Regulation (EU) 2024/2847
Recitals
The recitals explain why the Regulation says what it says. They are not operative law, but they steer interpretation.
- Recital 1 — Cybersecurity is one of the key challenges for the Union. The number an…
- Recital 2 — This Regulation aims to set the boundary conditions for the development…
- Recital 3 — Relevant Union law in force comprises several sets of horizontal rules …
- Recital 4 — While existing Union law applies to certain products with digital eleme…
- Recital 5 — As regards microenterprises and small and medium-sized enterprises, whe…
- Recital 6 — The Commission should provide guidance to assist economic operators, in…
- Recital 7 — At Union level, various programmatic and political documents, such as t…
- Recital 8 — To increase the overall level of cybersecurity of all products with dig…
- Recital 9 — Under certain conditions, all products with digital elements integrated…
- Recital 10 — By laying down cybersecurity requirements for placing on the market pro…
- Recital 11 — The purpose of this Regulation is to ensure a high level of cybersecuri…
- Recital 12 — Cloud solutions constitute remote data processing solutions within the …
- Recital 13 — In line with the objective of this Regulation to remove obstacles to th…
- Recital 14 — This Regulation should be without prejudice to the Member States’ res…
- Recital 15 — This Regulation applies to economic operators only in relation to produ…
- Recital 16 — Products with digital elements provided as part of the delivery of a se…
- Recital 17 — Software and data that are openly shared and where users can freely acc…
- Recital 18 — Free and open-source software is understood as software the source code…
- Recital 19 — Taking into account the importance for cybersecurity of many products w…
- Recital 20 — The sole act of hosting products with digital elements on open reposito…
- Recital 21 — In order to support and facilitate the due diligence of manufacturers t…
- Recital 22 — In view of the public cybersecurity objectives of this Regulation and i…
- Recital 23 — The effectiveness of the implementation of this Regulation will also de…
- Recital 24 — A secure internet is indispensable for the functioning of critical infr…
- Recital 25 — Regulation (EU) 2017/745 of the European Parliament and of the Council …
- Recital 26 — Products with digital elements that are developed or modified exclusive…
- Recital 27 — Regulation (EU) 2019/2144 of the European Parliament and of the Council…
- Recital 28 — This Regulation lays down horizontal cybersecurity rules which are not …
- Recital 29 — In order to ensure that products with digital elements made available o…
- Recital 30 — Commission Delegated Regulation (EU) 2022/30 specifies that a number of…
- Recital 31 — Directive (EU) 2024/2853 of the European Parliament and of the Council …
- Recital 32 — This Regulation should be without prejudice to Regulation (EU) 2016/679…
- Recital 33 — To the extent that their products fall within the scope of this Regulat…
- Recital 34 — When integrating components sourced from third parties in products with…
- Recital 35 — Immediately after the transitional period for the application of this R…
- Recital 36 — Products with digital elements should bear the CE marking to visibly, l…
- Recital 37 — In order to ensure that manufacturers can release software for testing …
- Recital 38 — In order to ensure that products with digital elements, when placed on …
- Recital 39 — As is the case for physical repairs or modifications, a product with di…
- Recital 40 — Taking into account the iterative nature of software development, manuf…
- Recital 41 — In line with the commonly established concept of substantial modificati…
- Recital 42 — Where a product with digital elements is subject to ‘refurbishment’…
- Recital 43 — Products with digital elements should be considered to be important if …
- Recital 44 — Certain categories of products with digital elements should be subject …
- Recital 45 — Important products with digital elements as referred to in this Regulat…
- Recital 46 — The categories of critical products with digital elements set out in th…
- Recital 47 — Delegated acts requiring mandatory European cybersecurity certification…
- Recital 48 — In order to ensure a common adequate cybersecurity protection in the Un…
- Recital 49 — The Commission should ensure that a wide range of relevant stakeholders…
- Recital 50 — This Regulation addresses cybersecurity risks in a targeted manner. Pro…
- Recital 51 — Products with digital elements classified as high-risk AI systems pursu…
- Recital 52 — In order to improve the security of products with digital elements plac…
- Recital 53 — Manufacturers of products falling within the scope of Regulation (EU) 2…
- Recital 54 — In order to ensure that products with digital elements are secure both …
- Recital 55 — Where certain essential cybersecurity requirements are not applicable t…
- Recital 56 — One of the most important measures for users to take in order to protec…
- Recital 57 — To improve the transparency of vulnerability handling processes and to …
- Recital 58 — The joint communication of the Commission and the High Representative o…
- Recital 59 — For the purpose of ensuring the security of products with digital eleme…
- Recital 60 — The support period for which the manufacturer ensures the effective han…
- Recital 61 — When products with digital elements reach the end of their support peri…
- Recital 62 — In order to ensure that manufacturers across the Union determine simila…
- Recital 63 — Manufacturers should set up a single point of contact that enables user…
- Recital 64 — Manufacturers should make their products with digital elements availabl…
- Recital 65 — Manufacturers should notify simultaneously via the single reporting pla…
- Recital 66 — Manufacturers should notify actively exploited vulnerabilities to ensur…
- Recital 67 — Manufacturers should also notify any severe incident having an impact o…
- Recital 68 — Actively exploited vulnerabilities concern instances where a manufactur…
- Recital 69 — To ensure that notifications can be disseminated quickly to all relevan…
- Recital 70 — In exceptional circumstances and in particular upon request by the manu…
- Recital 71 — When manufacturers notify an actively exploited vulnerability or a seve…
- Recital 72 — In order to simplify the reporting of information required under this R…
- Recital 73 — When establishing the single reporting platform referred to in this Reg…
- Recital 74 — Manufacturers and other natural and legal persons should be able to not…
- Recital 75 — Member States should aim to address, to the extent possible, the challe…
- Recital 76 — Manufacturers of products with digital elements should put in place coo…
- Recital 77 — In order to facilitate vulnerability analysis, manufacturers should ide…
- Recital 78 — Under the new complex business models linked to online sales, a busines…
- Recital 79 — In order to facilitate assessment of conformity with the requirements l…
- Recital 80 — The timely development of harmonised standards during the transitional …
- Recital 81 — Regulation (EU) 2019/881 establishes a voluntary European cybersecurity…
- Recital 82 — Upon entry into force of Implementing Regulation (EU) 2024/482 which co…
- Recital 83 — The current European standardisation framework, which is based on the N…
- Recital 84 — With a view to establishing, in the most efficient way, common specific…
- Recital 85 — ‘Reasonable period’ has the meaning, in relation to the publication…
- Recital 86 — In order to facilitate the assessment of conformity with the essential …
- Recital 87 — The application of harmonised standards, common specifications or Europ…
- Recital 88 — Manufacturers should draw up an EU declaration of conformity to provide…
- Recital 89 — The CE marking, indicating the conformity of a product, is the visible …
- Recital 90 — In order to allow economic operators to demonstrate conformity with the…
- Recital 91 — Conformity assessment of products with digital elements that are not li…
- Recital 92 — While the creation of tangible products with digital elements usually r…
- Recital 93 — In relation to microenterprises and small enterprises, in order to ensu…
- Recital 94 — In order to promote and protect innovation, it is important that the in…
- Recital 95 — In order to ensure a smooth application of this Regulation, Member Stat…
- Recital 96 — In order to ensure proportionality, conformity assessment bodies, when …
- Recital 97 — The objectives of regulatory sandboxes should be to foster innovation a…
- Recital 98 — In order to carry out third-party conformity assessment for products wi…
- Recital 99 — In order to ensure a consistent level of quality in the performance of …
- Recital 100 — Conformity assessment bodies that have been accredited and notified und…
- Recital 101 — Transparent accreditation as provided for in Regulation (EC) No 765/200…
- Recital 102 — Conformity assessment bodies frequently subcontract parts of their acti…
- Recital 103 — The notification of a conformity assessment body should be sent by the …
- Recital 104 — Since notified bodies may offer their services throughout the Union, it…
- Recital 105 — In the interests of competitiveness, it is crucial that notified bodies…
- Recital 106 — Market surveillance is an essential instrument in ensuring the proper a…
- Recital 107 — In accordance with Regulation (EU) 2019/1020, a market surveillance aut…
- Recital 108 — A dedicated ADCO for the cyber resilience of products with digital elem…
- Recital 109 — Market surveillance authorities, through ADCO established under this Re…
- Recital 110 — In order to ensure timely, proportionate and effective measures in rela…
- Recital 111 — In certain cases, a product with digital elements which complies with t…
- Recital 112 — For products with digital elements presenting a significant cybersecuri…
- Recital 113 — Where there are indications of non-compliance with this Regulation in s…
- Recital 114 — Simultaneous coordinated control actions (sweeps) are specific enforcem…
- Recital 115 — In light of its expertise and mandate, ENISA should be able to support …
- Recital 116 — This Regulation confers certain tasks upon ENISA which require appropri…
- Recital 117 — In order to ensure that the regulatory framework can be adapted where n…
- Recital 118 — In order to ensure uniform conditions for the implementation of this Re…
- Recital 119 — In order to ensure trusting and constructive cooperation of market surv…
- Recital 120 — In order to ensure effective enforcement of the obligations laid down i…
- Recital 121 — Where administrative fines are imposed on a person that is not an under…
- Recital 122 — Member States should examine, taking into account national circumstance…
- Recital 123 — In its relationships with third countries, the Union endeavours to prom…
- Recital 124 — Consumers should be entitled to enforce their rights in relation to the…
- Recital 125 — The Commission should periodically evaluate and review this Regulation,…
- Recital 126 — Economic operators should be provided with sufficient time to adapt to …
- Recital 127 — It is important to provide support to microenterprises and small and me…
- Recital 128 — Furthermore, Member States should consider taking complementary action …
- Recital 129 — Since the objective of this Regulation cannot be sufficiently achieved …
- Recital 130 — The European Data Protection Supervisor was consulted in accordance wit…