Source: OJ L 2024/2847, 20.11.2024
ENRecital 48 Updates to categories of critical products
In order to ensure a common adequate cybersecurity means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; protection in the Union of products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; that have the core functionality of a category of critical products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; set out in this Regulation, the Commission should also be empowered to adopt delegated acts to amend this Regulation by adding or withdrawing categories of critical products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; for which manufacturers means a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge; could be required to obtain a European cybersecurity means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; certificate under a European cybersecurity means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; certification scheme pursuant to Regulation (EU) 2019/881 to demonstrate conformity with this Regulation. A new category of critical products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; can be added to those categories if there is a critical dependency on them by essential entities means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; as referred to in Article 3(1) of Directive (EU) 2022/2555 or, if affected by incidents means an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555; or when containing exploited vulnerabilities means a weakness, susceptibility or flaw of a product with digital elements that can be exploited by a cyber threat;, this could lead to disruptions of critical supply chains. When assessing the need for adding or withdrawing categories of critical products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; by means of a delegated act, the Commission should be able to take into account whether the Member States have identified at national level products with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; that have a critical role for the resilience of essential entities means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; as referred to in Article 3(1) of Directive (EU) 2022/2555 and which increasingly face supply chain cyberattacks, with potential serious disruptive effects. Furthermore, the Commission should be able to take into account the outcome of the Union level coordinated security risk means the potential for loss or disruption caused by an incident and is to be expressed as a combination of the magnitude of such loss or disruption and the likelihood of occurrence of the incident; assessment of critical supply chains carried out in accordance with Article 22 of Directive (EU) 2022/2555.