Article 3 Definitions


For the purposes of this Regulation, the following definitions apply:

  1. product with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately;’ means a softwaremeans the part of an electronic information system which consists of computer code; or hardwaremeans a physical electronic information system, or parts thereof capable of processing, storing or transmitting digital data; product and its remote data processingmeans data processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the product with digital elements from performing one of its functions; solutions, including softwaremeans the part of an electronic information system which consists of computer code; or hardwaremeans a physical electronic information system, or parts thereof capable of processing, storing or transmitting digital data; componentsmeans software or hardware intended for integration into an electronic information system; being placed on the market separately;

  2. remote data processingmeans data processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the product with digital elements from performing one of its functions;’ means data processing at a distance for which the softwaremeans the part of an electronic information system which consists of computer code; is designed and developed by the manufacturermeans a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge;, or under the responsibility of the manufacturermeans a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge;, and the absence of which would prevent the product with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; from performing one of its functions;

  3. cybersecuritymeans cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881;’ means cybersecuritymeans cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; as defined in Article 2, point (1), of Regulation (EU) 2019/881;

  4. softwaremeans the part of an electronic information system which consists of computer code;’ means the part of an electronic information systemmeans a system, including electrical or electronic equipment, capable of processing, storing or transmitting digital data; which consists of computer code;

  5. hardwaremeans a physical electronic information system, or parts thereof capable of processing, storing or transmitting digital data;’ means a physical electronic information systemmeans a system, including electrical or electronic equipment, capable of processing, storing or transmitting digital data;, or parts thereof capable of processing, storing or transmitting digital data;

  6. componentmeans software or hardware intended for integration into an electronic information system;’ means softwaremeans the part of an electronic information system which consists of computer code; or hardwaremeans a physical electronic information system, or parts thereof capable of processing, storing or transmitting digital data; intended for integration into an electronic information systemmeans a system, including electrical or electronic equipment, capable of processing, storing or transmitting digital data;;

  7. electronic information systemmeans a system, including electrical or electronic equipment, capable of processing, storing or transmitting digital data;’ means a system, including electrical or electronic equipment, capable of processing, storing or transmitting digital data;

  8. logical connectionmeans a virtual representation of a data connection implemented through a software interface;’ means a virtual representation of a data connection implemented through a softwaremeans the part of an electronic information system which consists of computer code; interface;

  9. physical connectionmeans a connection between electronic information systems or components implemented using physical means, including through electrical, optical or mechanical interfaces, wires or radio waves;’ means a connection between electronic information systemsmeans a system, including electrical or electronic equipment, capable of processing, storing or transmitting digital data; or componentsmeans software or hardware intended for integration into an electronic information system; implemented using physical means, including through electrical, optical or mechanical interfaces, wires or radio waves;

  10. indirect connectionmeans a connection to a device or network, which does not take place directly but rather as part of a larger system that is directly connectable to such device or network;’ means a connection to a device or network, which does not take place directly but rather as part of a larger system that is directly connectable to such device or network;

  11. end-pointmeans any device that is connected to a network and serves as an entry point to that network;’ means any device that is connected to a network and serves as an entry point to that network;

  12. economic operatormeans the manufacturer, the authorised representative, the importer, the distributor, or other natural or legal person who is subject to obligations in relation to the manufacture of products with digital elements or to the making available of products with digital elements on the market in accordance with this Regulation;’ means the manufacturermeans a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge;, the authorised representativemeans a natural or legal person established within the Union who has received a written mandate from a manufacturer to act on its behalf in relation to specified tasks;, the importermeans a natural or legal person established in the Union who places on the market a product with digital elements that bears the name or trademark of a natural or legal person established outside the Union;, the distributormeans a natural or legal person in the supply chain, other than the manufacturer or the importer, that makes a product with digital elements available on the Union market without affecting its properties;, or other natural or legal person who is subject to obligations in relation to the manufacture of products with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; or to the making available of products with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; on the market in accordance with this Regulation;

  13. manufacturermeans a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge;’ means a natural or legal person who develops or manufactures products with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; or has products with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge;

  14. open-source software stewardmeans a legal person, other than a manufacturer, that has the purpose or objective of systematically providing support on a sustained basis for the development of specific products with digital elements, qualifying as free and open-source software and intended for commercial activities, and that ensures the viability of those products;’ means a legal person, other than a manufacturermeans a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge;, that has the purpose or objective of systematically providing support on a sustained basis for the development of specific products with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately;, qualifying as free and open-source softwaremeans software the source code of which is openly shared and which is made available under a free and open-source licence which provides for all rights to make it freely accessible, usable, modifiable and redistributable; and intended for commercial activities, and that ensures the viability of those products;

  15. authorised representativemeans a natural or legal person established within the Union who has received a written mandate from a manufacturer to act on its behalf in relation to specified tasks;’ means a natural or legal person established within the Union who has received a written mandate from a manufacturermeans a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge; to act on its behalf in relation to specified tasks;

  16. importermeans a natural or legal person established in the Union who places on the market a product with digital elements that bears the name or trademark of a natural or legal person established outside the Union;’ means a natural or legal person established in the Union who places on the market a product with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; that bears the name or trademark of a natural or legal person established outside the Union;

  17. distributormeans a natural or legal person in the supply chain, other than the manufacturer or the importer, that makes a product with digital elements available on the Union market without affecting its properties;’ means a natural or legal person in the supply chain, other than the manufacturermeans a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge; or the importermeans a natural or legal person established in the Union who places on the market a product with digital elements that bears the name or trademark of a natural or legal person established outside the Union;, that makes a product with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; available on the Union market without affecting its properties;

  18. consumermeans a natural person who acts for purposes which are outside that person’s trade, business, craft or profession;’ means a natural person who acts for purposes which are outside that person’s trade, business, craft or profession;

  19. microenterprises, ‘small enterprises’ and ‘medium-sized enterprises’ mean, respectively, microenterprises, small enterprises and medium-sized enterprises as defined in the Annex to Recommendation 2003/361/EC;’, ‘small enterprises’ and ‘medium-sized enterprises’ mean, respectively, microenterprises, ‘small enterprises’ and ‘medium-sized enterprises’ mean, respectively, microenterprises, small enterprises and medium-sized enterprises as defined in the Annex to Recommendation 2003/361/EC;, small enterprises and medium-sized enterprises as defined in the Annex to Recommendation 2003/361/EC;

  20. support periodmeans the period during which a manufacturer is required to ensure that vulnerabilities of a product with digital elements are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I;’ means the period during which a manufacturermeans a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge; is required to ensure that vulnerabilitiesmeans a weakness, susceptibility or flaw of a product with digital elements that can be exploited by a cyber threat; of a product with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; are handled effectively and in accordance with the essential cybersecuritymeans cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; requirements set out in Part II of Annex I;

  21. placing on the marketmeans the first making available of a product with digital elements on the Union market;’ means the first making available of a product with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; on the Union market;

  22. making available on the marketmeans the supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge;’ means the supply of a product with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge;

  23. intended purposemeans the use for which a product with digital elements is intended by the manufacturer, including the specific context and conditions of use, as specified in the information supplied by the manufacturer in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation;’ means the use for which a product with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; is intended by the manufacturermeans a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge;, including the specific context and conditions of use, as specified in the information supplied by the manufacturermeans a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge; in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation;

  24. reasonably foreseeable usemeans use that is not necessarily the intended purpose supplied by the manufacturer in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation, but which is likely to result from reasonably foreseeable human behaviour or technical operations or interactions;’ means use that is not necessarily the intended purposemeans the use for which a product with digital elements is intended by the manufacturer, including the specific context and conditions of use, as specified in the information supplied by the manufacturer in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation; supplied by the manufacturermeans a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge; in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation, but which is likely to result from reasonably foreseeable human behaviour or technical operations or interactions;

  25. reasonably foreseeable misusemeans the use of a product with digital elements in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems;’ means the use of a product with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; in a way that is not in accordance with its intended purposemeans the use for which a product with digital elements is intended by the manufacturer, including the specific context and conditions of use, as specified in the information supplied by the manufacturer in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation;, but which may result from reasonably foreseeable human behaviour or interaction with other systems;

  26. notifying authoritymeans the national authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring;’ means the national authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodiesmeans a conformity assessment body as defined in Article 2, point (13), of Regulation (EC) No 765/2008; and for their monitoring;

  27. conformity assessmentmeans the process of verifying whether the essential cybersecurity requirements set out in Annex I have been fulfilled;’ means the process of verifying whether the essential cybersecuritymeans cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; requirements set out in Annex I have been fulfilled;

  28. conformity assessment bodymeans a conformity assessment body as defined in Article 2, point (13), of Regulation (EC) No 765/2008;’ means a conformity assessment bodymeans a conformity assessment body as defined in Article 2, point (13), of Regulation (EC) No 765/2008; as defined in Article 2, point (13), of Regulation (EC) No 765/2008;

  29. notified bodymeans a conformity assessment body designated in accordance with Article 43 and other relevant Union harmonisation legislation;’ means a conformity assessment bodymeans a conformity assessment body as defined in Article 2, point (13), of Regulation (EC) No 765/2008; designated in accordance with Article 43 and other relevant Union harmonisation legislationmeans Union legislation listed in Annex I to Regulation (EU) 2019/1020 and any other Union legislation harmonising the conditions for the marketing of products to which that Regulation applies;;

  30. substantial modificationmeans a change to the product with digital elements following its placing on the market, which affects the compliance of the product with digital elements with the essential cybersecurity requirements set out in Part I of Annex I or which results in a modification to the intended purpose for which the product with digital elements has been assessed;’ means a change to the product with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; following its placing on the marketmeans the first making available of a product with digital elements on the Union market;, which affects the compliance of the product with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; with the essential cybersecuritymeans cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; requirements set out in Part I of Annex I or which results in a modification to the intended purposemeans the use for which a product with digital elements is intended by the manufacturer, including the specific context and conditions of use, as specified in the information supplied by the manufacturer in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation; for which the product with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; has been assessed;

  31. CE markingmeans a marking by which a manufacturer indicates that a product with digital elements and the processes put in place by the manufacturer are in conformity with the essential cybersecurity requirements set out in Annex I and other applicable Union harmonisation legislation providing for its affixing;’ means a marking by which a manufacturermeans a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge; indicates that a product with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; and the processes put in place by the manufacturermeans a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge; are in conformity with the essential cybersecuritymeans cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; requirements set out in Annex I and other applicable Union harmonisation legislationmeans Union legislation listed in Annex I to Regulation (EU) 2019/1020 and any other Union legislation harmonising the conditions for the marketing of products to which that Regulation applies; providing for its affixing;

  32. Union harmonisation legislationmeans Union legislation listed in Annex I to Regulation (EU) 2019/1020 and any other Union legislation harmonising the conditions for the marketing of products to which that Regulation applies;’ means Union legislation listed in Annex I to Regulation (EU) 2019/1020 and any other Union legislation harmonising the conditions for the marketing of products to which that Regulation applies;

  33. market surveillance authoritymeans a market surveillance authority as defined in Article 3, point (4), of Regulation (EU) 2019/1020;’ means a market surveillance authoritymeans a market surveillance authority as defined in Article 3, point (4), of Regulation (EU) 2019/1020; as defined in Article 3, point (4), of Regulation (EU) 2019/1020;

  34. international standardmeans an international standard as defined in Article 2, point (1)(a), of Regulation (EU) No 1025/2012;’ means an international standardmeans an international standard as defined in Article 2, point (1)(a), of Regulation (EU) No 1025/2012; as defined in Article 2, point (1)(a), of Regulation (EU) No 1025/2012;

  35. European standardmeans a European standard as defined in Article 2, point (1)(b), of Regulation (EU) No 1025/2012;’ means a European standardmeans a European standard as defined in Article 2, point (1)(b), of Regulation (EU) No 1025/2012; as defined in Article 2, point (1)(b), of Regulation (EU) No 1025/2012;

  36. harmonised standardmeans a harmonised standard as defined in Article 2, point (1)(c), of Regulation (EU) No 1025/2012;’ means a harmonised standardmeans a harmonised standard as defined in Article 2, point (1)(c), of Regulation (EU) No 1025/2012; as defined in Article 2, point (1)(c), of Regulation (EU) No 1025/2012;

  37. cybersecurity riskmeans the potential for loss or disruption caused by an incident and is to be expressed as a combination of the magnitude of such loss or disruption and the likelihood of occurrence of the incident;’ means the potential for loss or disruption caused by an incidentmeans an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555; and is to be expressed as a combination of the magnitude of such loss or disruption and the likelihood of occurrence of the incidentmeans an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555;;

  38. significant cybersecurity riskmeans a cybersecurity risk which, based on its technical characteristics, can be assumed to have a high likelihood of an incident that could lead to a severe negative impact, including by causing considerable material or non-material loss or disruption;’ means a cybersecurity riskmeans the potential for loss or disruption caused by an incident and is to be expressed as a combination of the magnitude of such loss or disruption and the likelihood of occurrence of the incident; which, based on its technical characteristics, can be assumed to have a high likelihood of an incidentmeans an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555; that could lead to a severe negative impact, including by causing considerable material or non-material loss or disruption;

  39. software bill of materialsmeans a formal record containing details and supply chain relationships of components included in the software elements of a product with digital elements;’ means a formal record containing details and supply chain relationships of componentsmeans software or hardware intended for integration into an electronic information system; included in the softwaremeans the part of an electronic information system which consists of computer code; elements of a product with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately;;

  40. vulnerabilitymeans a weakness, susceptibility or flaw of a product with digital elements that can be exploited by a cyber threat;’ means a weakness, susceptibility or flaw of a product with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; that can be exploited by a cyber threatmeans a cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881;;

  41. exploitable vulnerabilitymeans a vulnerability that has the potential to be effectively used by an adversary under practical operational conditions;’ means a vulnerabilitymeans a weakness, susceptibility or flaw of a product with digital elements that can be exploited by a cyber threat; that has the potential to be effectively used by an adversary under practical operational conditions;

  42. actively exploited vulnerabilitymeans a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner;’ means a vulnerabilitymeans a weakness, susceptibility or flaw of a product with digital elements that can be exploited by a cyber threat; for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner;

  43. incidentmeans an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555;’ means an incidentmeans an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555; as defined in Article 6, point (6), of Directive (EU) 2022/2555;

  44. incident having an impact on the security of the product with digital elementsmeans an incident that negatively affects or is capable of negatively affecting the ability of a product with digital elements to protect the availability, authenticity, integrity or confidentiality of data or functions;’ means an incidentmeans an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555; that negatively affects or is capable of negatively affecting the ability of a product with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; to protect the availability, authenticity, integrity or confidentiality of data or functions;

  45. near missmeans a near miss as defined in Article 6, point (5), of Directive (EU) 2022/2555;’ means a near missmeans a near miss as defined in Article 6, point (5), of Directive (EU) 2022/2555; as defined in Article 6, point (5), of Directive (EU) 2022/2555;

  46. cyber threatmeans a cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881;’ means a cyber threatmeans a cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881; as defined in Article 2, point (8), of Regulation (EU) 2019/881;

  47. personal datameans personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679;’ means personal datameans personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679; as defined in Article 4, point (1), of Regulation (EU) 2016/679;

  48. free and open-source softwaremeans software the source code of which is openly shared and which is made available under a free and open-source licence which provides for all rights to make it freely accessible, usable, modifiable and redistributable;’ means softwaremeans the part of an electronic information system which consists of computer code; the source code of which is openly shared and which is made available under a free and open-source licence which provides for all rights to make it freely accessible, usable, modifiable and redistributable;

  49. recallmeans recall as defined in Article 3, point (22), of Regulation (EU) 2019/1020;’ means recallmeans recall as defined in Article 3, point (22), of Regulation (EU) 2019/1020; as defined in Article 3, point (22), of Regulation (EU) 2019/1020;

  50. withdrawalmeans withdrawal as defined in Article 3, point (23), of Regulation (EU) 2019/1020;’ means withdrawalmeans withdrawal as defined in Article 3, point (23), of Regulation (EU) 2019/1020; as defined in Article 3, point (23), of Regulation (EU) 2019/1020;

  51. CSIRT designated as coordinatormeans a CSIRT designated as coordinator pursuant to Article 12(1) of Directive (EU) 2022/2555.’ means a CSIRT designated as coordinatormeans a CSIRT designated as coordinator pursuant to Article 12(1) of Directive (EU) 2022/2555. pursuant to Article 12(1) of Directive (EU) 2022/2555.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod