Defined terms — REGULATION (EU) 2024/2847 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) (Text with EEA relevance)
European Union · 32024R2847 · 359 provisions
38 defined in this instrument, 13 borrowed from other acts.
actively exploited vulnerability — a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner Article 3 — Definitions
authorised representative — a natural or legal person established within the Union who has received a written mandate from a manufacturer to act on its behalf in relation to specified tasks Article 3 — Definitions
CE marking — a marking by which a manufacturer indicates that a product with digital elements and the processes put in place by the manufacturer are in conformity with the essential cybersecurity requirements set out in Annex I and other applicable Union harmonisation legislation providing for its affixing Article 3 — Definitions
component — software or hardware intended for integration into an electronic information system Article 3 — Definitions
conformity assessment — the process of verifying whether the essential cybersecurity requirements set out in Annex I have been fulfilled Article 3 — Definitions
conformity assessment body — borrowed from another act; this instrument states no meaning of its own Article 3 — Definitions
consumer — a natural person who acts for purposes which are outside that person’s trade, business, craft or profession;
(19)
‘microenterprises’, ‘small enterprises’ and Article 3 — Definitions
CSIRT designated as coordinator — a CSIRT designated as coordinator pursuant to Article 12(1) of Directive (EU) 2022/2555 Article 3 — Definitions
cyber threat — borrowed from another act; this instrument states no meaning of its own Article 3 — Definitions
cybersecurity — borrowed from another act; this instrument states no meaning of its own Article 3 — Definitions
cybersecurity risk — the potential for loss or disruption caused by an incident and is to be expressed as a combination of the magnitude of such loss or disruption and the likelihood of occurrence of the incident Article 3 — Definitions
distributor — a natural or legal person in the supply chain, other than the manufacturer or the importer, that makes a product with digital elements available on the Union market without affecting its properties Article 3 — Definitions
economic operator — the manufacturer, the authorised representative, the importer, the distributor, or other natural or legal person who is subject to obligations in relation to the manufacture of products with digital elements or to the making available of products with digital elements on the market in accordance with this Regulation Article 3 — Definitions
electronic information system — a system, including electrical or electronic equipment, capable of processing, storing or transmitting digital data Article 3 — Definitions
end-point — any device that is connected to a network and serves as an entry point to that network Article 3 — Definitions
European standard — borrowed from another act; this instrument states no meaning of its own Article 3 — Definitions
exploitable vulnerability — a vulnerability that has the potential to be effectively used by an adversary under practical operational conditions Article 3 — Definitions
free and open-source software — software the source code of which is openly shared and which is made available under a free and open-source licence which provides for all rights to make it freely accessible, usable, modifiable and redistributable Article 3 — Definitions
hardware — a physical electronic information system, or parts thereof capable of processing, storing or transmitting digital data Article 3 — Definitions
harmonised standard — borrowed from another act; this instrument states no meaning of its own Article 3 — Definitions
importer — a natural or legal person established in the Union who places on the market a product with digital elements that bears the name or trademark of a natural or legal person established outside the Union Article 3 — Definitions
incident — borrowed from another act; this instrument states no meaning of its own Article 3 — Definitions
indirect connection — a connection to a device or network, which does not take place directly but rather as part of a larger system that is directly connectable to such device or network Article 3 — Definitions
intended purpose — the use for which a product with digital elements is intended by the manufacturer, including the specific context and conditions of use, as specified in the information supplied by the manufacturer in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation Article 3 — Definitions
international standard — borrowed from another act; this instrument states no meaning of its own Article 3 — Definitions
logical connection — a virtual representation of a data connection implemented through a software interface Article 3 — Definitions
making available on the market — the supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge Article 3 — Definitions
manufacturer — a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge Article 3 — Definitions
market surveillance authority — borrowed from another act; this instrument states no meaning of its own Article 3 — Definitions
medium-sized enterprises — respectively, microenterprises, small enterprises and medium-sized enterprises as defined in the Annex to Recommendation 2003/361/EC Article 3 — Definitions
near miss — borrowed from another act; this instrument states no meaning of its own Article 3 — Definitions
notified body — a conformity assessment body designated in accordance with Article 43 and other relevant Union harmonisation legislation Article 3 — Definitions
notifying authority — the national authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring Article 3 — Definitions
open-source software steward — a legal person, other than a manufacturer, that has the purpose or objective of systematically providing support on a sustained basis for the development of specific products with digital elements, qualifying as free and open-source software and intended for commercial activities, and that ensures the viability of those products Article 3 — Definitions
personal data — borrowed from another act; this instrument states no meaning of its own Article 3 — Definitions
physical connection — a connection between electronic information systems or components implemented using physical means, including through electrical, optical or mechanical interfaces, wires or radio waves Article 3 — Definitions
placing on the market — the first making available of a product with digital elements on the Union market Article 3 — Definitions
product with digital elements — a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately Article 3 — Definitions
reasonably foreseeable misuse — the use of a product with digital elements in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems Article 3 — Definitions
reasonably foreseeable use — use that is not necessarily the intended purpose supplied by the manufacturer in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation, but which is likely to result from reasonably foreseeable human behaviour or technical operations or interactions Article 3 — Definitions
recall — borrowed from another act; this instrument states no meaning of its own Article 3 — Definitions
remote data processing — data processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the product with digital elements from performing one of its functions Article 3 — Definitions
significant cybersecurity risk — a cybersecurity risk which, based on its technical characteristics, can be assumed to have a high likelihood of an incident that could lead to a severe negative impact, including by causing considerable material or non-material loss or disruption Article 3 — Definitions
software — the part of an electronic information system which consists of computer code Article 3 — Definitions
software bill of materials — a formal record containing details and supply chain relationships of components included in the software elements of a product with digital elements Article 3 — Definitions
substantial modification — a change to the product with digital elements following its placing on the market, which affects the compliance of the product with digital elements with the essential cybersecurity requirements set out in Part I of Annex I or which results in a modification to the intended purpose for which the product with digital elements has been assessed Article 3 — Definitions
support period — the period during which a manufacturer is required to ensure that vulnerabilities of a product with digital elements are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I Article 3 — Definitions
Union harmonisation legislation — borrowed from another act; this instrument states no meaning of its own Article 11 — General product safety
Union harmonisation legislation — Union legislation listed in Annex I to Regulation (EU) 2019/1020 and any other Union legislation harmonising the conditions for the marketing of products to which that Regulation applies Article 3 — Definitions
vulnerability — a weakness, susceptibility or flaw of a product with digital elements that can be exploited by a cyber threat Article 3 — Definitions
withdrawal — borrowed from another act; this instrument states no meaning of its own Article 3 — Definitions