu­re dis­tri­bu­ti­on of updates;
c) requi­red infor­ma­ti­on and spe­ci­fi­ca­ti­ons regar­ding the manu­fac­tu­ring and moni­to­ring pro­ce­s­ses of the pro­duct with digi­tal ele­ments and the vali­da­ti­on of the­se processes;
3.an assess­ment of the cyber­se­cu­ri­ty risks con­side­red in the design, deve­lo­p­ment, manu­fac­tu­re, sup­p­ly and main­ten­an­ce of the device with digi­tal ele­ments refer­red to in Artic­le 13, inclu­ding the ext­ent to which the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part I of Annex I apply;
4.rele­vant infor­ma­ti­on taken into account when deter­mi­ning the sup­port peri­od in accordance with Artic­le 13(8) of the pro­duct with digi­tal elements;
5.a list of the ful­ly or par­ti­al­ly applied har­mo­ni­zed stan­dards, the refe­ren­ces of which have been published in the Offi­ci­al Jour­nal of the Euro­pean Uni­on, com­mon spe­ci­fi­ca­ti­ons refer­red to in Artic­le 27 of this Regu­la­ti­on or Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­mes refer­red to in Artic­le 27(8) of this Regu­la­ti­on, adopted in accordance with Regu­la­ti­on (EU) 2019/881 and, whe­re no such har­mo­ni­zed stan­dards, com­mon spe­ci­fi­ca­ti­ons and Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­mes are applied, descrip­ti­ons of the solu­ti­ons mee­ting the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Parts I and II of Annex I, tog­e­ther with a list of other rele­vant tech­ni­cal spe­ci­fi­ca­ti­ons applied. In case of par­ti­al appli­ca­ti­on of har­mo­ni­zed stan­dards, com­mon spe­ci­fi­ca­ti­ons or Euro­pean cyber­se­cu­ri­ty cer­ti­fi­ca­ti­on sche­mes, the tech­ni­cal docu­men­ta­ti­on shall indi­ca­te which parts have been applied;
6.Reports on the tests and exami­na­ti­ons car­ri­ed out to veri­fy the con­for­mi­ty of the pro­duct with digi­tal ele­ments and vul­nerabi­li­ty hand­ling pro­ce­du­res with the appli­ca­ble essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Parts I and II of Annex I;
7.a copy of the EU Decla­ra­ti­on of Conformity;
8.whe­re appli­ca­ble, at the rea­so­ned request of the mar­ket sur­veil­lan­ce aut­ho­ri­ty, the soft­ware BOM, whe­re neces­sa­ry to enable that aut­ho­ri­ty to veri­fy com­pli­ance with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I.

Annex VIII Con­for­mi­ty assess­ment procedures

Part I Con­for­mi­ty assess­ment pro­ce­du­res based on inter­nal con­trol (based on Modu­le A)
1.Inter­nal con­trol is the con­for­mi­ty assess­ment pro­ce­du­re wher­eby the manu­fac­tu­rer ful­fills the obli­ga­ti­ons laid down in points 2, 3 and 4 of this Part, and ensu­res and decla­res on its sole respon­si­bi­li­ty that the devices incor­po­ra­ting digi­tal ele­ments satis­fy all the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part I of Annex I and that the manu­fac­tu­rer satis­fies the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part II of Annex I.
2.The manu­fac­tu­rer shall draw up the tech­ni­cal docu­men­ta­ti­on in accordance with Annex VII.
3.Design, deve­lo­p­ment, pro­duc­tion and tre­at­ment of vul­nerabi­li­ties in pro­ducts with digi­tal elements
The manu­fac­tu­rer shall take all mea­su­res neces­sa­ry so that the design, deve­lo­p­ment, manu­fac­tu­ring and vul­nerabi­li­ty tre­at­ment pro­ce­s­ses and their moni­to­ring ensu­re con­for­mi­ty of the manu­fac­tu­red or deve­lo­ped devices with digi­tal ele­ments and of the pro­ce­du­res defi­ned by the manu­fac­tu­rer with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Parts I and II of Annex I.
4.Con­for­mi­ty mar­king and decla­ra­ti­on of conformity
4.1.The manu­fac­tu­rer shall affix the CE mar­king to each indi­vi­du­al device incor­po­ra­ting digi­tal ele­ments that satis­fies the appli­ca­ble requi­re­ments laid down in this Regulation.
4.2.The manu­fac­tu­rer shall draw up a writ­ten EU decla­ra­ti­on of con­for­mi­ty in accordance with Artic­le 28 for each device incor­po­ra­ting digi­tal ele­ments and keep it tog­e­ther with the tech­ni­cal docu­men­ta­ti­on at the dis­po­sal of the natio­nal aut­ho­ri­ties for 10 years after the device incor­po­ra­ting digi­tal ele­ments has been pla­ced on the mar­ket or for the dura­ti­on of the sup­port peri­od, whi­che­ver is the lon­ger. The EU decla­ra­ti­on of con­for­mi­ty shall iden­ti­fy the pro­duct with digi­tal ele­ments for which it has been drawn up. A copy of the EU decla­ra­ti­on of con­for­mi­ty shall be made available to the rele­vant aut­ho­ri­ties upon request.
5.Aut­ho­ri­zed representative
The manufacturer’s obli­ga­ti­ons set out in point 4 may be ful­fil­led by his aut­ho­ri­zed repre­sen­ta­ti­ve, on his behalf and under his respon­si­bi­li­ty, pro­vi­ded that the rele­vant obli­ga­ti­ons are spe­ci­fi­ed in the mandate. 
Part II EU type-exami­na­ti­on (based on modu­le B)
1.EU type-exami­na­ti­on is the part of a con­for­mi­ty assess­ment pro­ce­du­re in which a noti­fi­ed body exami­nes and veri­fi­es the tech­ni­cal design and deve­lo­p­ment of a device incor­po­ra­ting digi­tal ele­ments and the pro­ce­du­res adopted by the manu­fac­tu­rer to address vul­nerabi­li­ties, and then cer­ti­fi­es that a device incor­po­ra­ting digi­tal ele­ments meets the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part I of Annex I and that the manu­fac­tu­rer com­plies with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part II of Annex I.
2.The EU-type exami­na­ti­on shall be car­ri­ed out as an assess­ment of the ade­qua­cy of the tech­ni­cal design and deve­lo­p­ment of the pro­duct with digi­tal ele­ments through exami­na­ti­on of the tech­ni­cal docu­men­ta­ti­on and sup­port­ing evi­dence refer­red to in point 3 and exami­na­ti­on of spe­ci­mens of one or more essen­ti­al parts of the pro­duct (com­bi­na­ti­on of pro­duc­tion type and design type).
3.The appli­ca­ti­on for EU type-exami­na­ti­on is sub­mit­ted by the manu­fac­tu­rer to a sin­gle noti­fi­ed body of his choice.
The appli­ca­ti­on con­ta­ins
3.1.the name and address of the manu­fac­tu­rer and, if the appli­ca­ti­on is sub­mit­ted by the aut­ho­ri­zed repre­sen­ta­ti­ve, the name and address of the aut­ho­ri­zed representative;
3.2.a writ­ten decla­ra­ti­on that the same appli­ca­ti­on has not been sub­mit­ted to any other noti­fi­ed body;
3.3.the tech­ni­cal docu­men­ta­ti­on that makes it pos­si­ble to assess the con­for­mi­ty of the device with digi­tal ele­ments with the appli­ca­ble essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part I of Annex I and the manufacturer’s pro­ce­du­res for addres­sing vul­nerabi­li­ties set out in Part II of Annex I; it shall also include an ade­qua­te risk ana­ly­sis and assess­ment. The tech­ni­cal docu­men­ta­ti­on shall spe­ci­fy the appli­ca­ble requi­re­ments and cover the design, manu­fac­tu­re and ope­ra­ti­on of the device with digi­tal ele­ments, whe­re rele­vant for the assess­ment. The tech­ni­cal docu­men­ta­ti­on shall con­tain at least the ele­ments listed in Annex VII, whe­re applicable;
3.4.addi­tio­nal evi­dence of the ade­qua­cy of the tech­ni­cal design and deve­lo­p­ment solu­ti­ons and of the vul­nerabi­li­ty manage­ment pro­ce­du­res. This sup­port­ing evi­dence shall men­ti­on any docu­ments that have been used, in par­ti­cu­lar whe­re the rele­vant har­mo­ni­zed stan­dards or tech­ni­cal spe­ci­fi­ca­ti­ons have not been applied in full. The sup­port­ing evi­dence shall include, whe­re neces­sa­ry, the results of tests car­ri­ed out by an appro­pria­te labo­ra­to­ry of the manu­fac­tu­rer or by ano­ther test­ing labo­ra­to­ry on his behalf and under his responsibility.
4.The noti­fi­ed body
4.1.exami­ne the tech­ni­cal docu­men­ta­ti­on and sup­port­ing evi­dence to assess the com­pli­ance of the tech­ni­cal design and deve­lo­p­ment of the device with digi­tal ele­ments with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part I of Annex I and of the vul­nerabi­li­ty hand­ling pro­ce­du­res defi­ned by the manu­fac­tu­rer with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part II of Annex I;
4.2.veri­fi­es that the specimen(s) have been desi­gned or manu­fac­tu­red in con­for­mi­ty with the tech­ni­cal docu­men­ta­ti­on, which ele­ments have been desi­gned and deve­lo­ped in accordance with the appli­ca­ble pro­vi­si­ons of the rele­vant har­mo­ni­zed stan­dards or tech­ni­cal spe­ci­fi­ca­ti­ons and which ele­ments have been desi­gned and deve­lo­ped wit­hout app­ly­ing the rele­vant pro­vi­si­ons of the­se standards;
4.3.car­ry out appro­pria­te exami­na­ti­ons and tests, or have them car­ri­ed out, to check whe­ther, whe­re the manu­fac­tu­rer has cho­sen to app­ly the solu­ti­ons in the rele­vant har­mo­ni­zed stan­dards or tech­ni­cal spe­ci­fi­ca­ti­ons, the­se have been applied cor­rect­ly in rela­ti­on to the requi­re­ments set out in Annex I;
4.4.car­ry out appro­pria­te exami­na­ti­ons and tests, or have them car­ri­ed out, to check whe­ther, whe­re the manu­fac­tu­rer has not applied the solu­ti­ons set out in the rele­vant har­mo­ni­zed stan­dards or tech­ni­cal spe­ci­fi­ca­ti­ons cove­ring the requi­re­ments set out in Annex I, the solu­ti­ons adopted by the manu­fac­tu­rer meet the cor­re­spon­ding essen­ti­al cyber­se­cu­ri­ty requirements;
4.5.agrees with the manu­fac­tu­rer whe­re the tests and inspec­tions will be car­ri­ed out.
5.The noti­fi­ed body shall draw up an assess­ment report on the acti­vi­ties car­ri­ed out under point 4 and their results. Wit­hout pre­ju­di­ce to its obli­ga­ti­ons vis-à-vis the noti­fy­ing aut­ho­ri­ties, the noti­fi­ed body shall release the con­tent of that report, in full or in part, only with the agree­ment of the manufacturer.
6.Whe­re the type and the vul­nerabi­li­ty tre­at­ment pro­ce­du­res meet the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I, the noti­fi­ed body shall issue an EU-type exami­na­ti­on cer­ti­fi­ca­te to the manu­fac­tu­rer. The cer­ti­fi­ca­te shall con­tain the name and address of the manu­fac­tu­rer, the con­clu­si­ons of the exami­na­ti­on, the con­di­ti­ons (if any) for its vali­di­ty and the neces­sa­ry data for iden­ti­fi­ca­ti­on of the appro­ved type and vul­nerabi­li­ty tre­at­ment pro­cess. The cer­ti­fi­ca­te may be accom­pa­nied by one or more annexes.
The cer­ti­fi­ca­te and its anne­xes shall con­tain all rele­vant infor­ma­ti­on to allow the con­for­mi­ty of manu­fac­tu­red or desi­gned pro­ducts incor­po­ra­ting digi­tal ele­ments with the exami­ned type and the con­for­mi­ty of the vul­nerabi­li­ty manage­ment pro­ce­du­res to be eva­lua­ted and, whe­re appro­pria­te, to allow for in-ser­vice con­trol. Whe­re the type and the vul­nerabi­li­ty manage­ment pro­ce­du­res do not satis­fy the appli­ca­ble essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I, the noti­fi­ed body shall refu­se to issue an EU-type exami­na­ti­on cer­ti­fi­ca­te and shall inform the appli­cant accor­din­gly, giving detail­ed rea­sons for its refu­sal.
7.The noti­fi­ed body shall keep its­elf app­ri­sed of any chan­ges in the gene­ral­ly ack­now­led­ged sta­te of the art which indi­ca­te that the appro­ved type and vul­nerabi­li­ty tre­at­ment pro­ce­du­res no lon­ger meet the appli­ca­ble essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I, and shall deter­mi­ne whe­ther such chan­ges requi­re fur­ther inve­sti­ga­ti­on. Whe­re this is the case, the noti­fi­ed body shall inform the manu­fac­tu­rer accordingly.
The manu­fac­tu­rer shall inform the noti­fi­ed body that holds the tech­ni­cal docu­men­ta­ti­on rela­ting to the EU-type exami­na­ti­on cer­ti­fi­ca­te of all modi­fi­ca­ti­ons to the appro­ved type and the pro­ce­du­re for addres­sing vul­nerabi­li­ties that may affect the con­for­mi­ty with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Annex I or the con­di­ti­ons for vali­di­ty of the cer­ti­fi­ca­te. Such chan­ges shall requi­re addi­tio­nal appr­oval in the form of an addi­ti­on to the ori­gi­nal EU-type exami­na­ti­on cer­ti­fi­ca­te.
8.The noti­fi­ed body shall peri­odi­cal­ly car­ry out audits to ensu­re that the vul­nerabi­li­ty manage­ment pro­ce­du­res set out in Part II of Annex I are ade­qua­te­ly implemented.
9.Each noti­fi­ed body shall inform its noti­fy­ing aut­ho­ri­ties con­cer­ning the EU-type exami­na­ti­on cer­ti­fi­ca­tes and any addi­ti­ons the­re­to which it has issued or with­drawn, and shall, peri­odi­cal­ly or upon request, make available to its noti­fy­ing aut­ho­ri­ties the list of cer­ti­fi­ca­tes and any addi­ti­ons the­re­to refu­sed, sus­pen­ded or other­wi­se restricted.
Each noti­fi­ed body shall inform the other noti­fi­ed bodies con­cer­ning the EU-type exami­na­ti­on cer­ti­fi­ca­tes and any addi­ti­ons the­re­to which it has refu­sed, with­drawn, sus­pen­ded or other­wi­se rest­ric­ted, and, upon request, con­cer­ning the cer­ti­fi­ca­tes and addi­ti­ons the­re­to which it has issued. On request, the Com­mis­si­on, the Mem­ber Sta­tes and the other noti­fi­ed bodies may obtain a copy of the EU-type exami­na­ti­on cer­ti­fi­ca­tes and any addi­ti­ons the­re­to. The Com­mis­si­on and the Mem­ber Sta­tes may, on request, obtain a copy of the tech­ni­cal docu­men­ta­ti­on and the results of the exami­na­ti­ons car­ri­ed out by the noti­fi­ed body. The noti­fi­ed body shall keep a copy of the EU-type exami­na­ti­on cer­ti­fi­ca­te, its anne­xes and addi­ti­ons, as well as the tech­ni­cal file inclu­ding the docu­men­ta­ti­on sub­mit­ted by the manu­fac­tu­rer, until the expiry of the vali­di­ty of the cer­ti­fi­ca­te.
10.The manu­fac­tu­rer shall keep a copy of the EU-type exami­na­ti­on cer­ti­fi­ca­te, its anne­xes and addi­ti­ons tog­e­ther with the tech­ni­cal docu­men­ta­ti­on at the dis­po­sal of the natio­nal aut­ho­ri­ties for 10 years after the pro­duct with digi­tal ele­ments has been pla­ced on the mar­ket or during the sup­port peri­od, whi­che­ver is the longer.
11.The manufacturer’s aut­ho­ri­zed repre­sen­ta­ti­ve may sub­mit the appli­ca­ti­on refer­red to in point 3 and ful­fil the obli­ga­ti­ons set out in points 7 and 10, if the rele­vant obli­ga­ti­ons are spe­ci­fi­ed in the mandate.
Part III Con­for­mi­ty to type based on inter­nal pro­duc­tion con­trol (based on modu­le C)
1.Con­for­mi­ty to type based on inter­nal pro­duc­tion con­trol is the part of a con­for­mi­ty assess­ment pro­ce­du­re wher­eby the manu­fac­tu­rer ful­fills the obli­ga­ti­ons laid down in points 2 and 3 of this Part, and ensu­res and decla­res that the pro­ducts con­cer­ned with digi­tal ele­ments are in con­for­mi­ty with the type descri­bed in the EU-type exami­na­ti­on cer­ti­fi­ca­te and satis­fy the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part I of Annex I and meet the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part II of Annex I.
2.Manu­fac­tu­re
The manu­fac­tu­rer shall take all mea­su­res neces­sa­ry so that the con­for­mi­ty of manu­fac­tu­red devices incor­po­ra­ting digi­tal ele­ments with the appro­ved type descri­bed in the EU-type exami­na­ti­on cer­ti­fi­ca­te and with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part I of Annex I is ensu­red through manu­fac­tu­re and its moni­to­ring, and shall ensu­re com­pli­ance with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part II of Annex I.
3.Con­for­mi­ty mar­king and decla­ra­ti­on of conformity
3.1.The manu­fac­tu­rer shall affix the CE mar­king to each indi­vi­du­al device incor­po­ra­ting digi­tal ele­ments that is in con­for­mi­ty with the type descri­bed in the EU-type exami­na­ti­on cer­ti­fi­ca­te and satis­fies the appli­ca­ble requi­re­ments set out in this Regulation.
3.2.The manu­fac­tu­rer shall draw up a writ­ten decla­ra­ti­on of con­for­mi­ty for a pro­duct model and keep it at the dis­po­sal of the natio­nal aut­ho­ri­ties for 10 years after the pro­duct with digi­tal ele­ments has been pla­ced on the mar­ket or during the sup­port peri­od, whi­che­ver is the lon­ger. The decla­ra­ti­on of con­for­mi­ty shall iden­ti­fy the pro­duct model for which it has been issued. A copy of the decla­ra­ti­on of con­for­mi­ty shall be made available to the rele­vant aut­ho­ri­ties upon request.
4.Aut­ho­ri­zed representative
The manufacturer’s obli­ga­ti­ons set out in point 3 may be ful­fil­led by his aut­ho­ri­zed repre­sen­ta­ti­ve, on his behalf and under his respon­si­bi­li­ty, pro­vi­ded that the rele­vant obli­ga­ti­ons are spe­ci­fi­ed in the mandate. 
Part IV Con­for­mi­ty based on full qua­li­ty assu­rance (based on Modu­le H)
1.Con­for­mi­ty based on full qua­li­ty assu­rance is the con­for­mi­ty assess­ment pro­ce­du­re wher­eby the manu­fac­tu­rer ful­fills the obli­ga­ti­ons laid down in points 2 and 5, and ensu­res and decla­res on his sole respon­si­bi­li­ty that the devices incor­po­ra­ting digi­tal ele­ments or pro­duct cate­go­ries con­cer­ned satis­fy the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part I of Annex I and that the manufacturer’s vul­nerabi­li­ty manage­ment pro­ce­du­res satis­fy the essen­ti­al requi­re­ments set out in Part II of Annex I.
2.Design, deve­lo­p­ment, pro­duc­tion and tre­at­ment of vul­nerabi­li­ties in pro­ducts with digi­tal elements
The manu­fac­tu­rer shall ope­ra­te and main­tain an appro­ved qua­li­ty manage­ment system as spe­ci­fi­ed in point 3 for the design, deve­lo­p­ment and final pro­duct inspec­tion and test­ing of the digi­tal devices con­cer­ned and for the manage­ment of vul­nerabi­li­ties throug­hout the peri­od of sup­port and shall be sub­ject to sur­veil­lan­ce as spe­ci­fi­ed in point 4.
3.Qua­li­ty assu­rance system
3.1.The manu­fac­tu­rer shall app­ly to a noti­fi­ed body of his choice for assess­ment of his qua­li­ty system for the pro­ducts con­cer­ned with digi­tal elements.
The appli­ca­ti­on con­ta­ins
a) the name and address of the manu­fac­tu­rer and, if the appli­ca­ti­on is sub­mit­ted by the aut­ho­ri­zed repre­sen­ta­ti­ve, the name and address of the aut­ho­ri­zed representative;
b) the tech­ni­cal docu­men­ta­ti­on for one model of each cate­go­ry of devices with digi­tal ele­ments to be manu­fac­tu­red or desi­gned; the tech­ni­cal docu­men­ta­ti­on shall include at least the ele­ments listed in Annex VII, whe­re applicable;
c) the docu­men­ta­ti­on for the qua­li­ty assu­rance system;
d) a writ­ten decla­ra­ti­on that the same appli­ca­ti­on has not been sub­mit­ted to any other noti­fi­ed body.
3.2.The qua­li­ty system shall ensu­re com­pli­ance of the device with digi­tal ele­ments with the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part I of Annex I and com­pli­ance of the manufacturer’s vul­nerabi­li­ty manage­ment pro­ce­du­res with the essen­ti­al requi­re­ments set out in Part II of Annex I.
All the ele­ments, requi­re­ments and pro­vi­si­ons adopted by the manu­fac­tu­rer shall be docu­men­ted in a syste­ma­tic and order­ly man­ner in the form of writ­ten poli­ci­es, pro­ce­du­res and ins­truc­tions. This qua­li­ty system docu­men­ta­ti­on shall ensu­re a con­si­stent inter­pre­ta­ti­on of the qua­li­ty pro­grams, plans, manu­als and qua­li­ty records. In par­ti­cu­lar, they shall con­tain an ade­qua­te descrip­ti­on of the fol­lo­wing points:
a) Qua­li­ty objec­ti­ves and orga­nizatio­nal struc­tu­re, respon­si­bi­li­ties and powers of manage­ment with regard to design, deve­lo­p­ment, pro­duct qua­li­ty and hand­ling of weaknesses;
b) tech­ni­cal spe­ci­fi­ca­ti­ons for design and deve­lo­p­ment, inclu­ding the stan­dards applied and, whe­re the rele­vant har­mo­ni­zed stan­dards or tech­ni­cal spe­ci­fi­ca­ti­ons are not applied in full, the means to ensu­re that the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part I of Annex I appli­ca­ble to the devices incor­po­ra­ting digi­tal ele­ments are met;
c) pro­ce­du­ral spe­ci­fi­ca­ti­ons, inclu­ding the stan­dards applied and, whe­re the rele­vant har­mo­ni­zed stan­dards or tech­ni­cal spe­ci­fi­ca­ti­ons are not applied in full, the means to ensu­re that the essen­ti­al cyber­se­cu­ri­ty requi­re­ments set out in Part II of Annex I appli­ca­ble to the manu­fac­tu­rer are met;
d) Design and deve­lo­p­ment con­trol tech­ni­ques and design and deve­lo­p­ment review tech­ni­ques, pro­ce­s­ses and syste­ma­tic actions used in the design and deve­lo­p­ment of pro­ducts with digi­tal ele­ments belon­ging to the rele­vant pro­duct category;
e) appro­pria­te applied tech­ni­ques, pro­ce­du­res and syste­ma­tic mea­su­res for pro­duc­tion, qua­li­ty con­trol and qua­li­ty assurance;
f) Tests and tri­als car­ri­ed out befo­re, during and after manu­fac­tu­re and their frequency;
g) qua­li­ty-rela­ted records such as inspec­tion reports, test and cali­bra­ti­on data and reports on the qua­li­fi­ca­ti­ons of employees working in this area;
h) Means by which the rea­lizati­on of the inten­ded design and pro­duct qua­li­ty and the effec­ti­ve ope­ra­ti­on of the qua­li­ty assu­rance system can be monitored.
3.3.The noti­fi­ed body shall assess the qua­li­ty system to deter­mi­ne whe­ther it satis­fies the requi­re­ments refer­red to in point 3.2.
It shall pre­su­me con­for­mi­ty with tho­se requi­re­ments in respect of the ele­ments of the qua­li­ty manage­ment system that com­ply with the cor­re­spon­ding spe­ci­fi­ca­ti­ons of the natio­nal stan­dard that imple­ments the rele­vant har­mo­ni­zed stan­dard or rele­vant tech­ni­cal spe­ci­fi­ca­ti­ons. In addi­ti­on to expe­ri­ence in qua­li­ty manage­ment systems, at least one mem­ber of the audi­ting team shall have expe­ri­ence of eva­lua­ti­on in the rele­vant field and tech­no­lo­gy of the pro­duct con­cer­ned and know­ledge of the appli­ca­ble requi­re­ments laid down in this Regu­la­ti­on. The audit shall include an inspec­tion visit to the manufacturer’s pre­mi­ses, if any. The audi­ting team shall review the tech­ni­cal docu­men­ta­ti­on refer­red to in point 3.1(b) in order to veri­fy the manufacturer’s abili­ty to iden­ti­fy the appli­ca­ble requi­re­ments set out in this Regu­la­ti­on and to car­ry out the neces­sa­ry exami­na­ti­ons with a view to ensu­ring com­pli­ance of the device with digi­tal ele­ments with tho­se requi­re­ments. The decis­i­on shall be noti­fi­ed to the manu­fac­tu­rer or his aut­ho­ri­zed repre­sen­ta­ti­ve. The noti­fi­ca­ti­on shall con­tain the con­clu­si­ons of the audit and the rea­so­ned assess­ment decis­i­on.
3.4.The manu­fac­tu­rer under­ta­kes to com­ply with the obli­ga­ti­ons ari­sing out of the appro­ved qua­li­ty system and to ensu­re that it is applied cor­rect­ly and effi­ci­ent­ly at all times.
3.5.The manu­fac­tu­rer shall keep the noti­fi­ed body that has appro­ved the qua­li­ty system infor­med of any inten­ded chan­ge to the qua­li­ty system.
The noti­fi­ed body shall eva­lua­te the modi­fi­ca­ti­ons pro­po­sed and deci­de whe­ther the amen­ded qua­li­ty system will still satis­fy the requi­re­ments refer­red to in point 3.2 or whe­ther a reas­sess­ment is requi­red. It shall noti­fy the manu­fac­tu­rer of its decis­i­on. The noti­fi­ca­ti­on shall con­tain the con­clu­si­ons of the exami­na­ti­on and the rea­so­ned assess­ment decis­i­on.
4.Sur­veil­lan­ce under the respon­si­bi­li­ty of the noti­fi­ed body
4.1.The pur­po­se of sur­veil­lan­ce is to ensu­re that the manu­fac­tu­rer duly ful­fills the obli­ga­ti­ons asso­cia­ted with the appro­ved qua­li­ty assu­rance system.
4.2.The manu­fac­tu­rer shall, for assess­ment pur­po­ses, allow the noti­fi­ed body access to the loca­ti­ons of design, manu­fac­tu­re, inspec­tion, test­ing and sto­rage and shall pro­vi­de it with all neces­sa­ry infor­ma­ti­on, in particular
a) the docu­men­ta­ti­on on the qua­li­ty assu­rance system,
b) the qua­li­ty reports as fore­seen in the qua­li­ty system for the design part, such as results of ana­ly­ses, cal­cu­la­ti­ons and tests,
c) the qua­li­ty records as fore­seen by the manu­fac­tu­ring part qua­li­ty system, such as inspec­tion reports, test and cali­bra­ti­on data and qua­li­fi­ca­ti­on reports of the per­son­nel concerned.
4.3.The noti­fi­ed body shall peri­odi­cal­ly car­ry out audits to make sure that the manu­fac­tu­rer main­ta­ins and applies the qua­li­ty system and shall pro­vi­de the manu­fac­tu­rer with an audit report.
5.Con­for­mi­ty mar­king and decla­ra­ti­on of conformity
5.1.The manu­fac­tu­rer shall affix the CE mar­king and, under the respon­si­bi­li­ty of the noti­fi­ed body refer­red to in para­graph 3.1, the latter’s iden­ti­fi­ca­ti­on num­ber to each indi­vi­du­al device incor­po­ra­ting digi­tal ele­ments that satis­fies the requi­re­ments set out in Annex I, Part I.
5.2.The manu­fac­tu­rer shall draw up a writ­ten decla­ra­ti­on of con­for­mi­ty for each pro­duct model and keep it at the dis­po­sal of the natio­nal aut­ho­ri­ties for 10 years after the pro­duct with digi­tal ele­ments has been pla­ced on the mar­ket or during the sup­port peri­od, whi­che­ver is the lon­ger. The decla­ra­ti­on of con­for­mi­ty shall iden­ti­fy the pro­duct model for which it has been issued.
A copy of the decla­ra­ti­on of con­for­mi­ty will be made available to the rele­vant aut­ho­ri­ties on request.
6.The manu­fac­tu­rer shall, for a peri­od of at least 10 years after the device with digi­tal ele­ments has been pla­ced on the mar­ket or during the sup­port peri­od, whi­che­ver is the lon­ger, keep the fol­lo­wing docu­men­ta­ti­on at the dis­po­sal of the natio­nal authorities:
a) the tech­ni­cal docu­men­ta­ti­on accor­ding to num­ber 3.1,
b) the docu­men­ta­ti­on on the qua­li­ty assu­rance system in accordance with point 3.1,
c) the amend­ment accor­ding to num­ber 3.5 in its appro­ved form,
d) the decis­i­ons and reports from the noti­fi­ed body refer­red to in points 3.5 and 4.3.
7.Each noti­fi­ed body shall inform its noti­fy­ing aut­ho­ri­ties con­cer­ning qua­li­ty system appr­ovals issued or with­drawn, and shall, peri­odi­cal­ly or upon request, make available to them the list of qua­li­ty system appr­ovals refu­sed, sus­pen­ded or other­wi­se restricted.
Each noti­fi­ed body shall inform the other noti­fi­ed bodies of qua­li­ty system appr­ovals which it has refu­sed, sus­pen­ded or with­drawn, and, upon request, of qua­li­ty system appr­ovals which it has issued.
8.Aut­ho­ri­zed representative
The manufacturer’s obli­ga­ti­ons set out in points 3.1, 3.5, 5 and 6 may be ful­fil­led by his aut­ho­ri­zed repre­sen­ta­ti­ve, on his behalf and under his respon­si­bi­li­ty, pro­vi­ded that the rele­vant obli­ga­ti­ons are spe­ci­fi­ed in the mandate.