Source: OJ L 2024/2847, 20.11.2024

Current language: DE

Artikel 53 Zugang zu Daten und zur Dokumentation


Summary What does Article 53 of the CRA regulation say?

This is a notably brief but practically significant article within the market surveillance framework of the regulation.

It establishes the access rights of market surveillance authorities when they need to assess whether a product with digital elements and its manufacturer's processes actually meet the essential cybersecurity requirements set out in Annex I.

Rather than defining enforcement powers or penalties, this article focuses specifically on the informational access that underpins any meaningful compliance evaluation, granting authorities the ability to look inside the economic operator's operations.

Important points:

  • Market surveillance authorities are granted access, upon a reasoned request, to all data necessary to assess the design, development, production, and vulnerability handling of a product with digital elements.
  • This access right extends to internal documentation held by any relevant economic operator, not just the manufacturer.
  • The data must be provided in a language easily understood by the market surveillance authority making the request.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

Soweit dies für die Bewertung der Konformität von Produkten mit digitalen Elementen und der von deren Herstellern festgelegten Verfahren mit den grundlegenden Cybersicherheitsanforderungen in Anhang I erforderlich ist, erhalten die Marktüberwachungsbehörden auf begründeten Antrag in einer für sie leicht verständlichen Sprache Zugang zu den Daten, die für die Bewertung der Konzeption, Entwicklung, Herstellung und die Behandlung von Schwachstellen solcher Produkte erforderlich sind, einschließlich der betreffenden internen Unterlagen des betroffenen Wirtschaftsakteurs.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod