Source: OJ L 2024/2847, 20.11.2024
EN- Cyber resilience for products with digital elements
Basic legislative acts
- CRA regulation
Article 31 Technical documentation
The technical documentation shall contain all relevant data or details of the means used by the manufacturer means a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge; to ensure that the product with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; and the processes put in place by the manufacturer means a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge; comply with the essential cybersecurity means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; requirements set out in Annex I. It shall at least contain the elements set out in Annex VII.
The technical documentation shall be drawn up before the product with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; is placed on the market and shall be continuously updated, where appropriate, at least during the support period means the period during which a manufacturer is required to ensure that vulnerabilities of a product with digital elements are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I;.
For products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; as referred to in Article 12, which are also subject to other Union legal acts which provide for technical documentation, a single set of technical documentation shall be drawn up containing the information referred to in Annex VII and the information required by those Union legal acts.
The technical documentation and correspondence relating to any conformity assessment means the process of verifying whether the essential cybersecurity requirements set out in Annex I have been fulfilled; procedure shall be drawn up in an official language of the Member State in which the notified body means a conformity assessment body designated in accordance with Article 43 and other relevant Union harmonisation legislation; is established or in a language acceptable to that body.
The Commission is empowered to adopt delegated acts in accordance with Article 61 to supplement this Regulation by adding elements to be included in the technical documentation set out in Annex VII to take account of technological developments, as well as developments encountered in the implementation process of this Regulation. To that end, the Commission shall strive to ensure that the administrative burden on microenterprises, ‘small enterprises’ and ‘medium-sized enterprises’ mean, respectively, microenterprises, small enterprises and medium-sized enterprises as defined in the Annex to Recommendation 2003/361/EC; and small and medium-sized enterprises means a financial entity that is not a small enterprise and employs fewer than 250 persons and has an annual turnover that does not exceed EUR 50 million and/or an annual balance sheet that does not exceed EUR 43 million; is proportionate.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.