Regulation (EU) 2024/2847 · Chapter
Article 1 — Subject matter
Subject matter: what the Regulation sets out to regulate.
LAW Official text — verbatim from the Official Journal snapshot; only the Official Journal is authentic.
This Regulation lays down:
(a) rules for the making available on the market of products with digital elements to ensure the cybersecurity of such products;
(b) essential cybersecurity requirements for the design, development and production of products with digital elements, and obligations for economic operators in relation to those products with respect to cybersecurity;
(c) essential cybersecurity requirements for the vulnerability handling processes put in place by manufacturers to ensure the cybersecurity of products with digital elements during the time the products are expected to be in use, and obligations for economic operators in relation to those processes;
(d) rules on market surveillance, including monitoring, and enforcement of the rules and requirements referred to in this Article.
sha256:27b7c6c64c773001… · CELEX 32024R2847What this article does
Article 1 is the table of contents in legal form: rules for making products with digital elements available, essential requirements for their design, development and production, vulnerability-handling expectations across the lifecycle, and the surveillance and enforcement machinery around all of it. The Regulation carrying it entered into force on 10 December 2024 F-001.
How to read it
The substance it previews lives elsewhere — the product properties and vulnerability-handling sets of Annex I F-017 F-018, and the reporting rhythm of Article 14 with its 24-hour early warning F-028. Article 1 is worth a single careful read for one reason: it names the four regulated things (making available, design requirements, lifecycle vulnerability handling, enforcement), and most later chapters unfold one or more of those four.
Verified facts this page relies on
- F-001 Regulation (EU) 2024/2847 entered into force on 10 December 2024. Art. 71(1)
- F-017 Annex I Part I — product properties (secure by design and default; see checklist items I.1–I.3m). Annex I Part I
- F-018 Annex I Part II — vulnerability handling requirements (checklist items II.1–II.8). Annex I Part II
- F-028 Actively exploited vulnerability: early warning within 24 hours of awareness; notification within 72 hours; final report within 14 days after a corrective or mitigating measure is available. Art. 14(1)–(2)
Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).
Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.