Cyber Resilience Act (CRA)
Table of Contents
Chapter I — GENERAL PROVISIONS
Art. 1 — Subject matterArt. 2 — ScopeArt. 3 — DefinitionsArt. 4 — Free movementArt. 5 — Procurement or use of products with digital elementsArt. 6 — Requirements for products with digital elementsArt. 7 — Important products with digital elementsArt. 8 — Critical products with digital elementsArt. 9 — Stakeholder consultationArt. 10 — Enhancing skills in a cyber resilient digital environmentArt. 11 — General product safetyArt. 12 — High-risk AI systems
Chapter II — OBLIGATIONS OF ECONOMIC OPERATORS AND PROVISIONS IN RELATION TO FREE AND OPEN-SOURCE SOFTWARE
Art. 13 — Obligations of manufacturersArt. 14 — Reporting obligations of manufacturersArt. 15 — Voluntary reportingArt. 16 — Establishment of a single reporting platformArt. 17 — Other provisions related to reportingArt. 18 — Authorised representativesArt. 19 — Obligations of importersArt. 20 — Obligations of distributorsArt. 21 — Cases in which obligations of manufacturers apply to importers and distributorsArt. 22 — Other cases in which obligations of manufacturers applyArt. 23 — Identification of economic operatorsArt. 24 — Obligations of open-source software stewardsArt. 25 — Security attestation of free and open-source softwareArt. 26 — Guidance
Chapter III — CONFORMITY OF THE PRODUCT WITH DIGITAL ELEMENTS
Art. 27 — Presumption of conformityArt. 28 — EU declaration of conformityArt. 29 — General principles of the CE markingArt. 30 — Rules and conditions for affixing the CE markingArt. 31 — Technical documentationArt. 32 — Conformity assessment procedures for products with digital elementsArt. 33 — Support measures for microenterprises and small and medium-sized enterprises, including start-upsArt. 34 — Mutual recognition agreements
Chapter IV — NOTIFICATION OF CONFORMITY ASSESSMENT BODIES
Art. 35 — NotificationArt. 36 — Notifying authoritiesArt. 37 — Requirements relating to notifying authoritiesArt. 38 — Information obligation on notifying authoritiesArt. 39 — Requirements relating to notified bodiesArt. 40 — Presumption of conformity of notified bodiesArt. 41 — Subsidiaries of and subcontracting by notified bodiesArt. 42 — Application for notificationArt. 43 — Notification procedureArt. 44 — Identification numbers and lists of notified bodiesArt. 45 — Changes to notificationsArt. 46 — Challenge of the competence of notified bodiesArt. 47 — Operational obligations of notified bodiesArt. 48 — Appeal against decisions of notified bodiesArt. 49 — Information obligation on notified bodiesArt. 50 — Exchange of experienceArt. 51 — Coordination of notified bodies
Chapter V — MARKET SURVEILLANCE AND ENFORCEMENT
Art. 52 — Market surveillance and control of products with digital elements in the Union marketArt. 53 — Access to data and documentationArt. 54 — Procedure at national level concerning products with digital elements presenting a significant cybersecurity riskArt. 55 — Union safeguard procedureArt. 56 — Procedure at Union level concerning products with digital elements presenting a significant cybersecurity riskArt. 57 — Compliant products with digital elements which present a significant cybersecurity riskArt. 58 — Formal non-complianceArt. 59 — Joint activities of market surveillance authoritiesArt. 60 — Sweeps