Skip to content

Security1 publisher2 min readPublished

The Cyber Resilience Act counts the hosted backend as part of the product

Regulation (EU) 2024/2847 defines a product with digital elements to include the remote data processing its functions depend on, and it makes vulnerability handling an essential requirement for as long as the product is expected to be in use.

The Watch · Security desk

Illustration accompanying The Cyber Resilience Act counts the hosted backend as part of the product

What happened

  • EUR-Lex publishes the consolidated text of the Cyber Resilience Act as document 02024R2847-20241120, stamped version 000.003 and carrying a corrigendum notice.
  • Article 2 takes out of scope only those products with digital elements covered by Regulations (EU) 2017/745, (EU) 2017/746 and (EU) 2019/2144.
  • The Commission can limit or exclude application further by delegated act under Article 61, where sectoral rules reach the same or a higher level of protection.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure A hosted service a product function depends on falls inside the manufacturer's product, so the team operating it inherits product obligations it may have scoped as service operations.
  • constraint The expected-in-use period fixes the duration of the vulnerability handling duty, so a published support window now measures a legal obligation.
  • decision Component vendors shipping separately are placing their own product on the market, so supply agreements have to state which party carries the conformity work.
  • contradiction The version most teams will read declares itself a documentation tool with no legal effect, so any position that has to survive a regulator must be checked against the Official Journal text.

Article 3 turns on whether the product still works without the service. "Remote data processing" is defined as processing at a distance for which the software is designed and developed by the manufacturer, or under the manufacturer's responsibility. Its absence, the definition adds, "would prevent the product with digital elements from performing one of its functions" [13]. A product with digital elements is then defined to include those remote data processing solutions [12].

Components get the same treatment. Article 3 counts software or hardware components placed on the market separately as products with digital elements [12]. A library sold to integrators is a product in its own right. The supporting definitions are wide: software is "the part of an electronic information system which consists of computer code". Hardware is "a physical electronic information system, or parts thereof capable of processing, storing or transmitting digital data" [14].

Article 1 puts vulnerability handling on the same footing as design. It sets essential cybersecurity requirements for the design, development and production of products with digital elements [6]. Separately, it sets requirements for the vulnerability handling processes manufacturers put in place "during the time the products are expected to be in use" [7]. Article 1 also covers market surveillance, including monitoring, and enforcement [8].

The exits from scope are narrow. Three Union acts take a product out entirely: Regulations (EU) 2017/745, (EU) 2017/746 and (EU) 2019/2144 [9][18]. Past those, application can be limited or excluded only where the limitation is consistent with the overall regulatory framework for the products and the sectoral rules achieve the same or a higher level of protection [10]. The Commission decides that by delegated act under Article 61, specifying whether the limitation is necessary, the products and rules concerned, and the scope of the limitation [11].

One caution about the document itself. The consolidated version on EUR-Lex is 02024R2847-20241120, stamped 000.003 and headed "Corrected by:" [2], dated 28 days after the regulation was adopted on 23 October 2024 [1][17]. It says it "is meant purely as a documentation tool and has no legal effect". The authentic versions of the relevant acts, including their preambles, are those published in the Official Journal of the European Union [3][4]. The excerpt runs from Chapter I to Article 3 and stops part-way through the list of definitions [16]; the reporting duties and the application dates sit in later chapters of the same regulation.

What to watch

  • A delegated act under Article 61 naming products or sectoral rules the Commission limits or excludes from the Regulation.
  • A further corrigendum producing a consolidated version after 000.003, which would replace the reference text teams are reading.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories