Annex II Information and instructions to the user


At minimum, the product with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; shall be accompanied by:

  1. the name, registered trade name or registered trademark of the manufacturer means a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge;, and the postal address, the email address or other digital contact as well as, where available, the website at which the manufacturer means a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge; can be contacted;

  2. the single point of contact where information about vulnerabilities means a weakness, susceptibility or flaw of a product with digital elements that can be exploited by a cyber threat; of the product with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; can be reported and received, and where the manufacturer means a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge;’s policy on coordinated vulnerability means a weakness, susceptibility or flaw of a product with digital elements that can be exploited by a cyber threat; disclosure can be found;

  3. name and type and any additional information enabling the unique identification of the product with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately;;

  4. the intended purpose means the use for which a product with digital elements is intended by the manufacturer, including the specific context and conditions of use, as specified in the information supplied by the manufacturer in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation; of the product with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately;, including the security environment provided by the manufacturer means a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge;, as well as the product’s essential functionalities and information about the security properties;

  5. any known or foreseeable circumstance, related to the use of the product with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; in accordance with its intended purpose means the use for which a product with digital elements is intended by the manufacturer, including the specific context and conditions of use, as specified in the information supplied by the manufacturer in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation; or under conditions of reasonably foreseeable misuse means the use of a product with digital elements in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems;, which may lead to significant cybersecurity risks means a cybersecurity risk which, based on its technical characteristics, can be assumed to have a high likelihood of an incident that could lead to a severe negative impact, including by causing considerable material or non-material loss or disruption;;

  6. where applicable, the internet address at which the EU declaration of conformity can be accessed;

  7. the type of technical security support offered by the manufacturer means a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge; and the end-date of the support period means the period during which a manufacturer is required to ensure that vulnerabilities of a product with digital elements are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I; during which users can expect vulnerabilities means a weakness, susceptibility or flaw of a product with digital elements that can be exploited by a cyber threat; to be handled and to receive security updates;

  8. detailed instructions or an internet address referring to such detailed instructions and information on:

    1. the necessary measures during initial commissioning and throughout the lifetime of the product with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; to ensure its secure use;

    2. how changes to the product with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; can affect the security of data;

    3. how security-relevant updates can be installed;

    4. the secure decommissioning of the product with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately;, including information on how user data can be securely removed;

    5. how the default setting enabling the automatic installation of security updates, as required by Part I, point (2)(c), of Annex I, can be turned off;

    6. where the product with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; is intended for integration into other products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately;, the information necessary for the integrator to comply with the essential cybersecurity means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; requirements set out in Annex I and the documentation requirements set out in Annex VII.

  9. If the manufacturer means a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge; decides to make available the software bill of materials means a formal record containing details and supply chain relationships of components included in the software elements of a product with digital elements; to the user, information on where the software bill of materials means a formal record containing details and supply chain relationships of components included in the software elements of a product with digital elements; can be accessed.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod