Source: OJ L 2024/2847, 20.11.2024

Current language: FR

Article premier Objet


Summary What does Article 1 of the Cyber Resilience Act say?

This is the foundational scope article of the regulation.

It establishes the four pillars of what the regulation covers: market access rules for products with digital elements, cybersecurity requirements tied to how those products are designed and built, requirements for how manufacturers handle vulnerabilities throughout a product's lifetime, and the framework for market surveillance and enforcement.

It sets the stage for everything that follows in the regulation.

Important points:

  • Comply with essential cybersecurity requirements covering both how products with digital elements are designed and produced, and how vulnerabilities in those products are managed over time.
  • Economic operators — including manufacturers, importers, and distributors — bear obligations under all three substantive pillars of the regulation.
  • Market surveillance and enforcement rules are included within the regulation's scope, not left to separate instruments.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

Le présent règlement établit:

  1. les règles relatives à la mise à disposition sur le marché de produits comportant des éléments numériques afin de garantir la cybersécurité de ces produits;

  2. les exigences essentielles de cybersécurité relatives à la conception, au développement et à la production de produits comportant des éléments numériques, et les obligations qui incombent aux opérateurs économiques en ce qui concerne ces produits eu égard à la cybersécurité;

  3. les exigences essentielles de cybersécurité relatives aux processus de gestion des vulnérabilités mis en place par les fabricants pour garantir la cybersécurité des produits comportant des éléments numériques durant la période d’utilisation prévue du produit, et les obligations incombant aux opérateurs économiques en ce qui concerne ces processus;

  4. les règles relatives à la surveillance, y compris le contrôle, du marché et au contrôle de l’application des règles et exigences visées au présent article.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod