Cyber Resilience Act: all tools and articles
Regulation (EU) 2024/2847 · Articles 13, 14, 19 to 24, 69, 71 and Annex I
The CRA obligations checklist: 85 rows by role, a status for each, one document
Pick the role you play under Article 3 and the page lists every row of the Regulation that binds it, in the Official Journal's words: what the product must meet, what the manufacturer must do and report, and what an importer, distributor or steward owes instead. The reporting duties apply from 11 September 2026, the rest from 11 December 2027. Set a status and an evidence line per row, and the page writes the checklist as a document. Nothing you type leaves this page.
67 rows bind this role. Each is the Official Journal's text; the ISO references are StandardOS's reading of where an ISO/IEC 27001 management system runs the process behind the row, never the product's evidence and never a presumption of conformity.
Article 13: obligations of manufacturers
13(1) · obligation
When placing a product with digital elements on the market, manufacturers shall ensure that it has been designed, developed and produced in accordance with the essential cybersecurity requirements set out in Part I of Annex I.
ISO 27001: A.8.25, A.8.27
13(2) · obligation
For the purpose of complying with paragraph 1, manufacturers shall undertake an assessment of the cybersecurity risks associated with a product with digital elements and take the outcome of that assessment into account during the planning, design, development, production, delivery and maintenance phases of the product with digital elements with a view to minimising cybersecurity risks, preventing incidents and minimising their impact, including in relation to the health and safety of users.
ISO 27001: Clause 6.1.2, A.8.26
13(3) · duty
The cybersecurity risk assessment shall be documented and updated as appropriate during a support period to be determined in accordance with paragraph 8 of this Article. That cybersecurity risk assessment shall comprise at least an analysis of cybersecurity risks based on the intended purpose and reasonably foreseeable use, as well as the conditions of use, of the product with digital elements, such as the operational environment or the assets to be protected, taking into account the length of time the product is expected to be in use. The cybersecurity risk assessment shall indicate whether and, if so in what manner, the security requirements set out in Part I, point (2), of Annex I are applicable to the relevant product with digital elements and how those requirements are implemented as informed by the cybersecurity risk assessment. It shall also indicate how the manufacturer is to apply Part I, point (1), of Annex I and the vulnerability handling requirements set out in Part II of Annex I.
ISO 27001: Clause 6.1.2, Clause 7.5, A.8.26
13(4) · duty
When placing a product with digital elements on the market, the manufacturer shall include the cybersecurity risk assessment referred to in paragraph 3 of this Article in the technical documentation required pursuant to Article 31 and Annex VII. For products with digital elements as referred to in Article 12, which are also subject to other Union legal acts, the cybersecurity risk assessment may be part of the risk assessment required by those Union legal acts. Where certain essential cybersecurity requirements are not applicable to the product with digital elements, the manufacturer shall include a clear justification to that effect in that technical documentation.
ISO 27001: Clause 7.5
13(5) · obligation
For the purpose of complying with paragraph 1, manufacturers shall exercise due diligence when integrating components sourced from third parties so that those components do not compromise the cybersecurity of the product with digital elements, including when integrating components of free and open-source software that have not been made available on the market in the course of a commercial activity.
ISO 27001: A.5.19, A.5.21, A.8.28
13(6) · duty
Manufacturers shall, upon identifying a vulnerability in a component, including in an open source-component, which is integrated in the product with digital elements report the vulnerability to the person or entity manufacturing or maintaining the component, and address and remediate the vulnerability in accordance with the vulnerability handling requirements set out in Part II of Annex I. Where manufacturers have developed a software or hardware modification to address the vulnerability in that component, they shall share the relevant code or documentation with the person or entity manufacturing or maintaining the component, where appropriate in a machine-readable format.
ISO 27001: A.5.21, A.8.8
13(7) · obligation
The manufacturers shall systematically document, in a manner that is proportionate to the nature and the cybersecurity risks, relevant cybersecurity aspects concerning the products with digital elements, including vulnerabilities of which they become aware and any relevant information provided by third parties, and shall, where applicable, update the cybersecurity risk assessment of the products.
ISO 27001: Clause 7.5, A.8.8
13(8)-1 · obligation
Manufacturers shall ensure, when placing a product with digital elements on the market, and for the support period, that vulnerabilities of that product, including its components, are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I.
ISO 27001: A.8.8
13(8)-2 · duty
Manufacturers shall determine the support period so that it reflects the length of time during which the product is expected to be in use, taking into account, in particular, reasonable user expectations, the nature of the product, including its intended purpose, as well as relevant Union law determining the lifetime of products with digital elements. When determining the support period, manufacturers may also take into account the support periods of products with digital elements offering a similar functionality placed on the market by other manufacturers, the availability of the operating environment, the support periods of integrated components that provide core functions and are sourced from third parties as well as relevant guidance provided by the dedicated administrative cooperation group (ADCO) established pursuant to Article 52(15) and the Commission. The matters to be taken into account in order to determine the support period shall be considered in a manner that ensures proportionality. Without prejudice to the second subparagraph, the support period shall be at least five years. Where the product with digital elements is expected to be in use for less than five years, the support period shall correspond to the expected use time.
ISO 27001: nothing in Annex A produces this
13(8)-5 · duty
Manufacturers shall include the information that was taken into account to determine the support period of a product with digital elements in the technical documentation as set out in Annex VII.
ISO 27001: Clause 7.5
13(8)-6 · obligation
Manufacturers shall have appropriate policies and procedures, including coordinated vulnerability disclosure policies, referred to in Part II, point (5), of Annex I to process and remediate potential vulnerabilities in the product with digital elements reported from internal or external sources.
ISO 27001: A.5.1, A.8.8
13(9) · obligation
Manufacturers shall ensure that each security update, as referred to in Part II, point (8), of Annex I, which has been made available to users during the support period, remains available after it has been issued for a minimum of 10 years or for the remainder of the support period, whichever is longer.
ISO 27001: A.8.8
13(12) · duty
Before placing a product with digital elements on the market, manufacturers shall draw up the technical documentation referred to in Article 31. They shall carry out the chosen conformity assessment procedures as referred to in Article 32 or have them carried out. Where compliance of the product with digital elements with the essential cybersecurity requirements set out in Part I of Annex I and of the processes put in place by the manufacturer with the essential cybersecurity requirements set out in Part II of Annex I has been demonstrated by that conformity assessment procedure, manufacturers shall draw up the EU declaration of conformity in accordance with Article 28 and affix the CE marking in accordance with Article 30.
ISO 27001: Clause 7.5
13(13) · duty
Manufacturers shall keep the technical documentation and the EU declaration of conformity at the disposal of the market surveillance authorities for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer.
ISO 27001: Clause 7.5, A.5.33
13(14) · obligation
Manufacturers shall ensure that procedures are in place for products with digital elements that are part of a series of production to remain in conformity with this Regulation. Manufacturers shall adequately take into account changes in the development and production process or in the design or characteristics of the product with digital elements and changes in the harmonised standards, European cybersecurity certification schemes or common specifications as referred to in Article 27 by reference to which the conformity of the product with digital elements is declared or by application of which its conformity is verified.
ISO 27001: A.8.32
13(15) · duty
Manufacturers shall ensure that their products with digital elements bear a type, batch or serial number or other element allowing their identification, or, where that is not possible, that that information is provided on their packaging or in a document accompanying the product with digital elements.
ISO 27001: nothing in Annex A produces this
13(16) · duty
Manufacturers shall indicate the name, registered trade name or registered trademark of the manufacturer, and the postal address, email address or other digital contact details, as well as, where applicable, the website where the manufacturer can be contacted, on the product with digital elements, on its packaging or in a document accompanying the product with digital elements. That information shall also be included in the information and instructions to the user set out in Annex II. The contact details shall be in a language which can be easily understood by users and market surveillance authorities.
ISO 27001: nothing in Annex A produces this
13(17) · duty
For the purposes of this Regulation, manufacturers shall designate a single point of contact to enable users to communicate directly and rapidly with them, including in order to facilitate reporting on vulnerabilities of the product with digital elements. Manufacturers shall ensure that the single point of contact is easily identifiable by the users. They shall also include the single point of contact in the information and instructions to the user set out in Annex II. The single point of contact shall allow users to choose their preferred means of communication and shall not limit such means to automated tools.
ISO 27001: A.8.8
13(18) · duty
Manufacturers shall ensure that products with digital elements are accompanied by the information and instructions to the user set out in Annex II, in paper or electronic form. Such information and instructions shall be provided in a language which can be easily understood by users and market surveillance authorities. They shall be clear, understandable, intelligible and legible. They shall allow for the secure installation, operation and use of products with digital elements. Manufacturers shall keep the information and instructions to the user set out in Annex II at the disposal of users and market surveillance authorities for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer. Where such information and instructions are provided online, manufacturers shall ensure that they are accessible, user-friendly and available online for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer.
ISO 27001: nothing in Annex A produces this
13(19) · duty
Manufacturers shall ensure that the end date of the support period referred to in paragraph 8, including at least the month and the year, is clearly and understandably specified at the time of purchase in an easily accessible manner and, where applicable, on the product with digital elements, its packaging or by digital means. Where technically feasible in light of the nature of the product with digital elements, manufacturers shall display a notification to users informing them that their product with digital elements has reached the end of its support period.
ISO 27001: nothing in Annex A produces this
13(20) · duty
Manufacturers shall either provide a copy of the EU declaration of conformity or a simplified EU declaration of conformity with the product with digital elements. Where a simplified EU declaration of conformity is provided, it shall contain the exact internet address at which the full EU declaration of conformity can be accessed.
ISO 27001: nothing in Annex A produces this
13(21) · duty
From the placing on the market and for the support period, manufacturers who know or have reason to believe that the product with digital elements or the processes put in place by the manufacturer are not in conformity with the essential cybersecurity requirements set out in Annex I shall immediately take the corrective measures necessary to bring that product with digital elements or the manufacturer’s processes into conformity, or to withdraw or recall the product, as appropriate.
ISO 27001: Clause 10.2
13(22) · duty
Manufacturers shall, upon a reasoned request from a market surveillance authority, provide that authority, in a language which can be easily understood by that authority, with all the information and documentation, in paper or electronic form, necessary to demonstrate the conformity of the product with digital elements and of the processes put in place by the manufacturer with the essential cybersecurity requirements set out in Annex I. Manufacturers shall cooperate with that authority, at its request, on any measures taken to eliminate the cybersecurity risks posed by the product with digital elements which they have placed on the market.
ISO 27001: Clause 7.5, A.5.5
13(23) · duty
A manufacturer that ceases its operations and, as a result, is not able to comply with this Regulation shall inform, before the cessation of operations takes effect, the relevant market surveillance authorities as well as, by any means available and to the extent possible, the users of the relevant products with digital elements placed on the market, of the impending cessation of operations.
ISO 27001: A.5.5
Annex I: the essential cybersecurity requirements
I.1 · essential requirement
Products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks.
ISO 27001: Clause 6.1.2, A.5.8, A.8.25
I.2 · reading
On the basis of the cybersecurity risk assessment referred to in Article 13(2) and where applicable, products with digital elements shall:
ISO 27001: nothing in Annex A produces this
I.2.a · essential requirement
be made available on the market without known exploitable vulnerabilities
ISO 27001: A.8.8, A.8.29
I.2.b · essential requirement
be made available on the market with a secure by default configuration, unless otherwise agreed between manufacturer and business user in relation to a tailor-made product with digital elements, including the possibility to reset the product to its original state
ISO 27001: A.8.9, A.8.26
I.2.c · essential requirement
ensure that vulnerabilities can be addressed through security updates, including, where applicable, through automatic security updates that are installed within an appropriate timeframe enabled as a default setting, with a clear and easy-to-use opt-out mechanism, through the notification of available updates to users, and the option to temporarily postpone them
ISO 27001: A.8.8, A.8.32
I.2.d · essential requirement
ensure protection from unauthorised access by appropriate control mechanisms, including but not limited to authentication, identity or access management systems, and report on possible unauthorised access
ISO 27001: A.8.26, A.8.5, A.5.15, A.5.16, A.5.17
I.2.e · essential requirement
protect the confidentiality of stored, transmitted or otherwise processed data, personal or other, such as by encrypting relevant data at rest or in transit by state of the art mechanisms, and by using other technical means
ISO 27001: A.8.26, A.8.24
I.2.f · essential requirement
protect the integrity of stored, transmitted or otherwise processed data, personal or other, commands, programs and configuration against any manipulation or modification not authorised by the user, and report on corruptions
ISO 27001: A.8.26, A.8.24, A.8.9
I.2.g · essential requirement
process only data, personal or other, that are adequate, relevant and limited to what is necessary in relation to the intended purpose of the product with digital elements (data minimisation)
ISO 27001: A.8.26, A.5.34
I.2.h · essential requirement
protect the availability of essential and basic functions, also after an incident, including through resilience and mitigation measures against denial-of-service attacks
ISO 27001: A.8.26, A.8.6, A.8.14
I.2.i · essential requirement
minimise the negative impact by the products themselves or connected devices on the availability of services provided by other devices or networks
ISO 27001: A.8.27, A.8.20
I.2.j · essential requirement
be designed, developed and produced to limit attack surfaces, including external interfaces
ISO 27001: A.8.27, A.8.9
I.2.k · essential requirement
be designed, developed and produced to reduce the impact of an incident using appropriate exploitation mitigation mechanisms and techniques
ISO 27001: A.8.27, A.8.28
I.2.l · essential requirement
provide security related information by recording and monitoring relevant internal activity, including the access to or modification of data, services or functions, with an opt-out mechanism for the user
ISO 27001: A.8.26, A.8.15, A.8.16
I.2.m · essential requirement
provide the possibility for users to securely and easily remove on a permanent basis all data and settings and, where such data can be transferred to other products or systems, ensure that this is done in a secure manner.
ISO 27001: A.8.26, A.8.10
II.1 · essential requirement
identify and document vulnerabilities and components contained in products with digital elements, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products
ISO 27001: A.8.8, A.5.9
II.2 · essential requirement
in relation to the risks posed to products with digital elements, address and remediate vulnerabilities without delay, including by providing security updates; where technically feasible, new security updates shall be provided separately from functionality updates
ISO 27001: A.8.8, A.8.32
II.3 · essential requirement
apply effective and regular tests and reviews of the security of the product with digital elements
ISO 27001: A.8.29, A.8.8, A.5.35
II.4 · essential requirement
once a security update has been made available, share and publicly disclose information about fixed vulnerabilities, including a description of the vulnerabilities, information allowing users to identify the product with digital elements affected, the impacts of the vulnerabilities, their severity and clear and accessible information helping users to remediate the vulnerabilities; in duly justified cases, where manufacturers consider the security risks of publication to outweigh the security benefits, they may delay making public information regarding a fixed vulnerability until after users have been given the possibility to apply the relevant patch
ISO 27001: nothing in Annex A produces this
II.5 · essential requirement
put in place and enforce a policy on coordinated vulnerability disclosure
ISO 27001: nothing in Annex A produces this
II.6 · essential requirement
take measures to facilitate the sharing of information about potential vulnerabilities in their product with digital elements as well as in third-party components contained in that product, including by providing a contact address for the reporting of the vulnerabilities discovered in the product with digital elements
ISO 27001: nothing in Annex A produces this
II.7 · essential requirement
provide for mechanisms to securely distribute updates for products with digital elements to ensure that vulnerabilities are fixed or mitigated in a timely manner and, where applicable for security updates, in an automatic manner
ISO 27001: A.8.24, A.8.32
II.8 · essential requirement
ensure that, where security updates are available to address identified security issues, they are disseminated without delay and, unless otherwise agreed between a manufacturer and a business user in relation to a tailor-made product with digital elements, free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken.
ISO 27001: nothing in Annex A produces this
Article 14: reporting obligations
14(1) · duty
A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA. The manufacturer shall notify that actively exploited vulnerability via the single reporting platform established pursuant to Article 16.
ISO 27001: A.5.5, A.5.24
14(2)(a) · deadline
an early warning notification of an actively exploited vulnerability, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, indicating, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available
ISO 27001: A.5.24, A.5.26 · Clock: within 24 hours of becoming aware
14(2)(b) · deadline
unless the relevant information has already been provided, a vulnerability notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the actively exploited vulnerability, which shall provide general information, as available, about the product with digital elements concerned, the general nature of the exploit and of the vulnerability concerned as well as any corrective or mitigating measures taken, and corrective or mitigating measures that users can take, and which shall also indicate, where applicable, how sensitive the manufacturer considers the notified information to be
ISO 27001: A.5.24, A.5.26 · Clock: within 72 hours of becoming aware
14(2)(c) · deadline
unless the relevant information has already been provided, a final report, no later than 14 days after a corrective or mitigating measure is available, including at least the following: (i) a description of the vulnerability, including its severity and impact; (ii) where available, information concerning any malicious actor that has exploited or that is exploiting the vulnerability; (iii) details about the security update or other corrective measures that have been made available to remedy the vulnerability.
ISO 27001: A.5.24, A.5.27, A.8.8 · Clock: within 14 days after a corrective or mitigating measure is available
14(3) · duty
A manufacturer shall notify any severe incident having an impact on the security of the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA. The manufacturer shall notify that incident via the single reporting platform established pursuant to Article 16.
ISO 27001: A.5.5, A.5.24
14(4)(a) · deadline
an early warning notification of a severe incident having an impact on the security of the product with digital elements, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, including at least whether the incident is suspected of being caused by unlawful or malicious acts, which shall also indicate, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available
ISO 27001: A.5.24, A.5.26 · Clock: within 24 hours of becoming aware
14(4)(b) · deadline
unless the relevant information has already been provided, an incident notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the incident, which shall provide general information, where available, about the nature of the incident, an initial assessment of the incident, as well as any corrective or mitigating measures taken, and corrective or mitigating measures that users can take, and which shall also indicate, where applicable, how sensitive the manufacturer considers the notified information to be
ISO 27001: A.5.24, A.5.26 · Clock: within 72 hours of becoming aware
14(4)(c) · deadline
unless the relevant information has already been provided, a final report, within one month after the submission of the incident notification under point (b), including at least the following: (i) a detailed description of the incident, including its severity and impact; (ii) the type of threat or root cause that is likely to have triggered the incident; (iii) applied and ongoing mitigation measures.
ISO 27001: A.5.24, A.5.27 · Clock: within 1 month after the notification is submitted
14(5) · reading
For the purposes of paragraph 3, an incident having an impact on the security of the product with digital elements shall be considered to be severe where: (a) it negatively affects or is capable of negatively affecting the ability of a product with digital elements to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions; or (b) it has led or is capable of leading to the introduction or execution of malicious code in a product with digital elements or in the network and information systems of a user of the product with digital elements.
ISO 27001: A.5.25
14(6) · duty
Where necessary, the CSIRT designated as coordinator initially receiving the notification may request manufacturers to provide an intermediate report on relevant status updates about the actively exploited vulnerability or severe incident having an impact on the security of the product with digital elements.
ISO 27001: A.5.24
14(7) · duty
The notifications referred to in paragraphs 1 and 3 of this Article shall be submitted via the single reporting platform referred to in Article 16 using one of the electronic notification end-points referred to in Article 16(1). The notification shall be submitted using the electronic notification end-point of the CSIRT designated as coordinator of the Member State where the manufacturers have their main establishment in the Union and shall be simultaneously accessible to ENISA. For the purposes of this Regulation, a manufacturer shall be considered to have its main establishment in the Union in the Member State where the decisions related to the cybersecurity of its products with digital elements are predominantly taken. If such a Member State cannot be determined, the main establishment shall be considered to be in the Member State where the manufacturer concerned has the establishment with the highest number of employees in the Union. Where a manufacturer has no main establishment in the Union, it shall submit the notifications referred to in paragraphs 1 and 3 using the electronic notification end-point of the CSIRT designated as coordinator in the Member State determined pursuant to the following order and based on the information available to the manufacturer: (a) the Member State in which the authorised representative acting on behalf of the manufacturer for the highest number of products with digital elements of that manufacturer is established; (b) the Member State in which the importer placing on the market the highest number of products with digital elements of that manufacturer is established; (c) the Member State in which the distributor making available on the market the highest number of products with digital elements of that manufacturer is established; (d) the Member State in which the highest number of users of products with digital elements of that manufacturer are located. In relation to the third subparagraph, point (d), a manufacturer may submit notifications related to any subsequent actively exploited vulnerability or severe incident having an impact on the security of the product with digital elements to the same CSIRT designated as coordinator to which it first reported.
ISO 27001: A.5.5
14(8) · duty
After becoming aware of an actively exploited vulnerability or a severe incident having an impact on the security of the product with digital elements, the manufacturer shall inform the impacted users of the product with digital elements, and where appropriate all users, of that vulnerability or incident and, where necessary, of any risk mitigation and corrective measures that the users can deploy to mitigate the impact of that vulnerability or incident, where appropriate in a structured, machine-readable format that is easily automatically processable. Where the manufacturer fails to inform the users of the product with digital elements in a timely manner, the notified CSIRTs designated as coordinators may provide such information to the users when considered to be proportionate and necessary for preventing or mitigating the impact of that vulnerability or incident.
ISO 27001: A.5.24, A.5.26
Roles, traceability, transition and dates: Articles 21 to 23, 69 and 71
22(1) · obligation
A natural or legal person, other than the manufacturer, the importer or the distributor, that carries out a substantial modification of a product with digital elements and makes that product available on the market, shall be considered to be a manufacturer for the purposes of this Regulation.
ISO 27001: nothing in Annex A produces this
22(2) · obligation
The person referred to in paragraph 1 of this Article shall be subject to the obligations set out in Articles 13 and 14 for the part of the product with digital elements that is affected by the substantial modification or, if the substantial modification has an impact on the cybersecurity of the product with digital elements as a whole, for the entire product.
ISO 27001: nothing in Annex A produces this
23(1) · duty
Economic operators shall, on request, provide the market surveillance authorities with the following information: (a) the name and address of any economic operator who has supplied them with a product with digital elements; (b) where available, the name and address of any economic operator to whom they have supplied a product with digital elements.
ISO 27001: A.5.5, A.5.19
23(2) · duty
Economic operators shall be able to present the information referred to in paragraph 1 for 10 years after they have been supplied with the product with digital elements and for 10 years after they have supplied the product with digital elements.
ISO 27001: A.5.33
69(2) · obligation
Products with digital elements that have been placed on the market before 11 December 2027 shall be subject to the requirements set out in this Regulation only if, from that date, those products are subject to a substantial modification.
ISO 27001: nothing in Annex A produces this
69(3) · obligation
By way of derogation from paragraph 2 of this Article, the obligations laid down in Article 14 shall apply to all products with digital elements that fall within the scope of this Regulation that have been placed on the market before 11 December 2027.
ISO 27001: nothing in Annex A produces this
71(2) · deadline
This Regulation shall apply from 11 December 2027.
ISO 27001: nothing in Annex A produces this · Clock: applies from 11 December 2027
71(2)-2 · deadline
However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026.
ISO 27001: nothing in Annex A produces this · Clock: applies from 11 September 2026
0 of 67 rows done, 0 in progress, 67 not started, 0 not applicable.
The checklist
# Cyber Resilience Act obligations, Manufacturer Prepared on against Regulation (EU) 2024/2847 as published in the Official Journal and read on 12 September 2026. Not legal advice. The Regulation applies from 11 December 2027; the reporting obligations of Article 14 apply from 11 September 2026 (Article 71(2)), to every product in scope whenever it was placed on the market (Article 69(3)). 0 of 67 rows done, 0 in progress, 67 not started, 0 not applicable. ## Article 13: obligations of manufacturers ### 13(1) · obligation When placing a product with digital elements on the market, manufacturers shall ensure that it has been designed, developed and produced in accordance with the essential cybersecurity requirements set out in Part I of Annex I. Status: Not started · ISO 27001: A.8.25, A.8.27 Evidence: [to complete] ### 13(2) · obligation For the purpose of complying with paragraph 1, manufacturers shall undertake an assessment of the cybersecurity risks associated with a product with digital elements and take the outcome of that assessment into account during the planning, design, development, production, delivery and maintenance phases of the product with digital elements with a view to minimising cybersecurity risks, preventing incidents and minimising their impact, including in relation to the health and safety of users. Status: Not started · ISO 27001: Clause 6.1.2, A.8.26 Evidence: [to complete] ### 13(3) · duty The cybersecurity risk assessment shall be documented and updated as appropriate during a support period to be determined in accordance with paragraph 8 of this Article. That cybersecurity risk assessment shall comprise at least an analysis of cybersecurity risks based on the intended purpose and reasonably foreseeable use, as well as the conditions of use, of the product with digital elements, such as the operational environment or the assets to be protected, taking into account the length of time the product is expected to be in use. The cybersecurity risk assessment shall indicate whether and, if so in what manner, the security requirements set out in Part I, point (2), of Annex I are applicable to the relevant product with digital elements and how those requirements are implemented as informed by the cybersecurity risk assessment. It shall also indicate how the manufacturer is to apply Part I, point (1), of Annex I and the vulnerability handling requirements set out in Part II of Annex I. Status: Not started · ISO 27001: Clause 6.1.2, Clause 7.5, A.8.26 Evidence: [to complete] ### 13(4) · duty When placing a product with digital elements on the market, the manufacturer shall include the cybersecurity risk assessment referred to in paragraph 3 of this Article in the technical documentation required pursuant to Article 31 and Annex VII. For products with digital elements as referred to in Article 12, which are also subject to other Union legal acts, the cybersecurity risk assessment may be part of the risk assessment required by those Union legal acts. Where certain essential cybersecurity requirements are not applicable to the product with digital elements, the manufacturer shall include a clear justification to that effect in that technical documentation. Status: Not started · ISO 27001: Clause 7.5 Evidence: [to complete] ### 13(5) · obligation For the purpose of complying with paragraph 1, manufacturers shall exercise due diligence when integrating components sourced from third parties so that those components do not compromise the cybersecurity of the product with digital elements, including when integrating components of free and open-source software that have not been made available on the market in the course of a commercial activity. Status: Not started · ISO 27001: A.5.19, A.5.21, A.8.28 Evidence: [to complete] ### 13(6) · duty Manufacturers shall, upon identifying a vulnerability in a component, including in an open source-component, which is integrated in the product with digital elements report the vulnerability to the person or entity manufacturing or maintaining the component, and address and remediate the vulnerability in accordance with the vulnerability handling requirements set out in Part II of Annex I. Where manufacturers have developed a software or hardware modification to address the vulnerability in that component, they shall share the relevant code or documentation with the person or entity manufacturing or maintaining the component, where appropriate in a machine-readable format. Status: Not started · ISO 27001: A.5.21, A.8.8 Evidence: [to complete] ### 13(7) · obligation The manufacturers shall systematically document, in a manner that is proportionate to the nature and the cybersecurity risks, relevant cybersecurity aspects concerning the products with digital elements, including vulnerabilities of which they become aware and any relevant information provided by third parties, and shall, where applicable, update the cybersecurity risk assessment of the products. Status: Not started · ISO 27001: Clause 7.5, A.8.8 Evidence: [to complete] ### 13(8)-1 · obligation Manufacturers shall ensure, when placing a product with digital elements on the market, and for the support period, that vulnerabilities of that product, including its components, are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I. Status: Not started · ISO 27001: A.8.8 Evidence: [to complete] ### 13(8)-2 · duty Manufacturers shall determine the support period so that it reflects the length of time during which the product is expected to be in use, taking into account, in particular, reasonable user expectations, the nature of the product, including its intended purpose, as well as relevant Union law determining the lifetime of products with digital elements. When determining the support period, manufacturers may also take into account the support periods of products with digital elements offering a similar functionality placed on the market by other manufacturers, the availability of the operating environment, the support periods of integrated components that provide core functions and are sourced from third parties as well as relevant guidance provided by the dedicated administrative cooperation group (ADCO) established pursuant to Article 52(15) and the Commission. The matters to be taken into account in order to determine the support period shall be considered in a manner that ensures proportionality. Without prejudice to the second subparagraph, the support period shall be at least five years. Where the product with digital elements is expected to be in use for less than five years, the support period shall correspond to the expected use time. Status: Not started · ISO 27001: nothing in Annex A produces this Evidence: [to complete] ### 13(8)-5 · duty Manufacturers shall include the information that was taken into account to determine the support period of a product with digital elements in the technical documentation as set out in Annex VII. Status: Not started · ISO 27001: Clause 7.5 Evidence: [to complete] ### 13(8)-6 · obligation Manufacturers shall have appropriate policies and procedures, including coordinated vulnerability disclosure policies, referred to in Part II, point (5), of Annex I to process and remediate potential vulnerabilities in the product with digital elements reported from internal or external sources. Status: Not started · ISO 27001: A.5.1, A.8.8 Evidence: [to complete] ### 13(9) · obligation Manufacturers shall ensure that each security update, as referred to in Part II, point (8), of Annex I, which has been made available to users during the support period, remains available after it has been issued for a minimum of 10 years or for the remainder of the support period, whichever is longer. Status: Not started · ISO 27001: A.8.8 Evidence: [to complete] ### 13(12) · duty Before placing a product with digital elements on the market, manufacturers shall draw up the technical documentation referred to in Article 31. They shall carry out the chosen conformity assessment procedures as referred to in Article 32 or have them carried out. Where compliance of the product with digital elements with the essential cybersecurity requirements set out in Part I of Annex I and of the processes put in place by the manufacturer with the essential cybersecurity requirements set out in Part II of Annex I has been demonstrated by that conformity assessment procedure, manufacturers shall draw up the EU declaration of conformity in accordance with Article 28 and affix the CE marking in accordance with Article 30. Status: Not started · ISO 27001: Clause 7.5 Evidence: [to complete] ### 13(13) · duty Manufacturers shall keep the technical documentation and the EU declaration of conformity at the disposal of the market surveillance authorities for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer. Status: Not started · ISO 27001: Clause 7.5, A.5.33 Evidence: [to complete] ### 13(14) · obligation Manufacturers shall ensure that procedures are in place for products with digital elements that are part of a series of production to remain in conformity with this Regulation. Manufacturers shall adequately take into account changes in the development and production process or in the design or characteristics of the product with digital elements and changes in the harmonised standards, European cybersecurity certification schemes or common specifications as referred to in Article 27 by reference to which the conformity of the product with digital elements is declared or by application of which its conformity is verified. Status: Not started · ISO 27001: A.8.32 Evidence: [to complete] ### 13(15) · duty Manufacturers shall ensure that their products with digital elements bear a type, batch or serial number or other element allowing their identification, or, where that is not possible, that that information is provided on their packaging or in a document accompanying the product with digital elements. Status: Not started · ISO 27001: nothing in Annex A produces this Evidence: [to complete] ### 13(16) · duty Manufacturers shall indicate the name, registered trade name or registered trademark of the manufacturer, and the postal address, email address or other digital contact details, as well as, where applicable, the website where the manufacturer can be contacted, on the product with digital elements, on its packaging or in a document accompanying the product with digital elements. That information shall also be included in the information and instructions to the user set out in Annex II. The contact details shall be in a language which can be easily understood by users and market surveillance authorities. Status: Not started · ISO 27001: nothing in Annex A produces this Evidence: [to complete] ### 13(17) · duty For the purposes of this Regulation, manufacturers shall designate a single point of contact to enable users to communicate directly and rapidly with them, including in order to facilitate reporting on vulnerabilities of the product with digital elements. Manufacturers shall ensure that the single point of contact is easily identifiable by the users. They shall also include the single point of contact in the information and instructions to the user set out in Annex II. The single point of contact shall allow users to choose their preferred means of communication and shall not limit such means to automated tools. Status: Not started · ISO 27001: A.8.8 Evidence: [to complete] ### 13(18) · duty Manufacturers shall ensure that products with digital elements are accompanied by the information and instructions to the user set out in Annex II, in paper or electronic form. Such information and instructions shall be provided in a language which can be easily understood by users and market surveillance authorities. They shall be clear, understandable, intelligible and legible. They shall allow for the secure installation, operation and use of products with digital elements. Manufacturers shall keep the information and instructions to the user set out in Annex II at the disposal of users and market surveillance authorities for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer. Where such information and instructions are provided online, manufacturers shall ensure that they are accessible, user-friendly and available online for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer. Status: Not started · ISO 27001: nothing in Annex A produces this Evidence: [to complete] ### 13(19) · duty Manufacturers shall ensure that the end date of the support period referred to in paragraph 8, including at least the month and the year, is clearly and understandably specified at the time of purchase in an easily accessible manner and, where applicable, on the product with digital elements, its packaging or by digital means. Where technically feasible in light of the nature of the product with digital elements, manufacturers shall display a notification to users informing them that their product with digital elements has reached the end of its support period. Status: Not started · ISO 27001: nothing in Annex A produces this Evidence: [to complete] ### 13(20) · duty Manufacturers shall either provide a copy of the EU declaration of conformity or a simplified EU declaration of conformity with the product with digital elements. Where a simplified EU declaration of conformity is provided, it shall contain the exact internet address at which the full EU declaration of conformity can be accessed. Status: Not started · ISO 27001: nothing in Annex A produces this Evidence: [to complete] ### 13(21) · duty From the placing on the market and for the support period, manufacturers who know or have reason to believe that the product with digital elements or the processes put in place by the manufacturer are not in conformity with the essential cybersecurity requirements set out in Annex I shall immediately take the corrective measures necessary to bring that product with digital elements or the manufacturer’s processes into conformity, or to withdraw or recall the product, as appropriate. Status: Not started · ISO 27001: Clause 10.2 Evidence: [to complete] ### 13(22) · duty Manufacturers shall, upon a reasoned request from a market surveillance authority, provide that authority, in a language which can be easily understood by that authority, with all the information and documentation, in paper or electronic form, necessary to demonstrate the conformity of the product with digital elements and of the processes put in place by the manufacturer with the essential cybersecurity requirements set out in Annex I. Manufacturers shall cooperate with that authority, at its request, on any measures taken to eliminate the cybersecurity risks posed by the product with digital elements which they have placed on the market. Status: Not started · ISO 27001: Clause 7.5, A.5.5 Evidence: [to complete] ### 13(23) · duty A manufacturer that ceases its operations and, as a result, is not able to comply with this Regulation shall inform, before the cessation of operations takes effect, the relevant market surveillance authorities as well as, by any means available and to the extent possible, the users of the relevant products with digital elements placed on the market, of the impending cessation of operations. Status: Not started · ISO 27001: A.5.5 Evidence: [to complete] ## Annex I: the essential cybersecurity requirements ### I.1 · essential requirement Products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks. Status: Not started · ISO 27001: Clause 6.1.2, A.5.8, A.8.25 Evidence: [to complete] ### I.2 · reading On the basis of the cybersecurity risk assessment referred to in Article 13(2) and where applicable, products with digital elements shall: Status: Not started · ISO 27001: nothing in Annex A produces this Evidence: [to complete] ### I.2.a · essential requirement be made available on the market without known exploitable vulnerabilities Status: Not started · ISO 27001: A.8.8, A.8.29 Evidence: [to complete] ### I.2.b · essential requirement be made available on the market with a secure by default configuration, unless otherwise agreed between manufacturer and business user in relation to a tailor-made product with digital elements, including the possibility to reset the product to its original state Status: Not started · ISO 27001: A.8.9, A.8.26 Evidence: [to complete] ### I.2.c · essential requirement ensure that vulnerabilities can be addressed through security updates, including, where applicable, through automatic security updates that are installed within an appropriate timeframe enabled as a default setting, with a clear and easy-to-use opt-out mechanism, through the notification of available updates to users, and the option to temporarily postpone them Status: Not started · ISO 27001: A.8.8, A.8.32 Evidence: [to complete] ### I.2.d · essential requirement ensure protection from unauthorised access by appropriate control mechanisms, including but not limited to authentication, identity or access management systems, and report on possible unauthorised access Status: Not started · ISO 27001: A.8.26, A.8.5, A.5.15, A.5.16, A.5.17 Evidence: [to complete] ### I.2.e · essential requirement protect the confidentiality of stored, transmitted or otherwise processed data, personal or other, such as by encrypting relevant data at rest or in transit by state of the art mechanisms, and by using other technical means Status: Not started · ISO 27001: A.8.26, A.8.24 Evidence: [to complete] ### I.2.f · essential requirement protect the integrity of stored, transmitted or otherwise processed data, personal or other, commands, programs and configuration against any manipulation or modification not authorised by the user, and report on corruptions Status: Not started · ISO 27001: A.8.26, A.8.24, A.8.9 Evidence: [to complete] ### I.2.g · essential requirement process only data, personal or other, that are adequate, relevant and limited to what is necessary in relation to the intended purpose of the product with digital elements (data minimisation) Status: Not started · ISO 27001: A.8.26, A.5.34 Evidence: [to complete] ### I.2.h · essential requirement protect the availability of essential and basic functions, also after an incident, including through resilience and mitigation measures against denial-of-service attacks Status: Not started · ISO 27001: A.8.26, A.8.6, A.8.14 Evidence: [to complete] ### I.2.i · essential requirement minimise the negative impact by the products themselves or connected devices on the availability of services provided by other devices or networks Status: Not started · ISO 27001: A.8.27, A.8.20 Evidence: [to complete] ### I.2.j · essential requirement be designed, developed and produced to limit attack surfaces, including external interfaces Status: Not started · ISO 27001: A.8.27, A.8.9 Evidence: [to complete] ### I.2.k · essential requirement be designed, developed and produced to reduce the impact of an incident using appropriate exploitation mitigation mechanisms and techniques Status: Not started · ISO 27001: A.8.27, A.8.28 Evidence: [to complete] ### I.2.l · essential requirement provide security related information by recording and monitoring relevant internal activity, including the access to or modification of data, services or functions, with an opt-out mechanism for the user Status: Not started · ISO 27001: A.8.26, A.8.15, A.8.16 Evidence: [to complete] ### I.2.m · essential requirement provide the possibility for users to securely and easily remove on a permanent basis all data and settings and, where such data can be transferred to other products or systems, ensure that this is done in a secure manner. Status: Not started · ISO 27001: A.8.26, A.8.10 Evidence: [to complete] ### II.1 · essential requirement identify and document vulnerabilities and components contained in products with digital elements, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products Status: Not started · ISO 27001: A.8.8, A.5.9 Evidence: [to complete] ### II.2 · essential requirement in relation to the risks posed to products with digital elements, address and remediate vulnerabilities without delay, including by providing security updates; where technically feasible, new security updates shall be provided separately from functionality updates Status: Not started · ISO 27001: A.8.8, A.8.32 Evidence: [to complete] ### II.3 · essential requirement apply effective and regular tests and reviews of the security of the product with digital elements Status: Not started · ISO 27001: A.8.29, A.8.8, A.5.35 Evidence: [to complete] ### II.4 · essential requirement once a security update has been made available, share and publicly disclose information about fixed vulnerabilities, including a description of the vulnerabilities, information allowing users to identify the product with digital elements affected, the impacts of the vulnerabilities, their severity and clear and accessible information helping users to remediate the vulnerabilities; in duly justified cases, where manufacturers consider the security risks of publication to outweigh the security benefits, they may delay making public information regarding a fixed vulnerability until after users have been given the possibility to apply the relevant patch Status: Not started · ISO 27001: nothing in Annex A produces this Evidence: [to complete] ### II.5 · essential requirement put in place and enforce a policy on coordinated vulnerability disclosure Status: Not started · ISO 27001: nothing in Annex A produces this Evidence: [to complete] ### II.6 · essential requirement take measures to facilitate the sharing of information about potential vulnerabilities in their product with digital elements as well as in third-party components contained in that product, including by providing a contact address for the reporting of the vulnerabilities discovered in the product with digital elements Status: Not started · ISO 27001: nothing in Annex A produces this Evidence: [to complete] ### II.7 · essential requirement provide for mechanisms to securely distribute updates for products with digital elements to ensure that vulnerabilities are fixed or mitigated in a timely manner and, where applicable for security updates, in an automatic manner Status: Not started · ISO 27001: A.8.24, A.8.32 Evidence: [to complete] ### II.8 · essential requirement ensure that, where security updates are available to address identified security issues, they are disseminated without delay and, unless otherwise agreed between a manufacturer and a business user in relation to a tailor-made product with digital elements, free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken. Status: Not started · ISO 27001: nothing in Annex A produces this Evidence: [to complete] ## Article 14: reporting obligations ### 14(1) · duty A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA. The manufacturer shall notify that actively exploited vulnerability via the single reporting platform established pursuant to Article 16. Status: Not started · ISO 27001: A.5.5, A.5.24 Evidence: [to complete] ### 14(2)(a) · deadline an early warning notification of an actively exploited vulnerability, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, indicating, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available Status: Not started · ISO 27001: A.5.24, A.5.26 · Clock: within 24 hours of becoming aware Evidence: [to complete] ### 14(2)(b) · deadline unless the relevant information has already been provided, a vulnerability notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the actively exploited vulnerability, which shall provide general information, as available, about the product with digital elements concerned, the general nature of the exploit and of the vulnerability concerned as well as any corrective or mitigating measures taken, and corrective or mitigating measures that users can take, and which shall also indicate, where applicable, how sensitive the manufacturer considers the notified information to be Status: Not started · ISO 27001: A.5.24, A.5.26 · Clock: within 72 hours of becoming aware Evidence: [to complete] ### 14(2)(c) · deadline unless the relevant information has already been provided, a final report, no later than 14 days after a corrective or mitigating measure is available, including at least the following: (i) a description of the vulnerability, including its severity and impact; (ii) where available, information concerning any malicious actor that has exploited or that is exploiting the vulnerability; (iii) details about the security update or other corrective measures that have been made available to remedy the vulnerability. Status: Not started · ISO 27001: A.5.24, A.5.27, A.8.8 · Clock: within 14 days after a corrective or mitigating measure is available Evidence: [to complete] ### 14(3) · duty A manufacturer shall notify any severe incident having an impact on the security of the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA. The manufacturer shall notify that incident via the single reporting platform established pursuant to Article 16. Status: Not started · ISO 27001: A.5.5, A.5.24 Evidence: [to complete] ### 14(4)(a) · deadline an early warning notification of a severe incident having an impact on the security of the product with digital elements, without undue delay and in any event within 24 hours of the manufacturer becoming aware of it, including at least whether the incident is suspected of being caused by unlawful or malicious acts, which shall also indicate, where applicable, the Member States on the territory of which the manufacturer is aware that their product with digital elements has been made available Status: Not started · ISO 27001: A.5.24, A.5.26 · Clock: within 24 hours of becoming aware Evidence: [to complete] ### 14(4)(b) · deadline unless the relevant information has already been provided, an incident notification, without undue delay and in any event within 72 hours of the manufacturer becoming aware of the incident, which shall provide general information, where available, about the nature of the incident, an initial assessment of the incident, as well as any corrective or mitigating measures taken, and corrective or mitigating measures that users can take, and which shall also indicate, where applicable, how sensitive the manufacturer considers the notified information to be Status: Not started · ISO 27001: A.5.24, A.5.26 · Clock: within 72 hours of becoming aware Evidence: [to complete] ### 14(4)(c) · deadline unless the relevant information has already been provided, a final report, within one month after the submission of the incident notification under point (b), including at least the following: (i) a detailed description of the incident, including its severity and impact; (ii) the type of threat or root cause that is likely to have triggered the incident; (iii) applied and ongoing mitigation measures. Status: Not started · ISO 27001: A.5.24, A.5.27 · Clock: within 1 month after the notification is submitted Evidence: [to complete] ### 14(5) · reading For the purposes of paragraph 3, an incident having an impact on the security of the product with digital elements shall be considered to be severe where: (a) it negatively affects or is capable of negatively affecting the ability of a product with digital elements to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions; or (b) it has led or is capable of leading to the introduction or execution of malicious code in a product with digital elements or in the network and information systems of a user of the product with digital elements. Status: Not started · ISO 27001: A.5.25 Evidence: [to complete] ### 14(6) · duty Where necessary, the CSIRT designated as coordinator initially receiving the notification may request manufacturers to provide an intermediate report on relevant status updates about the actively exploited vulnerability or severe incident having an impact on the security of the product with digital elements. Status: Not started · ISO 27001: A.5.24 Evidence: [to complete] ### 14(7) · duty The notifications referred to in paragraphs 1 and 3 of this Article shall be submitted via the single reporting platform referred to in Article 16 using one of the electronic notification end-points referred to in Article 16(1). The notification shall be submitted using the electronic notification end-point of the CSIRT designated as coordinator of the Member State where the manufacturers have their main establishment in the Union and shall be simultaneously accessible to ENISA. For the purposes of this Regulation, a manufacturer shall be considered to have its main establishment in the Union in the Member State where the decisions related to the cybersecurity of its products with digital elements are predominantly taken. If such a Member State cannot be determined, the main establishment shall be considered to be in the Member State where the manufacturer concerned has the establishment with the highest number of employees in the Union. Where a manufacturer has no main establishment in the Union, it shall submit the notifications referred to in paragraphs 1 and 3 using the electronic notification end-point of the CSIRT designated as coordinator in the Member State determined pursuant to the following order and based on the information available to the manufacturer: (a) the Member State in which the authorised representative acting on behalf of the manufacturer for the highest number of products with digital elements of that manufacturer is established; (b) the Member State in which the importer placing on the market the highest number of products with digital elements of that manufacturer is established; (c) the Member State in which the distributor making available on the market the highest number of products with digital elements of that manufacturer is established; (d) the Member State in which the highest number of users of products with digital elements of that manufacturer are located. In relation to the third subparagraph, point (d), a manufacturer may submit notifications related to any subsequent actively exploited vulnerability or severe incident having an impact on the security of the product with digital elements to the same CSIRT designated as coordinator to which it first reported. Status: Not started · ISO 27001: A.5.5 Evidence: [to complete] ### 14(8) · duty After becoming aware of an actively exploited vulnerability or a severe incident having an impact on the security of the product with digital elements, the manufacturer shall inform the impacted users of the product with digital elements, and where appropriate all users, of that vulnerability or incident and, where necessary, of any risk mitigation and corrective measures that the users can deploy to mitigate the impact of that vulnerability or incident, where appropriate in a structured, machine-readable format that is easily automatically processable. Where the manufacturer fails to inform the users of the product with digital elements in a timely manner, the notified CSIRTs designated as coordinators may provide such information to the users when considered to be proportionate and necessary for preventing or mitigating the impact of that vulnerability or incident. Status: Not started · ISO 27001: A.5.24, A.5.26 Evidence: [to complete] ## Roles, traceability, transition and dates: Articles 21 to 23, 69 and 71 ### 22(1) · obligation A natural or legal person, other than the manufacturer, the importer or the distributor, that carries out a substantial modification of a product with digital elements and makes that product available on the market, shall be considered to be a manufacturer for the purposes of this Regulation. Status: Not started · ISO 27001: nothing in Annex A produces this Evidence: [to complete] ### 22(2) · obligation The person referred to in paragraph 1 of this Article shall be subject to the obligations set out in Articles 13 and 14 for the part of the product with digital elements that is affected by the substantial modification or, if the substantial modification has an impact on the cybersecurity of the product with digital elements as a whole, for the entire product. Status: Not started · ISO 27001: nothing in Annex A produces this Evidence: [to complete] ### 23(1) · duty Economic operators shall, on request, provide the market surveillance authorities with the following information: (a) the name and address of any economic operator who has supplied them with a product with digital elements; (b) where available, the name and address of any economic operator to whom they have supplied a product with digital elements. Status: Not started · ISO 27001: A.5.5, A.5.19 Evidence: [to complete] ### 23(2) · duty Economic operators shall be able to present the information referred to in paragraph 1 for 10 years after they have been supplied with the product with digital elements and for 10 years after they have supplied the product with digital elements. Status: Not started · ISO 27001: A.5.33 Evidence: [to complete] ### 69(2) · obligation Products with digital elements that have been placed on the market before 11 December 2027 shall be subject to the requirements set out in this Regulation only if, from that date, those products are subject to a substantial modification. Status: Not started · ISO 27001: nothing in Annex A produces this Evidence: [to complete] ### 69(3) · obligation By way of derogation from paragraph 2 of this Article, the obligations laid down in Article 14 shall apply to all products with digital elements that fall within the scope of this Regulation that have been placed on the market before 11 December 2027. Status: Not started · ISO 27001: nothing in Annex A produces this Evidence: [to complete] ### 71(2) · deadline This Regulation shall apply from 11 December 2027. Status: Not started · ISO 27001: nothing in Annex A produces this · Clock: applies from 11 December 2027 Evidence: [to complete] ### 71(2)-2 · deadline However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026. Status: Not started · ISO 27001: nothing in Annex A produces this · Clock: applies from 11 September 2026 Evidence: [to complete] An importer or distributor that places a product on the market under its own name or trademark, or substantially modifies it, is a manufacturer (Article 21), as is anyone else who substantially modifies a product and makes it available (Article 22). An open-source software steward carries the Article 14 rows only to the extent of Article 24(3). This checklist is written from the text of the Regulation against the statuses given. It is not legal advice; the ISO 27001 references are StandardOS's reading, and the Regulation grants no presumption of conformity beyond Article 27.
StandardOS keeps these rows as positions
Register the product and StandardOS holds every row that binds your role as a position with its status, owner and evidence, starts the Article 14 clocks when an event is logged, and assembles the technical file the Annex I rows are documented in.
Is your product in scope, and which tier?The Article 14 deadline calculatorAnnex I mapped to ISO 27001