Regulation (EU) 2024/2847
Articles
All operative provisions of the Cyber Resilience Act, with verbatim official text and — where marked — reviewed explanation.
- Art. 1 — Subject matter ·
- Art. 2 — Scope ·
- Art. 3 — Definitions ·
- Art. 4 — Free movement ·
- Art. 5 — Procurement or use of products with digital elements ·
- Art. 6 — Requirements for products with digital elements ·
- Art. 7 — Important products with digital elements ·
- Art. 8 — Critical products with digital elements ·
- Art. 9 — Stakeholder consultation ·
- Art. 10 — Enhancing skills in a cyber resilient digital environment ·
- Art. 11 — General product safety ·
- Art. 12 — High-risk AI systems ·
- Art. 13 — Obligations of manufacturers ·
- Art. 14 — Reporting obligations of manufacturers ·
- Art. 15 — Voluntary reporting ·
- Art. 16 — Establishment of a single reporting platform ·
- Art. 17 — Other provisions related to reporting ·
- Art. 18 — Authorised representatives ·
- Art. 19 — Obligations of importers ·
- Art. 20 — Obligations of distributors ·
- Art. 21 — Cases in which obligations of manufacturers apply to importers and distributors ·
- Art. 22 — Other cases in which obligations of manufacturers apply ·
- Art. 23 — Identification of economic operators ·
- Art. 24 — Obligations of open-source software stewards ·
- Art. 25 — Security attestation of free and open-source software ·
- Art. 26 — Guidance ·
- Art. 27 — Presumption of conformity ·
- Art. 28 — EU declaration of conformity ·
- Art. 29 — General principles of the CE marking ·
- Art. 30 — Rules and conditions for affixing the CE marking ·
- Art. 31 — Technical documentation ·
- Art. 32 — Conformity assessment procedures for products with digital elements ·
- Art. 33 — Support measures for microenterprises and small and medium-sized enterprises, including start-ups ·
- Art. 34 — Mutual recognition agreements ·
- Art. 35 — Notification ·
- Art. 36 — Notifying authorities ·
- Art. 37 — Requirements relating to notifying authorities ·
- Art. 38 — Information obligation on notifying authorities ·
- Art. 39 — Requirements relating to notified bodies ·
- Art. 40 — Presumption of conformity of notified bodies ·
- Art. 41 — Subsidiaries of and subcontracting by notified bodies ·
- Art. 42 — Application for notification ·
- Art. 43 — Notification procedure ·
- Art. 44 — Identification numbers and lists of notified bodies ·
- Art. 45 — Changes to notifications ·
- Art. 46 — Challenge of the competence of notified bodies ·
- Art. 47 — Operational obligations of notified bodies ·
- Art. 48 — Appeal against decisions of notified bodies ·
- Art. 49 — Information obligation on notified bodies ·
- Art. 50 — Exchange of experience ·
- Art. 51 — Coordination of notified bodies ·
- Art. 52 — Market surveillance and control of products with digital elements in the Union market ·
- Art. 53 — Access to data and documentation ·
- Art. 54 — Procedure at national level concerning products with digital elements presenting a significant cybersecurity risk ·
- Art. 55 — Union safeguard procedure ·
- Art. 56 — Procedure at Union level concerning products with digital elements presenting a significant cybersecurity risk ·
- Art. 57 — Compliant products with digital elements which present a significant cybersecurity risk ·
- Art. 58 — Formal non-compliance ·
- Art. 59 — Joint activities of market surveillance authorities ·
- Art. 60 — Sweeps ·
- Art. 61 — Exercise of the delegation ·
- Art. 62 — Committee procedure ·
- Art. 63 — Confidentiality ·
- Art. 64 — Penalties ·
- Art. 65 — Representative actions ·
- Art. 66 — Amendment to Regulation (EU) 2019/1020 ·
- Art. 67 — Amendment to Directive (EU) 2020/1828 ·
- Art. 68 — Amendment to Regulation (EU) No 168/2013 ·
- Art. 69 — Transitional provisions ·
- Art. 70 — Evaluation and review ·
- Art. 71 — Entry into force and application ·
A dot marks articles with an InsideCRA explanation layer beyond the official text.