Regulation (EU) 2024/2847 · Chapter
Article 33 — Support measures for microenterprises and small and medium-sized enterprises, including start-ups
SME support: the Regulation's own on-ramp for small manufacturers.
LAW Official text — verbatim from the Official Journal snapshot; only the Official Journal is authentic.
1.1. Member States shall, where appropriate, undertake the following actions, tailored to the needs of microenterprises and small enterprises:
(a) organise specific awareness-raising and training activities about the application of this Regulation;
(b) establish a dedicated channel for communication with microenterprises and small enterprises and, as appropriate, local public authorities to provide advice and respond to queries about the implementation of this Regulation;
(c) support testing and conformity assessment activities, including where relevant with the support of the European Cybersecurity Competence Centre.
2.2. Member States may, where appropriate, establish cyber resilience regulatory sandboxes. Such regulatory sandboxes shall provide for controlled testing environments for innovative products with digital elements to facilitate their development, design, validation and testing for the purpose of complying with this Regulation for a limited period of time before the placing on the market. The Commission and, where appropriate, ENISA, may provide technical support, advice and tools for the establishment and operation of regulatory sandboxes. The regulatory sandboxes shall be set up under the direct supervision, guidance and support by the market surveillance authorities. Member States shall inform the Commission and the other market surveillance authorities of the establishment of a regulatory sandbox through ADCO. The regulatory sandboxes shall not affect the supervisory and corrective powers of the competent authorities. Member States shall ensure open, fair, and transparent access to regulatory sandboxes, and in particular facilitate access by microenterprises and small enterprises, including start-ups.
3.3. In accordance with Article 26, the Commission shall provide guidance for microenterprises and small and medium-sized enterprises in relation to the implementation of this Regulation.
4.4. The Commission shall advertise available financial support in the regulatory framework of existing Union programmes, in particular in order to ease the financial burden on microenterprises and small enterprises.
5.5. Microenterprises and small enterprises may provide all elements of the technical documentation specified in Annex VII by using a simplified format. For that purpose, the Commission shall, by means of implementing acts, specify the simplified technical documentation form targeted at the needs of microenterprises and small enterprises, including how the elements set out in Annex VII are to be provided. Where a microenterprise or small enterprise opts to provide the information set out in Annex VII in a simplified manner, it shall use the form referred to in this paragraph. Notified bodies shall accept that form for the purposes of conformity assessment.
Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 62(2).
sha256:27b7c6c64c773001… · CELEX 32024R2847What this article does
Article 33 acknowledges who bears the compliance load hardest: micro, small and medium-sized enterprises, including startups. It has Member States, where appropriate, run measures tailored to microenterprises and small enterprises — awareness-raising and training, a dedicated communication channel for advice and queries, and support for testing and conformity assessment — and lets Member States set up cyber resilience regulatory sandboxes. The Commission provides guidance for SMEs, advertises available financial support under existing Union programmes, and is to specify a simplified technical documentation form that microenterprises and small enterprises may use.
Funding alongside it
One funding example, run under the Digital Europe Programme rather than created by Article 33, is the EU SECURE programme: co-funding of up to EUR 30,000 per SME for readiness activities, first call 28 January to 29 March 2026 F-039. For a small manufacturer, co-funding of that kind can shift the build-versus-defer calculus on compliance tooling and assessments.
Reading the room
Article 33 is a support article. It is not a discount on the requirements themselves.
Verified facts this page relies on
- F-039 The EU SECURE programme co-funds micro, small and medium enterprises up to EUR 30,000 for CRA readiness activities; first call ran 28 January–29 March 2026. Digital Europe Programme
Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).
Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.
Related in the reference
- Article 10 — Enhancing skills in a cyber resilient digital environment
- Article 26 — Guidance
- Topic: Conformity assessment