Source: OJ L, 2025/2392, 1.12.2025

Current language: EN

Technical description of product categories

COMMISSION IMPLEMENTING REGULATION (EU) 2025/2392

of 28 November 2025

on the technical description of the categories of important and critical products with digital elements pursuant to Regulation (EU) 2024/2847 of the European Parliament and of the Council

(Text with EEA relevance)

THE EUROPEAN COMMISSION,

Having regard to the Treaty on the Functioning of the European Union,

Having regard to Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act)(1)OJ L, 2024/2847, 20.11.2024, ELI: http://data.europa.eu/eli/reg/2024/2847/oj., and in particular Article 7(4) thereof,

Whereas:

Open full page
Recital 1

Regulation (EU) 2024/2847 lays down rules on the cybersecuritymeans cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; of products with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately;. In particular, Annex III to that Regulation sets out categories of important products with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; that, when placed on the market, are subject to conformity assessmentmeans the process of verifying whether the essential cybersecurity requirements set out in Annex I have been fulfilled; procedures that are stricter than those applicable to other products with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately;. Annex IV to Regulation (EU) 2024/2847 sets out categories of critical products with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; for which manufacturersmeans a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge; could be required to obtain a European cybersecuritymeans cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; certificate under a European cybersecuritymeans cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; certification scheme pursuant to Regulation (EU) 2019/881 of the European Parliament and of the Council(2)Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act) (OJ L 151, 7.6.2019, p. 15, ELI: http://data.europa.eu/eli/reg/2019/881/oj). or which would be subject to mandatory third-party conformity assessmentmeans the process of verifying whether the essential cybersecurity requirements set out in Annex I have been fulfilled;, when placed on the market.

Recital 2

Pursuant to Article 7(1) and Article 8(1) of Regulation (EU) 2024/2847, the core functionality of a product with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; determines whether that product with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; meets the technical description of a category of important or critical products with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; and therefore the applicable conformity assessmentmeans the process of verifying whether the essential cybersecurity requirements set out in Annex I have been fulfilled; procedures.

Recital 3

When developing a product with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately;, and in order to achieve their desired set of functionalities, manufacturersmeans a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge; typically integrate into their own products with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; other componentsmeans software or hardware intended for integration into an electronic information system; which are also products with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; and that can meet the technical description of a category of important or critical products. Pursuant to Regulation (EU) 2024/2847, a product with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; is subject to the conformity assessmentmeans the process of verifying whether the essential cybersecurity requirements set out in Annex I have been fulfilled; procedures applicable to important or critical products with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately;, if that product as a whole is an important or critical product as set out in Annexes III and IV to that Regulation. For example, integrating an embedded browser as a componentmeans software or hardware intended for integration into an electronic information system; of a news app for use in smartphones does not in itself render the news app subject to the conformity assessmentmeans the process of verifying whether the essential cybersecurity requirements set out in Annex I have been fulfilled; procedure applicable to products with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; that have the core functionality of ‘standalone and embedded browsers’. Nonetheless, in accordance with Regulation (EU) 2024/2847, the manufacturermeans a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge; needs to ensure that the product with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; as a whole meets the essential cybersecuritymeans cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; requirements. Therefore, the manufacturermeans a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge; needs to evaluate the security of the whole product, considering, as appropriate, the security of the componentsmeans software or hardware intended for integration into an electronic information system; or functionalities that are integrated into it. For example, in order for the manufacturermeans a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge; of a news app to demonstrate that its product with digital elementsmeans a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately; is in conformity with Regulation (EU) 2024/2847, that manufacturermeans a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge; is to demonstrate that the news app as a whole satisfies the applicable requirements, considering, as appropriate, the security of the embedded browser that is integrated into its app.

HAS ADOPTED THIS REGULATION:

  1. Article 1Definitions
  2. Article 2
  3. Article 3
Annexes(1 – 2)
  1. Annex IIMPORTANT PRODUCTS WITH DIGITAL ELEMENTS
  2. Annex IICRITICAL PRODUCTS WITH DIGITAL ELEMENTS

This Regulation shall be binding in its entirety and directly applicable in all Member States.

Done at Brussels, 28 November 2025.

For the Commission

The President

Ursula VON DER LEYEN

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod