Regulation (EU) 2024/2847 · Chapter
Article 6 — Requirements for products with digital elements
Requirements: the one-sentence article that switches on Annex I.
LAW Official text — verbatim from the Official Journal snapshot; only the Official Journal is authentic.
Products with digital elements shall be made available on the market only where:
(a) they meet the essential cybersecurity requirements set out in Part I of Annex I, provided that they are properly installed, maintained, used for their intended purpose or under conditions which can reasonably be foreseen, and, where applicable, the necessary security updates have been installed; and
(b) the processes put in place by the manufacturer comply with the essential cybersecurity requirements set out in Part II of Annex I.
sha256:27b7c6c64c773001… · CELEX 32024R2847What this article does
Article 6 is short and load-bearing: products with digital elements are made available only if they meet the essential requirements — Annex I Part I for product properties F-017 and, for manufacturer processes, the vulnerability-handling set of Part II F-018. The Part I condition is framed for a product that is properly installed, maintained, used for its intended purpose or under reasonably foreseeable conditions and, where applicable, has had the necessary security updates installed.
Reading it right
The article is a pointer, and the direction of the pointer matters. The requirements attach to making the product available — they are market-entry conditions, not aspirations F-040 F-017. Everything operational about them (risk-conditioned application, documentation, assessment) arrives through Article 13 and the Annexes; Article 6 just closes the front door unless they are met F-017 F-018.
Verified facts this page relies on
- F-017 Annex I Part I — product properties (secure by design and default; see checklist items I.1–I.3m). Annex I Part I
- F-018 Annex I Part II — vulnerability handling requirements (checklist items II.1–II.8). Annex I Part II
- F-040 Products are made available without known exploitable vulnerabilities and with a secure-by-default configuration. Annex I Part I(2)(a)–(b)
Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).
Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.
Related in the reference
- Annex I — Essential cybersecurity requirements
- Article 13 — Obligations of manufacturers
- Topic: Secure by design and default