Article 26 Guidance


    1. In order to facilitate implementation and ensure the consistency of such implementation, the Commission shall publish guidance to assist economic operators means the manufacturer, the authorised representative, the importer, the distributor, or other natural or legal person who is subject to obligations in relation to the manufacture of products with digital elements or to the making available of products with digital elements on the market in accordance with this Regulation; in applying this Regulation, with a particular focus on facilitating compliance by microenterprises, ‘small enterprises’ and ‘medium-sized enterprises’ mean, respectively, microenterprises, small enterprises and medium-sized enterprises as defined in the Annex to Recommendation 2003/361/EC; and small and medium-sized enterprises means a financial entity that is not a small enterprise and employs fewer than 250 persons and has an annual turnover that does not exceed EUR 50 million and/or an annual balance sheet that does not exceed EUR 43 million;.

    1. Where it intends to provide guidance as referred to in paragraph 1, the Commission shall address at least the following aspects:

      1. the scope of this Regulation, with a particular focus on remote data processing means data processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the product with digital elements from performing one of its functions; solutions and free and open-source software means software the source code of which is openly shared and which is made available under a free and open-source licence which provides for all rights to make it freely accessible, usable, modifiable and redistributable;;

      2. the application of support periods means the period during which a manufacturer is required to ensure that vulnerabilities of a product with digital elements are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I; in relation to particular categories of products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately;;

      3. guidance targeted at manufacturers means a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge; subject to this Regulation that are also subject to Union harmonisation legislation means Union legislation listed in Annex I to Regulation (EU) 2019/1020 and any other Union legislation harmonising the conditions for the marketing of products to which that Regulation applies; other than this Regulation or to other related Union legal acts;

      4. the concept of substantial modification means a change to the product with digital elements following its placing on the market, which affects the compliance of the product with digital elements with the essential cybersecurity requirements set out in Part I of Annex I or which results in a modification to the intended purpose for which the product with digital elements has been assessed;.

    2. The Commission shall also maintain an easy-to-access list of the delegated and implementing acts adopted pursuant to this Regulation.

    1. When preparing the guidance pursuant to this Article, the Commission shall consult relevant stakeholders.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod