Product Liability Directive

The Product Liability Directive: nothing to certify, and a technical file a court can order out of you

Who it applies to
Every manufacturer of a product placed on the EU market, and software is a product in so many words (Article 4(1)). Where the manufacturer is outside the Union, the importer, the authorised representative or the fulfilment service provider can be liable instead.
The dates
Products placed on the market or put into service after 8 December 2026. Member states must have their national law in force by 9 December 2026: one day apart in the act itself.
The one thing to do
Nothing to register, certify or declare, so no company can be compliant with this Directive. Reduce the exposure, and keep the evidence a court can order you to disclose.

Where the Cyber Resilience Act meets it, and which way it runs

6 of the 9 connections run against the manufacturer. Conformity with the CRA shields nobody from this liability; a breach of it is the claimant's shortcut.

How each provision of the Directive meets the Cyber Resilience Act, and whether it helps or harms the manufacturer
Against youArt. 10(2)(b)CRA 13(1)

Breaching the CRA presumes the product was defective

Defectiveness is presumed where the claimant shows the product does not comply with mandatory product safety requirements laid down in Union or national law that protect against the risk of the damage suffered. The CRA's essential requirements are mandatory Union product safety requirements, so a claimant who shows a breach of them need not prove defectiveness separately; the manufacturer has to rebut it.

Against youArt. 7(2)(f)CRA 13(1)

Cybersecurity requirements are weighed in the defect test

Relevant product safety requirements, including safety-relevant cybersecurity requirements, are among the circumstances a court takes into account in assessing defectiveness. Weaker than the presumption above, and it points the same way: the CRA is a yardstick a court may hold the product to, not a shelter from one.

Against youArt. 11(2)(c)CRA 13(8)

Not shipping a security update is inside the liability

A manufacturer is normally exempt where the defect came about after the product was placed on the market. That exemption does not apply where the defectiveness is due to the absence of software updates or upgrades needed to maintain safety, within the manufacturer's control. The CRA obliges manufacturers to provide security updates through the support period, so the duty and the exposure describe the same failure.

Against youArt. 11(2)(b)CRA 13(9)

A bad update is the manufacturer's too

The same exemption does not apply where the defectiveness is due to software, including updates or upgrades, within the manufacturer's control. An update that introduces the defect is not answered by saying the product left the factory sound.

Against youArt. 7(2)(e)CRA 13(8)

A support period is a period of retained control

The moment that matters for assessing a defect is when the product was placed on the market or, where the manufacturer keeps control after that, when it left their control. A CRA support period is a period of retained control, so it is also the period the defect test looks at.

Against youArt. 10(2)(a)CRA 13(7)

The technical file can be ordered out of you, and withholding it presumes the defect

A court may order a defendant to disclose relevant evidence at its disposal, and defectiveness is presumed where the defendant fails to. A CRA technical file is evidence at the manufacturer's disposal. Keeping one in order is how that order is survivable; not keeping one does not avoid it.

For youArt. 11(1)(e)

The development risk defence, which is about knowledge, not compliance

A manufacturer is exempt where the objective state of scientific and technical knowledge at the time did not allow the defect to be discovered. It is the nearest thing to a defence a diligent manufacturer has, and it turns on what was knowable, not on what was certified. Article 18 lets a member state remove it, so it is not available everywhere.

For youArt. 7(3)

Improving the product later does not make the old one defective

A product is not defective for the sole reason that a better product, including updates or upgrades, has since been placed on the market. Shipping improvements is not an admission.

NeitherArt. 15

None of this can be contracted away

Liability under the Directive cannot be limited or excluded, in relation to the injured person, by a contractual term or by national law. Terms of service do not reach it, and neither does a CRA conformity assessment: nothing in the Directive makes conformity with another instrument a defence.

Your technical file is evidence at your disposal

A court can order it disclosed under Article 9, and failing to disclose presumes the defect under Article 10(2)(a). Keeping the file in order is how that order is survivable.

The CRA technical file

The Directive's provisions, in the Official Journal's words

33 provisions, grouped by what they do. The text is the Official Journal's as corrected, with the paragraph numbers it prints.

Scope

  • Art. 2(1)1. This Directive shall apply to products placed on the market or put into service after 8 December 2026.
  • Art. 21(1)Directive 85/374/EEC is repealed with effect from 9 December 2026. However, it shall continue to apply with regard to products placed on the market or put into service before that date. References to the repealed Directive shall be construed as references to this Directive and shall be read in accordance with the correlation table set out in the Annex.

Definitions

  • Art. 4(1)‘product’ means all movables, even if integrated into, or inter-connected with, another movable or an immovable; it includes electricity, digital manufacturing files, raw materials and software;

Damage

  • Art. 5(1)1. Member States shall ensure that any natural person who suffers damage caused by a defective product (the ‘injured person’) is entitled to compensation in accordance with this Directive.
  • Art. 6(1)1. The right to compensation pursuant to Article 5 shall apply in respect of only the following types of damage:

Defectiveness

  • Art. 7(1)1. A product shall be considered defective where it does not provide the safety that a person is entitled to expect or that is required under Union or national law.
  • Art. 7(2)(c)the effect on the product of any ability to continue to learn or acquire new features after it is placed on the market or put into service;
  • Art. 7(2)(d)the reasonably foreseeable effect on the product of other products that can be expected to be used together with the product, including by means of inter-connection;
  • Art. 7(2)(e)the moment in time when the product was placed on the market or put into service or, where the manufacturer retains control over the product after that moment, the moment in time when the product left the control of the manufacturer;
  • Art. 7(2)(f)relevant product safety requirements, including safety-relevant cybersecurity requirements;
  • Art. 7(3)3. A product shall not be considered to be defective for the sole reason that a better product, including updates or upgrades for a product, has already been or is subsequently placed on the market or put into service.

Who is liable

  • Art. 8(1)1. Member States shall ensure that the following economic operators are liable for damage in accordance with this Directive:
  • Art. 8(2)2. Any natural or legal person that substantially modifies a product outside the manufacturer’s control and thereafter makes it available on the market or puts it into service shall be considered to be a manufacturer of that product for the purposes of paragraph 1.
  • Art. 12(1)1. Without prejudice to national law concerning rights of contribution or recourse, Member States shall ensure that where two or more economic operators are liable for the same damage pursuant to this Directive, they can be held liable jointly and severally.
  • Art. 15Member States shall ensure that the liability of an economic operator pursuant to this Directive is not, in relation to the injured person, limited or excluded by a contractual provision or by national law.

Disclosure of evidence

  • Art. 9(1)1. Member States shall ensure that, at the request of a person who is claiming compensation in proceedings before a national court for damage caused by a defective product (the ‘claimant’) and who has presented facts and evidence sufficient to support the plausibility of the claim for compensation, the defendant is required to disclose relevant evidence that is at the defendant’s disposal, subject to the conditions set out in this Article.

Burden of proof

  • Art. 10(2)2. The defectiveness of the product shall be presumed where any of the following conditions are met:
  • Art. 10(2)(a)the defendant fails to disclose relevant evidence pursuant to Article 9(1);
  • Art. 10(2)(b)the claimant demonstrates that the product does not comply with mandatory product safety requirements laid down in Union or national law that are intended to protect against the risk of the damage suffered by the injured person; or
  • Art. 10(2)(c)the claimant demonstrates that the damage was caused by an obvious malfunction of the product during reasonably foreseeable use or under ordinary circumstances.
  • Art. 10(3)3. The causal link between the defectiveness of the product and the damage shall be presumed where it has been established that the product is defective and that the damage caused is of a kind typically consistent with the defect in question.

Exemptions

  • Art. 11(1)1. An economic operator as referred to in Article 8 shall not be liable for damage caused by a defective product if that economic operator proves any of the following:
  • Art. 11(1)(c)that it is probable that the defectiveness that caused the damage did not exist at the time the product was placed on the market, put into service or, in the case of a distributor, made available on the market, or that that defectiveness came into being after that moment;
  • Art. 11(1)(e)that the objective state of scientific and technical knowledge at the time the product was placed on the market or put into service or during the period in which the product was within the manufacturer’s control was not such that the defectiveness could be discovered;
  • Art. 11(2)2. By way of derogation from paragraph 1, point (c), an economic operator shall not be exempted from liability where the defectiveness of a product is due to any of the following, provided that it is within the manufacturer’s control:
  • Art. 11(2)(a)a related service;
  • Art. 11(2)(b)software, including software updates or upgrades;
  • Art. 11(2)(c)a lack of software updates or upgrades necessary to maintain safety;
  • Art. 18(1)1. Member States may, by way of derogation from Article 11(1), point (e), maintain in their legal systems existing measures whereby economic operators are liable even if they prove that the objective state of scientific and technical knowledge at the time the product was placed on the market or put into service or during the period in which the product was within the manufacturer’s control was not such that the defectiveness could be discovered. Any Member State wishing to maintain measures in accordance with this paragraph shall notify the text of the measures to the Commission no later than 9 December 2026. The Commission shall inform the other Member States thereof.

Recourse

  • Art. 14(1)Where more than one economic operator is liable for the same damage, an economic operator that has compensated the injured person shall be entitled to pursue remedies against other economic operators liable pursuant to Article 8 in accordance with national law.

Time limits

  • Art. 16(1)1. Member States shall ensure that a limitation period of three years applies to the initiation of proceedings to claim compensation for damage falling within the scope of this Directive. The limitation period shall run from the day on which the injured person became aware, or should reasonably have become aware, of all of the following:
  • Art. 17(1)1. Member States shall ensure that an injured person is no longer entitled to compensation pursuant to this Directive upon the expiry of a period of 10 years, unless that injured person has, in the meantime, initiated proceedings against an economic operator that can be held liable pursuant to Article 8. That period shall run from:

Transposition

  • Art. 22(1)1. Member States shall bring into force the laws, regulations and administrative provisions necessary to comply with this Directive by 9 December 2026. They shall immediately inform the Commission thereof. When Member States adopt those measures, they shall contain a reference to this Directive or shall be accompanied by such a reference on the occasion of their official publication. The methods of making such reference shall be laid down by the Member States.

National law

Each member state must bring its national measures into force by 9 December 2026. Which states have communicated measures so far is in the EU register of national implementing measures. It lists only what a government has notified, so a state whose parliament has acted but has not notified appears there as none. National implementing measures on EUR-Lex

Read from Directive (EU) 2024/2853 in the Official Journal on 29 September 2026, with the corrigendum applied in every language shown. EUR-Lex

Questions

Does the Cyber Resilience Act protect me from product liability?
No. Conformity with the CRA is not a defence and creates no presumption that the product is not defective. A breach of it lets the claimant presume the defect (Article 10(2)(b)), as the table above shows.
Can I limit this liability in my terms of service?
No. Under Article 15, liability cannot be limited or excluded, in relation to the injured person, by contract or by national law.
We only ship software, not hardware. Does it reach us?
Yes. Article 4(1) lists software as a product.
We placed the product on the market before the date.
Article 2(1) applies to products placed on the market or put into service after 8 December 2026. What came before stays under the 1985 Directive, which Article 21 repeals with a transitional provision.
Is not shipping a security update a defect?
It can be. Article 11(2)(c) removes the exemption for a defect that came about later where the defectiveness is due to the absence of updates necessary to maintain safety, within your control.

Keep the file a court can ask for

StandardOS keeps the CRA technical file, the support period and the record of every update in one place, versioned, so the evidence exists and says what you did and when.

Related:Cyber Resilience ActArticles

This page in:DeutschFrançaisNederlandsEspañolDansk