Cyber Resilience Act
Sectors
Articles (71)
Article 1 — Subject matterArticle 2 — ScopeArticle 3 — DefinitionsArticle 4 — Free movementArticle 5 — Procurement or use of products with digital elementsArticle 6 — Requirements for products with digital elementsArticle 7 — Important products with digital elementsArticle 8 — Critical products with digital elementsArticle 9 — Stakeholder consultationArticle 10 — Enhancing skills in a cyber resilient digital environmentArticle 11 — General product safetyArticle 12 — High-risk AI systemsArticle 13 — Obligations of manufacturersArticle 14 — Reporting obligations of manufacturersArticle 15 — Voluntary reportingArticle 16 — Establishment of a single reporting platformArticle 17 — Other provisions related to reportingArticle 18 — Authorised representativesArticle 19 — Obligations of importersArticle 20 — Obligations of distributorsArticle 21 — Cases in which obligations of manufacturers apply to importers and distributorsArticle 22 — Other cases in which obligations of manufacturers applyArticle 23 — Identification of economic operatorsArticle 24 — Obligations of open-source software stewardsArticle 25 — Security attestation of free and open-source softwareArticle 26 — GuidanceArticle 27 — Presumption of conformityArticle 28 — EU declaration of conformityArticle 29 — General principles of the CE markingArticle 30 — Rules and conditions for affixing the CE markingArticle 31 — Technical documentationArticle 32 — Conformity assessment procedures for products with digital elementsArticle 33 — Support measures for microenterprises and small and medium-sized enterprises, including start-upsArticle 34 — Mutual recognition agreementsArticle 35 — NotificationArticle 36 — Notifying authoritiesArticle 37 — Requirements relating to notifying authoritiesArticle 38 — Information obligation on notifying authoritiesArticle 39 — Requirements relating to notified bodiesArticle 40 — Presumption of conformity of notified bodiesArticle 41 — Subsidiaries of and subcontracting by notified bodiesArticle 42 — Application for notificationArticle 43 — Notification procedureArticle 44 — Identification numbers and lists of notified bodiesArticle 45 — Changes to notificationsArticle 46 — Challenge of the competence of notified bodiesArticle 47 — Operational obligations of notified bodiesArticle 48 — Appeal against decisions of notified bodiesArticle 49 — Information obligation on notified bodiesArticle 50 — Exchange of experienceArticle 51 — Coordination of notified bodiesArticle 52 — Market surveillance and control of products with digital elements in the Union marketArticle 53 — Access to data and documentationArticle 54 — Procedure at national level concerning products with digital elements presenting a significant cybersecurity riskArticle 55 — Union safeguard procedureArticle 56 — Procedure at Union level concerning products with digital elements presenting a significant cybersecurity riskArticle 57 — Compliant products with digital elements which present a significant cybersecurity riskArticle 58 — Formal non-complianceArticle 59 — Joint activities of market surveillance authoritiesArticle 60 — SweepsArticle 61 — Exercise of the delegationArticle 62 — Committee procedureArticle 63 — ConfidentialityArticle 64 — PenaltiesArticle 65 — Representative actionsArticle 66 — Amendment to Regulation (EU) 2019/1020Article 67 — Amendment to Directive (EU) 2020/1828Article 68 — Amendment to Regulation (EU) No 168/2013Article 69 — Transitional provisionsArticle 70 — Evaluation and reviewArticle 71 — Entry into force and application