Source: OJ L 2024/2847, 20.11.2024

Current language: EN

Article 1 Subject matter


Summary What does Article 1 of the Cyber Resilience Act say?

This is the foundational scope article of the regulation.

It establishes the four pillars of what the regulation covers: market access rules for products with digital elements, cybersecurity requirements tied to how those products are designed and built, requirements for how manufacturers handle vulnerabilities throughout a product's lifetime, and the framework for market surveillance and enforcement.

It sets the stage for everything that follows in the regulation.

Important points:

  • Comply with essential cybersecurity requirements covering both how products with digital elements are designed and produced, and how vulnerabilities in those products are managed over time.
  • Economic operators — including manufacturers, importers, and distributors — bear obligations under all three substantive pillars of the regulation.
  • Market surveillance and enforcement rules are included within the regulation's scope, not left to separate instruments.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

This Regulation lays down:

  1. rules for the making available on the market of products with digital elements to ensure the cybersecurity of such products;

  2. essential cybersecurity requirements for the design, development and production of products with digital elements, and obligations for economic operators in relation to those products with respect to cybersecurity;

  3. essential cybersecurity requirements for the vulnerability handling processes put in place by manufacturers to ensure the cybersecurity of products with digital elements during the time the products are expected to be in use, and obligations for economic operators in relation to those processes;

  4. rules on market surveillance, including monitoring, and enforcement of the rules and requirements referred to in this Article.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod