Reference
Definitions
Every key defined term, mapped to the verified Facts Table entry that explains it.
| Actively exploited vulnerability | One of the two reporting triggers, with a 24-hour fuse. |
| Authorised representative (definition) | Defined at Article 3(15): the mandated person in the Union. |
| Commercial activity | The scope trigger the Regulation leans on but does not define in Article 3. |
| Distributor (definition) | Defined at Article 3(17): making available without importing. |
| Importer (definition) | Defined at Article 3(16): the EU-established person placing a non-EU brand's product on the market. |
| Making available on the market | The market trigger, and why company location is irrelevant. |
| Manufacturer | The role that carries the duty set — and the ways you become it without noticing. |
| Open-source software steward | The institutional role behind the open-source regime. |
| Placing on the market | Defined at Article 3(21): the first supply, and why 'first' carries so much weight. |
| Product with digital elements | The gateway definition: hardware or software plus the remote processing it depends on. |
| Remote data processing | The definition that pulls your backend into your product. |
| Severe incident | The second reporting trigger, aimed at the product's own security. |
| Substantial modification | The post-market change that brings conformity duties into play. |
| Support period | The manufacturer-set window: at least five years unless expected use is shorter. |