Annexes to COM(2022)454 - Horizontal cybersecurity requirements for products with digital elements - Main contents
Please note
This page contains a limited version of this dossier in the EU Monitor.
dossier | COM(2022)454 - Horizontal cybersecurity requirements for products with digital elements. |
---|---|
document | COM(2022)454 ![]() |
date | October 23, 2024 |
ESSENTIAL CYBERSECURITY REQUIREMENTS
Part I Cybersecurity requirements relating to the properties of products with digital elements
(1) | Products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks. |
(2) | On the basis of the cybersecurity risk assessment referred to in Article 13(2) and where applicable, products with digital elements shall:
|
Part II Vulnerability handling requirements
Manufacturers of products with digital elements shall:
(1) | identify and document vulnerabilities and components contained in products with digital elements, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products; |
(2) | in relation to the risks posed to products with digital elements, address and remediate vulnerabilities without delay, including by providing security updates; where technically feasible, new security updates shall be provided separately from functionality updates; |
(3) | apply effective and regular tests and reviews of the security of the product with digital elements; |
(4) | once a security update has been made available, share and publicly disclose information about fixed vulnerabilities, including a description of the vulnerabilities, information allowing users to identify the product with digital elements affected, the impacts of the vulnerabilities, their severity and clear and accessible information helping users to remediate the vulnerabilities; in duly justified cases, where manufacturers consider the security risks of publication to outweigh the security benefits, they may delay making public information regarding a fixed vulnerability until after users have been given the possibility to apply the relevant patch; |
(5) | put in place and enforce a policy on coordinated vulnerability disclosure; |
(6) | take measures to facilitate the sharing of information about potential vulnerabilities in their product with digital elements as well as in third-party components contained in that product, including by providing a contact address for the reporting of the vulnerabilities discovered in the product with digital elements; |
(7) | provide for mechanisms to securely distribute updates for products with digital elements to ensure that vulnerabilities are fixed or mitigated in a timely manner and, where applicable for security updates, in an automatic manner; |
(8) | ensure that, where security updates are available to address identified security issues, they are disseminated without delay and, unless otherwise agreed between a manufacturer and a business user in relation to a tailor-made product with digital elements, free of charge, accompanied by advisory messages providing users with the relevant information, including on potential action to be taken. |
ANNEX II
INFORMATION AND INSTRUCTIONS TO THE USER
At minimum, the product with digital elements shall be accompanied by:
1. | the name, registered trade name or registered trademark of the manufacturer, and the postal address, the email address or other digital contact as well as, where available, the website at which the manufacturer can be contacted; |
2. | the single point of contact where information about vulnerabilities of the product with digital elements can be reported and received, and where the manufacturer’s policy on coordinated vulnerability disclosure can be found; |
3. | name and type and any additional information enabling the unique identification of the product with digital elements; |
4. | the intended purpose of the product with digital elements, including the security environment provided by the manufacturer, as well as the product’s essential functionalities and information about the security properties; |
5. | any known or foreseeable circumstance, related to the use of the product with digital elements in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to significant cybersecurity risks; |
6. | where applicable, the internet address at which the EU declaration of conformity can be accessed; |
7. | the type of technical security support offered by the manufacturer and the end-date of the support period during which users can expect vulnerabilities to be handled and to receive security updates; |
8. | detailed instructions or an internet address referring to such detailed instructions and information on:
|
9. | If the manufacturer decides to make available the software bill of materials to the user, information on where the software bill of materials can be accessed. |
ANNEX III
IMPORTANT PRODUCTS WITH DIGITAL ELEMENTS
Class I
1. | Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers |
2. | Standalone and embedded browsers |
3. | Password managers |
4. | Software that searches for, removes, or quarantines malicious software |
5. | Products with digital elements with the function of virtual private network (VPN) |
6. | Network management systems |
7. | Security information and event management (SIEM) systems |
8. | Boot managers |
9. | Public key infrastructure and digital certificate issuance software |
10. | Physical and virtual network interfaces |
11. | Operating systems |
12. | Routers, modems intended for the connection to the internet, and switches |
13. | Microprocessors with security-related functionalities |
14. | Microcontrollers with security-related functionalities |
15. | Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalities |
16. | Smart home general purpose virtual assistants |
17. | Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems |
18. | Internet connected toys covered by Directive 2009/48/EC of the European Parliament and of the Council (1) that have social interactive features (e.g. speaking or filming) or that have location tracking features |
19. | Personal wearable products to be worn or placed on a human body that have a health monitoring (such as tracking) purpose and to which Regulation (EU) 2017/745 or (EU) No 2017/746 do not apply, or personal wearable products that are intended for the use by and for children |
Class II
1. | Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments |
2. | Firewalls, intrusion detection and prevention systems |
3. | Tamper-resistant microprocessors |
4. | Tamper-resistant microcontrollers |
(1) Directive 2009/48/EC of the European Parliament and of the Council of 18 June 2009 on the safety of toys (OJ L 170, 30.6.2009, p. 1).
ANNEX IV
CRITICAL PRODUCTS WITH DIGITAL ELEMENTS
1.
Hardware Devices with Security Boxes
2.
Smart meter gateways within smart metering systems as defined in Article 2, point (23) of Directive (EU) 2019/944 of the European Parliament and of the Council (1) and other devices for advanced security purposes, including for secure cryptoprocessing
3.
Smartcards or similar devices, including secure elements
(1) Directive (EU) 2019/944 of the European Parliament and of the Council of 5 June 2019 on common rules for the internal market for electricity and amending Directive 2012/27/EU (OJ L 158, 14.6.2019, p. 125).
ANNEX V
EU DECLARATION OF CONFORMITY
The EU declaration of conformity referred to in Article 28, shall contain all of the following information:
1. | Name and type and any additional information enabling the unique identification of the product with digital elements |
2. | Name and address of the manufacturer or its authorised representative |
3. | A statement that the EU declaration of conformity is issued under the sole responsibility of the provider |
4. | Object of the declaration (identification of the product with digital elements allowing traceability, which may include a photograph, where appropriate) |
5. | A statement that the object of the declaration described above is in conformity with the relevant Union harmonisation legislation |
6. | References to any relevant harmonised standards used or any other common specification or cybersecurity certification in relation to which conformity is declared |
7. | Where applicable, the name and number of the notified body, a description of the conformity assessment procedure performed and identification of the certificate issued |
8. | Additional information: Signed for and on behalf of: (place and date of issue): (name, function) (signature): |
ANNEX VI
SIMPLIFIED EU DECLARATION OF CONFORMITY
The simplified EU declaration of conformity referred to in Article 13(20) shall be provided as follows:
Hereby, … [name of manufacturer] declares that the product with digital elements type … [designation of type of product with digital element] is in compliance with Regulation (EU) 2024/2847 (1).
The full text of the EU declaration of conformity is available at the following internet address: …
(1) OJ L, 2024/2847, 20.11.2024, ELI: http://data.europa.eu/eli/reg/2024/2847/oj.
ANNEX VII
CONTENT OF THE TECHNICAL DOCUMENTATION
The technical documentation referred to in Article 31 shall contain at least the following information, as applicable to the relevant product with digital elements:
1. | a general description of the product with digital elements, including:
|
2. | a description of the design, development and production of the product with digital elements and vulnerability handling processes, including:
|
3. | an assessment of the cybersecurity risks against which the product with digital elements is designed, developed, produced, delivered and maintained pursuant to Article 13, including how the essential cybersecurity requirements set out in Part I of Annex I are applicable; |
4. | relevant information that was taken into account to determine the support period pursuant to Article 13(8) of the product with digital elements; |
5. | a list of the harmonised standards applied in full or in part the references of which have been published in the Official Journal of the European Union, common specifications as set out in Article 27 of this Regulation or European cybersecurity certification schemes adopted pursuant to Regulation (EU) 2019/881 pursuant to Article 27(8) of this Regulation, and, where those harmonised standards, common specifications or European cybersecurity certification schemes have not been applied, descriptions of the solutions adopted to meet the essential cybersecurity requirements set out in Parts I and II of Annex I, including a list of other relevant technical specifications applied. In the event of partly applied harmonised standards, common specifications or European cybersecurity certification schemes, the technical documentation shall specify the parts which have been applied; |
6. | reports of the tests carried out to verify the conformity of the product with digital elements and of the vulnerability handling processes with the applicable essential cybersecurity requirements as set out in Parts I and II of Annex I; |
7. | a copy of the EU declaration of conformity; |
8. | where applicable, the software bill of materials, further to a reasoned request from a market surveillance authority provided that it is necessary in order for that authority to be able to check compliance with the essential cybersecurity requirements set out in Annex I. |
ANNEX VIII
CONFORMITY ASSESSMENT PROCEDURES
Part I Conformity assessment procedure based on internal control (based on module A)
1. | Internal control is the conformity assessment procedure whereby the manufacturer fulfils the obligations set out in points 2, 3 and 4 of this Part, and ensures and declares on its sole responsibility that the products with digital elements satisfy all the essential cybersecurity requirements set out in Part I of Annex I and the manufacturer meets the essential cybersecurity requirements set out in Part II of Annex I. |
2. | The manufacturer shall draw up the technical documentation described in Annex VII. |
3. | Design, development, production and vulnerability handling of products with digital elements The manufacturer shall take all measures necessary so that the design, development, production and vulnerability handling processes and their monitoring ensure compliance of the manufactured or developed products with digital elements and of the processes put in place by the manufacturer with the essential cybersecurity requirements set out in Parts I and II of Annex I. |
4. | Conformity marking and declaration of conformity
|
5. | Authorised representatives The manufacturer’s obligations set out in point 4 may be fulfilled by its authorised representative, on its behalf and under its responsibility, provided that the relevant obligations are specified in the mandate. |
Part II EU-type examination (based on module B)
1. | EU-type examination is the part of a conformity assessment procedure in which a notified body examines the technical design and development of a product with digital elements and the vulnerability handling processes put in place by the manufacturer, and attests that a product with digital elements meets the essential cybersecurity requirements set out in Part I of Annex I and that the manufacturer meets the essential cybersecurity requirements set out in Part II of Annex I. |
2. | EU-type examination shall be carried out by assessing the adequacy of the technical design and development of the product with digital elements through the examination of the technical documentation and supporting evidence referred to in point 3, and the examination of specimens of one or more critical parts of the product (combination of production type and design type). |
3. | The manufacturer shall lodge an application for EU-type examination with a single notified body of its choice. The application shall include:
|
4. | The notified body shall:
|
5. | The notified body shall draw up an evaluation report that records the activities undertaken in accordance with point 4 and their outcomes. Without prejudice to its obligations vis-à-vis the notifying authorities, the notified body shall release the content of that report, in full or in part, only with the agreement of the manufacturer. |
6. | Where the type and the vulnerability handling processes meet the essential cybersecurity requirements set out in Annex I, the notified body shall issue an EU-type examination certificate to the manufacturer. The certificate shall contain the name and address of the manufacturer, the conclusions of the examination, the conditions (if any) for its validity and the necessary data for identification of the approved type and vulnerability handling processes. The certificate may have one or more annexes attached. The certificate and its annexes shall contain all relevant information to allow the conformity of manufactured or developed products with digital elements with the examined type and vulnerability handling processes to be evaluated and to allow for in-service control. Where the type and the vulnerability handling processes do not satisfy the applicable essential cybersecurity requirements set out in Annex I, the notified body shall refuse to issue an EU-type examination certificate and shall inform the applicant accordingly, giving detailed reasons for its refusal. |
7. | The notified body shall keep itself apprised of any changes in the generally acknowledged state of the art which indicate that the approved type and the vulnerability handling processes may no longer comply with the applicable essential cybersecurity requirements set out in Annex I, and shall determine whether such changes require further investigation. If so, the notified body shall inform the manufacturer accordingly. The manufacturer shall inform the notified body that holds the technical documentation relating to the EU-type examination certificate of all modifications to the approved type and the vulnerability handling processes that may affect the conformity with the essential cybersecurity requirements set out in Annex I, or the conditions for validity of the certificate. Such modifications shall require additional approval in the form of an addition to the original EU-type examination certificate. |
8. | The notified body shall carry out periodic audits to ensure that the vulnerability handling processes as set out in Part II of Annex I are implemented adequately. |
9. | Each notified body shall inform its notifying authorities concerning the EU-type examination certificates and any additions thereto which it has issued or withdrawn, and shall, periodically or upon request, make available to its notifying authorities the list of certificates and any additions thereto refused, suspended or otherwise restricted. Each notified body shall inform the other notified bodies concerning the EU-type examination certificates and any additions thereto which it has refused, withdrawn, suspended or otherwise restricted, and, upon request, concerning the certificates and additions thereto which it has issued. The Commission, the Member States and the other notified bodies may, on request, obtain a copy of the EU-type examination certificates and any additions thereto. On request, the Commission and the Member States may obtain a copy of the technical documentation and the results of the examinations carried out by the notified body. The notified body shall keep a copy of the EU-type examination certificate, its annexes and additions, as well as the technical file including the documentation submitted by the manufacturer, until the expiry of the validity of the certificate. |
10. | The manufacturer shall keep a copy of the EU-type examination certificate, its annexes and additions together with the technical documentation at the disposal of the national authorities for 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer. |
11. | The manufacturer’s authorised representative may lodge the application referred to in point 3 and fulfil the obligations set out in points 7 and 10, provided that the relevant obligations are specified in the mandate. |
Part III Conformity to type based on internal production control (based on module C)
1. | Conformity to type based on internal production control is the part of a conformity assessment procedure whereby the manufacturer fulfils the obligations set out in points 2 and 3 of this Part, and ensures and declares that the products with digital elements concerned are in conformity with the type described in the EU-type examination certificate and satisfy the essential cybersecurity requirements set out in Part I of Annex I and that the manufacturer meets the essential cybersecurity requirements set out in Part II of Annex I. |
2. | Production The manufacturer shall take all measures necessary so that the production and its monitoring ensure conformity of the manufactured products with digital elements with the approved type described in the EU-type examination certificate and with the essential cybersecurity requirements as set out in Part I of Annex I and ensures that the manufacturer meets the essential cybersecurity requirements set out in Part II of Annex I. |
3. | Conformity marking and declaration of conformity
|
4. | Authorised representative The manufacturer’s obligations set out in point 3 may be fulfilled by its authorised representative, on its behalf and under its responsibility, provided that the relevant obligations are specified in the mandate. |
Part IV Conformity based on full quality assurance (based on module H)
1. | Conformity based on full quality assurance is the conformity assessment procedure whereby the manufacturer fulfils the obligations set out in points 2 and 5 of this Part, and ensures and declares on its sole responsibility that the products with digital elements or product categories concerned satisfy the essential cybersecurity requirements set out in Part I of Annex I and that the vulnerability handling processes put in place by the manufacturer meet the requirements set out in Part II of Annex I. |
2. | Design, development, production and vulnerability handling of products with digital elements The manufacturer shall operate an approved quality system as specified in point 3 for the design, development and final product inspection and testing of the products with digital elements concerned and for handling vulnerabilities, maintain its effectiveness throughout the support period, and shall be subject to surveillance as specified in point 4. |
3. | Quality system
|
4. | Surveillance under the responsibility of the notified body
|
5. | Conformity marking and declaration of conformity
|
6. | The manufacturer shall, for a period ending at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer, keep at the disposal of the national authorities:
|
7. | Each notified body shall inform its notifying authorities of quality system approvals issued or withdrawn, and shall, periodically or upon request, make available to its notifying authorities the list of quality system approvals refused, suspended or otherwise restricted. Each notified body shall inform the other notified bodies of quality system approvals which it has refused, suspended or withdrawn, and, upon request, of quality system approvals which it has issued. |
8. | Authorised representative The manufacturer’s obligations set out in points 3.1, 3.5, 5 and 6 may be fulfilled by its authorised representative, on its behalf and under its responsibility, provided that the relevant obligations are specified in the mandate. |
A statement has been made with regard to this act and can be found in OJ C, 2024/6786, 20.11.2024, ELI: http://data.europa.eu/eli/C/2024/6786/oj.
ELI: http://data.europa.eu/eli/reg/2024/2847/oj
ISSN 1977-0677 (electronic edition)