Article 7 Important products with digital elements


    1. Products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; which have the core functionality of a product category set out in Annex III shall be considered to be important products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; and shall be subject to the conformity assessment means the process of verifying whether the essential cybersecurity requirements set out in Annex I have been fulfilled; procedures referred to in Article 32(2) and (3). The integration of a product with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; which has the core functionality of a product category set out in Annex III shall not in itself render the product in which it is integrated subject to the conformity assessment means the process of verifying whether the essential cybersecurity requirements set out in Annex I have been fulfilled; procedures referred to in Article 32(2) and (3).

    1. The categories of products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; referred to in paragraph 1 of this Article, divided into classes I and II as set out in Annex III, meet at least one of the following criteria:

      1. the product with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; primarily performs functions critical to the cybersecurity means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; of other products, networks or services, including securing authentication and access, intrusion prevention and detection, end-point means any device that is connected to a network and serves as an entry point to that network; security or network protection;

      2. the product with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; performs a function which carries a significant risk means the potential for loss or disruption caused by an incident and is to be expressed as a combination of the magnitude of such loss or disruption and the likelihood of occurrence of the incident; of adverse effects in terms of its intensity and ability to disrupt, control or cause damage to a large number of other products or to the health, security or safety of its users through direct manipulation, such as a central system function, including network management, configuration control, virtualisation or processing of personal data means personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679;.

    1. The Commission is empowered to adopt delegated acts in accordance with Article 61 to amend Annex III by including in the list a new category within each class of the categories of products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; and specifying its definition, moving a category of products from one class to the other or withdrawing an existing category from that list. When assessing the need to amend the list set out in Annex III, the Commission shall take into account the cybersecurity-related functionalities or the function and the level of cybersecurity risk means the potential for loss or disruption caused by an incident and is to be expressed as a combination of the magnitude of such loss or disruption and the likelihood of occurrence of the incident; posed by the products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; as set out by the criteria referred to in paragraph 2 of this Article.

    2. The delegated acts referred to in the first subparagraph of this paragraph shall, where appropriate, provide for a minimum transitional period of 12 months, in particular where a new category of important products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; is added to class I or II or is moved from class I to II as set out in Annex III, before the relevant conformity assessment means the process of verifying whether the essential cybersecurity requirements set out in Annex I have been fulfilled; procedures as referred to in Article 32(2) and (3) start applying, unless a shorter transitional period is justified on imperative grounds of urgency.

    1. By 11 December 2025, the Commission shall adopt an implementing act specifying the technical description of the categories of products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; under classes I and II as set out in Annex III and the technical description of the categories of products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; as set out in Annex IV. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 62(2).

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod