Source: OJ L 2024/2847, 20.11.2024

Current language: FR

Article 6 Exigences applicables aux produits comportant des éléments numériques


Summary What does Article 6 of the CRA regulation say?

This is a short but foundational article that sets the overarching market access condition for products with digital elements.

It establishes a dual gate: both the product itself and the manufacturer's internal processes must meet the essential cybersecurity requirements set out in Annex I before a product can be placed on the market.

It effectively acts as the core compliance threshold that the more detailed obligations found in later articles (such as Articles 13 and 14) are built around and designed to satisfy.

Important points:

  • Products with digital elements must meet the essential cybersecurity requirements of Annex I Part I, assuming proper installation, maintenance, intended use, and where applicable, installation of security updates.
  • Manufacturers are required to ensure their internal processes also comply with the essential cybersecurity requirements, specifically those set out in Part II of Annex I.
  • Both conditions must be satisfied simultaneously — product compliance alone is not sufficient for market access.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

Les produits comportant des éléments numériques ne sont mis à disposition sur le marché que:

  1. s’ils satisfont aux exigences essentielles de cybersécurité énoncées à l’annexe I, partie I, à condition qu’ils soient correctement installés, entretenus et utilisés conformément à l’utilisation prévue ou dans des conditions raisonnablement prévisibles et, le cas échéant, que les mises à jour de sécurité nécessaires aient été installées; et

  2. si les processus mis en place par le fabricant sont conformes aux exigences essentielles de cybersécurité énoncées à l’annexe I, partie II.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod