REGULATION (EU) 2024/2847 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL | 32024R2847 — European Union law | Esheria

REGULATION (EU) 2024/2847 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

This segment says manufacturers, Member States, and the Commission have several cybersecurity-related responsibilities and powers, including designing secure products, providing guidance, and supporting surveillance and skills.

AI-assisted research synopsis — verify against the official legal text below.

Jurisdiction
European Union
Instrument
Regulation
Citation
32024R2847
Status
In force
Version
Undated source snapshot
Language
en
Official source
View official record ↗
CE marking SME support certification compliance guidance conformity assessment consumer protection documentation fines incident notification incident reporting manufacturing market controls market surveillance notified bodies notified body procedures penalties product compliance product security quality system reporting software components software updates technical documentation technical standards +2 more

Publicly available, excluded from search-engine indexing

This page remains available for direct access and API use, but this release emits noindex,follow for the following reason:

  • The record does not meet this release's canonical indexing criteria. (market-indexing-disabled)

Statute overview

About this statute

This segment says manufacturers, Member States, and the Commission have several cybersecurity-related responsibilities and powers, including designing secure products, providing guidance, and supporting surveillance and skills. Manufacturers of products with digital elements must keep products secure over the support period, provide updates and vulnerability handling, notify incidents, and maintain disclosure and contact processes. This provision explains how cybersecurity conformity can be shown for products with digital elements, and what Member States, manufacturers, the Commission, market surveillance authorities, and ENISA may or must do. This Regulation sets cybersecurity rules for products with digital elements, including manufacturer obligations, market access conditions, and vulnerability reporting duties. Manufacturers must report severe incidents and notify users; ENISA and CSIRTs handle platform operation, dissemination, and support.