Lex Browse everything
For developers

Regulation (EU) 2024/2847

as it stood on 2024-11-20, permalink: /eu-eurlex/32024r2847/2024-11-20--59834fbc3a7ee89d3fd920d36b6d6b85b888b9794dc7768bc989db136ed00f68

2024-10-232024-11-20
Browse 2 dated versions

2 versions · choose a date to read the law as it stood that day · the one you are reading

Official publisher wording state selected for 2024-11-20. This is the consolidated version dated 2024-11-20. Its interval on Lex's publisher-version axis is publisher version 2024-11-20 → latest held; that is not a claim about entry into force or application.
Text included, per-article reading view. Deterministic extraction of the verbatim retrieved document; each displayed provision carries its own hash and anchor. © European Union, 1998-2026. Reuse permitted with attribution under Commission Decision 2011/833/EU. Consolidated texts have no legal effect; only acts published in the Official Journal are authentic.
Outline, 71 provisions

Article 1 Article 2 Article 3 Article 4 Article 5 Article 6 Article 7 Article 8 Article 9 Article 10 Article 11 Article 12 Article 13 Article 14 Article 15 Article 16 Article 17 Article 18 Article 19 Article 20 Article 21 Article 22 Article 23 Article 24 Article 25 Article 26 Article 27 Article 28 Article 29 Article 30 Article 31 Article 32 Article 33 Article 34 Article 35 Article 36 Article 37 Article 38 Article 39 Article 40 Article 41 Article 42 Article 43 Article 44 Article 45 Article 46 Article 47 Article 48 Article 49 Article 50 Article 51 Article 52 Article 53 Article 54 Article 55 Article 56 Article 57 Article 58 Article 59 Article 60 Article 61 Article 62 Article 63 Article 64 Article 65 Article 66 Article 67 Article 68 Article 69 Article 70 Article 71

CHAPTER I — GENERAL PROVISIONS

Article 1, Subject matter #art_1
Article 2, Scope #art_2
Article 3, Definitions #art_3
Article 4, Free movement #art_4
Article 5, Procurement or use of products with digital elements #art_5
Article 6, Requirements for products with digital elements #art_6
Article 7, Important products with digital elements #art_7
Article 8, Critical products with digital elements #art_8
Article 9, Stakeholder consultation #art_9
Article 10, Enhancing skills in a cyber resilient digital environment #art_10
Article 11, General product safety #art_11
Article 12, High-risk AI systems #art_12

CHAPTER II — OBLIGATIONS OF ECONOMIC OPERATORS AND PROVISIONS IN RELATION TO FREE AND OPEN-SOURCE SOFTWARE

Article 13, Obligations of manufacturers #art_13
Article 14, Reporting obligations of manufacturers #art_14
Article 15, Voluntary reporting #art_15
Article 16, Establishment of a single reporting platform #art_16
Article 17, Other provisions related to reporting #art_17
Article 18, Authorised representatives #art_18
Article 19, Obligations of importers #art_19
Article 20, Obligations of distributors #art_20
Article 21, Cases in which obligations of manufacturers apply to importers and distributors #art_21
Article 22, Other cases in which obligations of manufacturers apply #art_22
Article 23, Identification of economic operators #art_23
Article 24, Obligations of open-source software stewards #art_24
Article 25, Security attestation of free and open-source software #art_25
Article 26, Guidance #art_26

CHAPTER III — CONFORMITY OF THE PRODUCT WITH DIGITAL ELEMENTS

Article 27, Presumption of conformity #art_27
Article 28, EU declaration of conformity #art_28
Article 29, General principles of the CE marking #art_29
Article 30, Rules and conditions for affixing the CE marking #art_30
Article 31, Technical documentation #art_31
Article 32, Conformity assessment procedures for products with digital elements #art_32
Article 33, Support measures for microenterprises and small and medium-sized enterprises, including start-ups #art_33
Article 34, Mutual recognition agreements #art_34

CHAPTER IV — NOTIFICATION OF CONFORMITY ASSESSMENT BODIES

Article 35, Notification #art_35
Article 36, Notifying authorities #art_36
Article 37, Requirements relating to notifying authorities #art_37
Article 38, Information obligation on notifying authorities #art_38
Article 39, Requirements relating to notified bodies #art_39
Article 40, Presumption of conformity of notified bodies #art_40
Article 41, Subsidiaries of and subcontracting by notified bodies #art_41
Article 42, Application for notification #art_42
Article 43, Notification procedure #art_43
Article 44, Identification numbers and lists of notified bodies #art_44
Article 45, Changes to notifications #art_45
Article 46, Challenge of the competence of notified bodies #art_46
Article 47, Operational obligations of notified bodies #art_47
Article 48, Appeal against decisions of notified bodies #art_48
Article 49, Information obligation on notified bodies #art_49
Article 50, Exchange of experience #art_50
Article 51, Coordination of notified bodies #art_51

CHAPTER V — MARKET SURVEILLANCE AND ENFORCEMENT

Article 52, Market surveillance and control of products with digital elements in the Union market #art_52
Article 53, Access to data and documentation #art_53
Article 54, Procedure at national level concerning products with digital elements presenting a significant cybersecurity risk #art_54
Article 55, Union safeguard procedure #art_55
Article 56, Procedure at Union level concerning products with digital elements presenting a significant cybersecurity risk #art_56
Article 57, Compliant products with digital elements which present a significant cybersecurity risk #art_57
Article 58, Formal non-compliance #art_58
Article 59, Joint activities of market surveillance authorities #art_59
Article 60, Sweeps #art_60

CHAPTER VI — DELEGATED POWERS AND COMMITTEE PROCEDURE

Article 61, Exercise of the delegation #art_61
Article 62, Committee procedure #art_62

CHAPTER VII — CONFIDENTIALITY AND PENALTIES

Article 63, Confidentiality #art_63
Article 64, Penalties #art_64
Article 65, Representative actions #art_65

CHAPTER VIII — TRANSITIONAL AND FINAL PROVISIONS

Article 66, Amendment to Regulation (EU) 2019/1020 #art_66
Article 67, Amendment to Directive (EU) 2020/1828 #art_67
Article 68, Amendment to Regulation (EU) No 168/2013 #art_68
Article 69, Transitional provisions #art_69
Article 70, Evaluation and review #art_70
Article 71, Entry into force and application #art_71
Provenance and validity dates, identifier, hash
as of2024-11-20 → this publisher state was selected
publisher statepublisher version 2024-11-20 → latest held publisher-asserted
typeREG Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) (Text with EEA relevance)
languageen
published2024-11-20
lex_ideu-eurlex:32024r2847:2024-11-20--59834fbc3a7ee89d3fd920d36b6d6b85b888b9794dc7768bc989db136ed00f68
record sha25613de3dafbb18959571b2ae981b9cf14d1d2828e77a5ee7e5b09f5a26b642539f
New here? What am I looking at?

This is an official consolidated text: the original act with later amendments merged by EUR-Lex for the date shown above.

The consolidation date is not an entry-into-force or application date. It identifies a publisher wording state. The authentic legal acts remain those published in the Official Journal; Lex preserves the consolidated wording, source and hashes as a reading and comparison aid.

Each displayed provision carries its own hash so you can verify that Lex served the indexed text unchanged, here is how.

← previous version (2024-10-23)   what changed?   timeline

tierA, publisher-supplied consolidated wording-state dates
history beginspublisher
index built2026-08-15T09:01:06Z · corpus e9c4df0981c855855a1a28218cf086ddeb5bb691
stamp signaturevalid (ECDSA-P256)