Key Terms
- Product with digital elements
- Any software or hardware product and its remote data processing solutions, including components placed on the market separately, that has a direct or indirect data connection to a device or network [Art. 3(1)].
- Software bill of materials (SBOM)
- A formal, machine-readable record detailing the components and supply chain relationships within the software elements of a product with digital elements [Art. 3(39)].
- Actively exploited vulnerability
- A vulnerability for which reliable evidence exists that a malicious actor has exploited it in a system without the system owner's permission [Art. 3(42)].
- Support period
- The time during which a manufacturer must ensure effective vulnerability handling in accordance with Annex I Part II — at least five years unless the expected product lifetime is shorter [Art. 3(20), Art. 13(8)].
- Open-source software steward
- A legal person, other than a manufacturer, that systematically provides sustained support for the development of specific free and open-source products intended for commercial activities [Art. 3(14)].
- Substantial modification
- A change to a product with digital elements after its placing on the market that affects compliance with the essential cybersecurity requirements in Annex I Part I, or that changes the product's intended purpose [Art. 3(30)].
- Conformity assessment
- The process of verifying whether the essential cybersecurity requirements set out in Annex I have been fulfilled, carried out through self-assessment or third-party evaluation depending on the product category [Art. 3(27), Art. 32].
Frequently Asked Questions
Does the CRA apply to pure SaaS products?
Are open-source projects affected?
What qualifies as an 'important' or 'critical' product?
What are the reporting deadlines for actively exploited vulnerabilities?
How long must security updates be provided?
What happens to products already on the market when the CRA applies?
Is a software bill of materials (SBOM) mandatory to share with customers?
Assessment Factors & Checklist
PremiumQuestions for Your Lawyer
PremiumConclusion & Summary
PremiumDetailed analysis with source links.
Schalten Sie die KI-Analyse frei — mit markierten Fundstellen und direkten Links zu EUR-Lex. 7 Tage kostenlos testen.
Keine Kreditkarte heute. Kündigung jederzeit.