Cyber Resilience Act (CRA)
Table of Contents
Chapter I – GENERAL PROVISIONS
Chapter II – OBLIGATIONS OF ECONOMIC OPERATORS AND PROVISIONS IN RELATION TO FREE AND OPEN-SOURCE SOFTWARE
Chapter III – CONFORMITY OF THE PRODUCT WITH DIGITAL ELEMENTS
Chapter IV – NOTIFICATION OF CONFORMITY ASSESSMENT BODIES
Chapter V – MARKET SURVEILLANCE AND ENFORCEMENT
Chapter VI – DELEGATED POWERS AND COMMITTEE PROCEDURE
Chapter VII – CONFIDENTIALITY AND PENALTIES
Chapter VIII – TRANSITIONAL AND FINAL PROVISIONS
Recitals (130)
Annexes
Recital 38
(38) In order to ensure that products with digital elements, when placed on the market, do not pose cybersecurity risks to persons and organisations, essential cybersecurity requirements should be set out for such products. Those essential cybersecurity requirements, including vulnerability management handling requirements, apply to each individual product with digital elements when placed on the market, irrespective of whether the product with digital elements is manufactured as an individual unit or in series. For example, for a product type, each individual product with digital elements should have received all security patches or updates available to address relevant security issues when it is placed on the market. Where products with digital elements are subsequently modified, by physical or digital means, in a way that is not foreseen by the manufacturer in the initial risk assessment and that may imply that they no longer meet the relevant essential cybersecurity requirements, the modification should be considered to be substantial. For example, repairs could be assimilated to maintenance operations provided that they do not modify a product with digital elements already placed on the market in such a way that compliance with the applicable requirements may be affected, or that the intended purpose for which the product has been assessed may be changed.