Source: OJ L 2024/2847, 20.11.2024

Current language: DE

Artikel 6 Anforderungen an Produkte mit digitalen Elementen


Summary What does Article 6 of the CRA regulation say?

This is a short but foundational article that sets the overarching market access condition for products with digital elements.

It establishes a dual gate: both the product itself and the manufacturer's internal processes must meet the essential cybersecurity requirements set out in Annex I before a product can be placed on the market.

It effectively acts as the core compliance threshold that the more detailed obligations found in later articles (such as Articles 13 and 14) are built around and designed to satisfy.

Important points:

  • Products with digital elements must meet the essential cybersecurity requirements of Annex I Part I, assuming proper installation, maintenance, intended use, and where applicable, installation of security updates.
  • Manufacturers are required to ensure their internal processes also comply with the essential cybersecurity requirements, specifically those set out in Part II of Annex I.
  • Both conditions must be satisfied simultaneously — product compliance alone is not sufficient for market access.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

Produkte mit digitalen Elementen werden nur dann auf dem Markt bereitgestellt, wenn

  1. sie den grundlegenden Cybersicherheitsanforderungen in Anhang I Teil I genügen und unter der Bedingung, dass sie ordnungsgemäß installiert, gewartet und bestimmungsgemäß oder unter vernünftigerweise vorhersehbaren Umständen verwendet werden sowie gegebenenfalls die erforderlichen Sicherheitsaktualisierungen installiert wurden; und

  2. die vom Hersteller festgelegten Verfahren den grundlegenden Cybersicherheitsanforderungen in Anhang I Teil II entsprechen.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod