Chapter I - GENERAL PROVISIONS
6

Article 6

Requirements for products with digital elements

Regulation (EU) 2024/2847 — published 10 December 2024 · Last reviewed by Kunnus: March 2026

Quick Answer for Manufacturers

Article 6 references the essential cybersecurity requirements set out in Annex I. Manufacturers must comply with these requirements throughout the product lifecycle — through risk assessment, secure development, and continuous vulnerability handling.

This quick answer + FAQ supplements the original legal text with practice-oriented interpretation. Only the original text is legally binding.

Products with digital elements shall be made available on the market only where:

a)

they meet the essential cybersecurity requirements set out in Part I of Annex I, provided that they are properly installed, maintained, used for their intended purpose or under conditions which can reasonably be foreseen, and, where applicable, the necessary security updates have been installed; and

b)

the processes put in place by the manufacturer comply with the essential cybersecurity requirements set out in Part II of Annex I.

Common Manufacturer Questions

What are the core requirements under Article 6 and Annex I?

Secure default configuration, protection against unauthorized access, confidentiality and integrity of data, availability of critical functions, minimization of attack surface, and a secure update mechanism. See Annex I for details.

Do all Annex I requirements apply to every product?

Not necessarily. If a requirement is not applicable to a specific product, the manufacturer must justify this in the cybersecurity risk assessment included in the technical documentation (see Recital 55).

What role does risk assessment play under Article 6?

It is both mandatory and a steering instrument: the manufacturer derives from the risk assessment which requirements apply and how they are implemented. The assessment itself is part of the technical documentation under Annex VII.

Related Recitals

(6)

CRA updates by email

Deadlines, official guidance, and myth-busting fact-checks on the Cyber Resilience Act — compact in our newsletter.

View newsletters

This text is reproduced from Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024. It is provided for informational purposes only and does not constitute legal advice. Only the text published in the Official Journal of the European Union is legally binding. Original text on EUR-Lex