Chapter IIOBLIGATIONS OF ECONOMIC OPERATORS AND PROVISIONS IN RELATION TO FREE AND OPEN-SOURCE SOFTWARE
- Article 13Obligations of manufacturers
1. When placing a product with digital elements on the market, manufacturers shall ensure that it has been designed, developed and produced in accordance with the essential cybersecurity…
- Article 14Reporting obligations of manufacturers
1. A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator,…
- Article 15Voluntary reporting
1. Manufacturers as well as other natural or legal persons may notify any vulnerability contained in a product with digital elements as well as cyber threats that could…
- Article 16Establishment of a single reporting platform
1. For the purposes of the notifications referred to in Article 14(1) and (3) and Article 15(1) and (2) and in order to simplify the reporting obligations of…
- Article 17Other provisions related to reporting
1. ENISA may submit to the European cyber crisis liaison organisation network (EU-CyCLONe) established under Article 16 of Directive (EU) 2022/2555 information notified pursuant to Article 14(1) and…
- Article 18Authorised representatives
1. A manufacturer may, by a written mandate, appoint an authorised representative. 2. The obligations laid down in Article 13(1) to (11) , Article 13(12) , first subparagraph,…
- Article 19Obligations of importers
1. Importers shall place on the market only products with digital elements that comply with the essential cybersecurity requirements set out in Part I of Annex I and…
- Article 20Obligations of distributors
1. When making a product with digital elements available on the market, distributors shall act with due care in relation to the requirements set out in this Regulation.…
- Article 21Cases in which obligations of manufacturers apply to importers and distributors
An importer or distributor shall be considered to be a manufacturer for the purposes of this Regulation and shall be subject to Articles 13 and 14 , where…
- Article 22Other cases in which obligations of manufacturers apply
1. A natural or legal person, other than the manufacturer, the importer or the distributor, that carries out a substantial modification of a product with digital elements and…
- Article 23Identification of economic operators
1. Economic operators shall, on request, provide the market surveillance authorities with the following information: (a) the name and address of any economic operator who has supplied them…
- Article 24Obligations of open-source software stewards
1. Open-source software stewards shall put in place and document in a verifiable manner a cybersecurity policy to foster the development of a secure product with digital elements…
- Article 25Security attestation of free and open-source software
In order to facilitate the due diligence obligation set out in Article 13(5) , in particular as regards manufacturers that integrate free and open-source software components in their…
- Article 26Guidance
1. In order to facilitate implementation and ensure the consistency of such implementation, the Commission shall publish guidance to assist economic operators in applying this Regulation, with a…
https://cra.digiphile.law/chapter/chapter-II.html
Text as at 19 September 2026.
This is an unofficial convenience version of the EU Cyber Resilience Act (Regulation (EU) 2024/2847). It is presented “as is” without guarantee of accuracy, completeness or reliability. See the source text for the official version. This site was last updated in September 2026.