Need help?

Cybersecurity Resilience Act Regulation

wave

  Directive

Cybersecurity Resilience Act Regulation ((EU) 2024/2847)

  Scope

1. This Regulation applies to products with digital elements made available on the market, the intended purpose or reasonably foreseeable use of which includes a direct or indirect logical or physical data connection to a device or network.

2. This Regulation does not apply to products with digital elements to which the following Union legal acts apply:

 

(a) Regulation (EU) 2017/745;

(b) Regulation (EU) 2017/746;

(c) Regulation (EU) 2019/2144.

 

3. This Regulation does not apply to products with digital elements that have been certified in accordance with Regulation (EU) 2018/1139.

4. This Regulation does not apply to equipment that falls within the scope of Directive 2014/90/EU of the European Parliament and of the Council (36).

5. The application of this Regulation to products with digital elements covered by other Union rules laying down requirements that address all or some of the risks covered by the essential cybersecurity requirements set out in Annex I may be limited or excluded where:

 

(a) such limitation or exclusion is consistent with the overall regulatory framework that applies to those products; and

(b) the sectoral rules achieve the same or a higher level of protection as that provided for by this Regulation.

 

The Commission is empowered to adopt delegated acts in accordance with Article 61 to supplement this Regulation by specifying whether such limitation or exclusion is necessary, the products and rules concerned, as well as the scope of the limitation, if relevant.

6. This Regulation does not apply to spare parts that are made available on the market to replace identical components in products with digital elements and that are manufactured according to the same specifications as the components that they are intended to replace.

7. This Regulation does not apply to products with digital elements developed or modified exclusively for national security or defence purposes or to products specifically designed to process classified information.

8. The obligations laid down in this Regulation shall not entail the supply of information the disclosure of which would be contrary to the essential interests of Member States’ national security, public security or defence.

  Description

The Cyber Resilience Act enhances cybersecurity standards of products that contain a digital component, requiring manufacturers and retailers to ensure cybersecurity throughout the lifecycle of their products.

  Download

  Stay up to date

CELAB is Notified Body No.2037 for the EMC Directive and Italian office of a Notified Body for the RED Directive.

CELAB performs voluntary inspection activities on technical construction files to check their contents.

CELAB can accomplish all the required tests in order to affix the CE-marking related to EMC, LVD, RED, MDD, machines and many others.

CLICK HERE TO GET TESTS AND INFO ON THIS DIRECTIVE

  ACCESS

Search for a standard
GO

Register

Already a member?
Login

  OTHER APPLICATIONS

If you are interested in DO160 tests, you can give a try to our other free of charge software:
CE-Marking assistant, Version: 1.3.0