Source: OJ L, 2025/2392, 1.12.2025

Current language: EN

Technical description of product categories

COMMISSION IMPLEMENTING REGULATION (EU) 2025/2392

of 28 November 2025

on the technical description of the categories of important and critical products with digital elements pursuant to Regulation (EU) 2024/2847 of the European Parliament and of the Council

(Text with EEA relevance)

THE EUROPEAN COMMISSION,

Having regard to the Treaty on the Functioning of the European Union,

Having regard to Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)(1)OJ L, 2024/2847, 20.11.2024, ELI: http://data.europa.eu/eli/reg/2024/2847/oj., and in particular Article 7(4) thereof,

Whereas:

Open full page
Recital 1Important and critical products with digital elements

Regulation (EU) 2024/2847 lays down rules on the cybersecurity of products with digital elements. In particular, Annex III to that Regulation sets out categories of important products with digital elements that, when placed on the market, are subject to conformity assessment procedures that are stricter than those applicable to other products with digital elements. Annex IV to Regulation (EU) 2024/2847 sets out categories of critical products with digital elements for which manufacturers could be required to obtain a European cybersecurity certificate under a European cybersecurity certification scheme pursuant to Regulation (EU) 2019/881 of the European Parliament and of the Council(2)Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act) (OJ L 151, 7.6.2019, p. 15, ELI: http://data.europa.eu/eli/reg/2019/881/oj). or which would be subject to mandatory third-party conformity assessment, when placed on the market.

Recital 2Core functionality determines product category

Pursuant to Article 7(1) and Article 8(1) of Regulation (EU) 2024/2847, the core functionality of a product with digital elements determines whether that product with digital elements meets the technical description of a category of important or critical products with digital elements and therefore the applicable conformity assessment procedures.

Recital 3Integrated components that are important or critical products

When developing a product with digital elements, and in order to achieve their desired set of functionalities, manufacturers typically integrate into their own products with digital elements other components which are also products with digital elements and that can meet the technical description of a category of important or critical products. Pursuant to Regulation (EU) 2024/2847, a product with digital elements is subject to the conformity assessment procedures applicable to important or critical products with digital elements, if that product as a whole is an important or critical product as set out in Annexes III and IV to that Regulation. For example, integrating an embedded browser as a component of a news app for use in smartphones does not in itself render the news app subject to the conformity assessment procedure applicable to products with digital elements that have the core functionality of ‘standalone and embedded browsers’. Nonetheless, in accordance with Regulation (EU) 2024/2847, the manufacturer needs to ensure that the product with digital elements as a whole meets the essential cybersecurity requirements. Therefore, the manufacturer needs to evaluate the security of the whole product, considering, as appropriate, the security of the components or functionalities that are integrated into it. For example, in order for the manufacturer of a news app to demonstrate that its product with digital elements is in conformity with Regulation (EU) 2024/2847, that manufacturer is to demonstrate that the news app as a whole satisfies the applicable requirements, considering, as appropriate, the security of the embedded browser that is integrated into its app.

HAS ADOPTED THIS REGULATION:

  1. Article 1Definitions
  2. Article 2
  3. Article 3
Annexes(1 – 2)
  1. Annex IIMPORTANT PRODUCTS WITH DIGITAL ELEMENTS
  2. Annex IICRITICAL PRODUCTS WITH DIGITAL ELEMENTS

This Regulation shall be binding in its entirety and directly applicable in all Member States.

Done at Brussels, 28 November 2025.

For the Commission

The President

Ursula VON DER LEYEN

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod