Recital 41 Verification of compliance after substantial modification


In line with the commonly established concept of substantial modification means a change to the product with digital elements following its placing on the market, which affects the compliance of the product with digital elements with the essential cybersecurity requirements set out in Part I of Annex I or which results in a modification to the intended purpose for which the product with digital elements has been assessed; for products regulated by Union harmonisation legislation means Union legislation listed in Annex I to Regulation (EU) 2019/1020 and any other Union legislation harmonising the conditions for the marketing of products to which that Regulation applies;, where a substantial modification means a change to the product with digital elements following its placing on the market, which affects the compliance of the product with digital elements with the essential cybersecurity requirements set out in Part I of Annex I or which results in a modification to the intended purpose for which the product with digital elements has been assessed; occurs that may affect the compliance of a product with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; with this Regulation or when the intended purpose means the use for which a product with digital elements is intended by the manufacturer, including the specific context and conditions of use, as specified in the information supplied by the manufacturer in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation; of that product changes, it is appropriate that the compliance of the product with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; is verified and that, where applicable, it undergoes a new conformity assessment means the process of verifying whether the essential cybersecurity requirements set out in Annex I have been fulfilled;. Where applicable, if the manufacturer means a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge; undertakes a conformity assessment means the process of verifying whether the essential cybersecurity requirements set out in Annex I have been fulfilled; involving a third party, a change that might lead to a substantial modification means a change to the product with digital elements following its placing on the market, which affects the compliance of the product with digital elements with the essential cybersecurity requirements set out in Part I of Annex I or which results in a modification to the intended purpose for which the product with digital elements has been assessed; should be notified to the third party.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod