Glossary
Cyber Resilience Act glossary
Reviewed August 2026 against Regulation (EU) 2024/2847, OJ L, 12.12.2024.
Thirty terms used across the Cybiq FAQ, the timeline and the wizard. Each entry states where the Regulation defines the term and quotes the definition word-for-word from the Official Journal; where the Regulation does not define a term but uses it, the entry says what the text does say.
Actively exploited vulnerability
A vulnerability for which there is reliable evidence that a malicious actor has already exploited it without permission. This is the trigger category for Article 14 reporting.
“a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner”
Annex III (important products)
The list of important products with digital elements, from password managers and browsers through operating systems and network equipment to smart home security devices, connected toys and health wearables. Class I items keep conditional self-assessment; Class II items require third-party assessment.
“IMPORTANT PRODUCTS WITH DIGITAL ELEMENTS”
“Password managers”
“Operating systems”
Annex IV (critical products)
The list of critical products with digital elements: hardware devices with security boxes, smart meter gateways within smart metering systems, and smartcards or similar devices including secure elements. These categories face the strictest conformity route.
“CRITICAL PRODUCTS WITH DIGITAL ELEMENTS”
“Smartcards or similar devices, including secure elements”
CE marking
The marking by which a manufacturer indicates that a product with digital elements, and the processes behind it, conform with the essential cybersecurity requirements. For software it is affixed to the EU declaration of conformity or the accompanying website rather than to the product itself.
“a marking by which a manufacturer indicates that a product with digital elements and the processes put in place by the manufacturer are in conformity with the essential cybersecurity requirements set out in Annex I and other applicable Union harmonisation legislation providing for its affixing”
“visibly, legibly and indelibly indicate their conformity”
Common specification
A technical specification established by the Commission through implementing acts as an alternative means to comply with the essential cybersecurity requirements, used where harmonised standards do not cover them. Applying common specifications in full keeps the Class I self-assessment route open.
“The Commission may adopt implementing acts establishing common specifications covering technical requirements that provide a means to comply with the essential cybersecurity requirements set out in Annex I for products with digital elements that fall within the scope of this Regulation.”
Conformity assessment
The process of verifying whether the essential cybersecurity requirements set out in Annex I have been fulfilled. The manufacturer performs it; its depth depends on the product’s class and route.
“the process of verifying whether the essential cybersecurity requirements set out in Annex I have been fulfilled”
“The manufacturer shall perform a conformity assessment of the product with digital elements and the processes put in place by the manufacturer to determine whether the essential cybersecurity requirements set out in Annex I are met.”
CSIRT designated as coordinator
A computer security incident response team designated as coordinator under the NIS 2 Directive. Manufacturers report actively exploited vulnerabilities and severe incidents to it simultaneously with ENISA.
“a CSIRT designated as coordinator pursuant to Article 12(1) of Directive (EU) 2022/2555”
“A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA.”
Distributor
A person in the supply chain, other than the manufacturer or importer, that makes a product available on the Union market without affecting its properties. Distributors owe due-care verification and pass-through notification duties.
“a natural or legal person in the supply chain, other than the manufacturer or the importer, that makes a product with digital elements available on the Union market without affecting its properties”
“act with due care in relation to the requirements set out in this Regulation”
Economic operator
The umbrella term for everyone carrying CRA obligations: the manufacturer, the authorised representative, the importer, the distributor, and any other person subject to obligations about manufacturing or making products available.
“the manufacturer, the authorised representative, the importer, the distributor, or other natural or legal person who is subject to obligations in relation to the manufacture of products with digital elements or to the making available of products with digital elements on the market in accordance with this Regulation”
ENISA
The European Union Agency for Cybersecurity. The CRA does not define ENISA; it uses the agency as a reporting recipient: manufacturers notify actively exploited vulnerabilities and severe incidents to the CSIRT designated as coordinator and to ENISA simultaneously.
“A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA.”
EU declaration of conformity
The document drawn up by the manufacturer stating that fulfilment of the applicable essential cybersecurity requirements has been demonstrated. Its model structure is set out in Annex V.
“The EU declaration of conformity shall be drawn up by manufacturers in accordance with Article 13(12) and state that the fulfilment of the applicable essential cybersecurity requirements set out in Annex I has been demonstrated.”
“EU DECLARATION OF CONFORMITY”
Free and open-source software
Software whose source code is openly shared under a licence providing all rights to make it freely accessible, usable, modifiable and redistributable. Contributing to such software without responsibility for it falls outside the CRA; supplying it commercially does not.
“software the source code of which is openly shared and which is made available under a free and open-source licence which provides for all rights to make it freely accessible, usable, modifiable and redistributable”
“does not apply to natural or legal persons who contribute with source code to products with digital elements qualifying as free and open-source software that are not under their responsibility”
Harmonised standard
A harmonised standard within the meaning of the Standardisation Regulation (EU) No 1025/2012: a standard adopted by the European standardisation organisations following a Commission request. The Regulation points at that definition rather than restating it, and applying harmonised standards in full keeps Class I self-assessment available.
“a harmonised standard as defined in Article 2, point (1)(c), of Regulation (EU) No 1025/2012”
Importer
A person established in the Union who places on the market a product bearing the name or trademark of a person established outside the Union. Importers verify compliance before placing products on the market and pass vulnerability information through to the manufacturer and, for significant risks, to authorities.
“a natural or legal person established in the Union who places on the market a product with digital elements that bears the name or trademark of a natural or legal person established outside the Union”
“place on the market only products with digital elements that comply with the essential cybersecurity requirements”
Making available on the market
Supplying a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge. Free supply within a commercial activity counts.
“the supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge”
Manufacturer
A person who develops or manufactures products with digital elements, or has them designed, developed or manufactured by others, and markets them under its name or trademark, whether for payment, monetisation or free of charge. Rebranding someone else’s product makes you the manufacturer.
“a natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge”
“An importer or distributor shall be considered to be a manufacturer for the purposes of this Regulation and shall be subject to Articles 13 and 14, where that importer or distributor places a product with digital elements on the market under its name or trademark or carries out a substantial modification of a product with digital elements already placed on the market.”
Market surveillance authority
A market surveillance authority within the meaning of Regulation (EU) 2019/1020: the national body that polices product rules in each Member State. Importers and distributors escalate significant cybersecurity risks to these authorities immediately.
“a market surveillance authority as defined in Article 3, point (4), of Regulation (EU) 2019/1020”
“where the product with digital elements presents a significant cybersecurity risk, importers shall immediately inform the market surveillance authorities of the Member States in which they have made the product with digital elements available on the market”
Module B+C
EU-type examination (module B) followed by conformity to type based on internal production control (module C). This third-party pair applies to Class II products and replaces self-assessment for Class I products where standards or common specifications are not applied in full.
“(a) the EU-type examination procedure (based on module B) set out in Annex VIII followed by conformity to EU-type based on internal production control (based on module C) set out in Annex VIII; or (b) a conformity assessment based on full quality assurance (based on module H)”
Module H
Conformity assessment based on full quality assurance: an alternative to module B+C wherever those third-party procedures apply under Article 32.
“(a) the EU-type examination procedure (based on module B) set out in Annex VIII followed by conformity to EU-type based on internal production control (based on module C) set out in Annex VIII; or (b) a conformity assessment based on full quality assurance (based on module H)”
Notified body
A conformity assessment body designated in accordance with Article 43 and other relevant Union harmonisation legislation. Products in Annex III Class II and Annex IV demonstrate conformity through procedures involving one.
“a conformity assessment body designated in accordance with Article 43 and other relevant Union harmonisation legislation”
“Where the product is an important product with digital elements that falls under class II as set out in Annex III, the manufacturer shall demonstrate conformity with the essential cybersecurity requirements set out in Annex I by using any of the following procedures”
Open-source software steward
A legal person, other than a manufacturer, that systematically supports the development of specific free and open-source products intended for commercial activities and ensures their viability. Stewards must maintain a verifiable cybersecurity policy.
“a legal person, other than a manufacturer, that has the purpose or objective of systematically providing support on a sustained basis for the development of specific products with digital elements, qualifying as free and open-source software and intended for commercial activities, and that ensures the viability of those products”
“Open-source software stewards shall put in place and document in a verifiable manner a cybersecurity policy to foster the development of a secure product with digital elements as well as an effective handling of vulnerabilities by the developers of that product.”
Placing on the market
The first making available of a product with digital elements on the Union market. A one-off trigger per product; later supplies and updates rest on other duties.
“the first making available of a product with digital elements on the Union market”
Product with digital elements
A software or hardware product and its remote data processing solutions, including software or hardware components placed on the market separately. This is the Regulation’s central object of regulation.
“a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately”
Remote data processing
Data processing at a distance whose software is designed and developed by the manufacturer or under its responsibility, and without which the product could not perform one of its functions. It belongs to the product definition itself.
“data processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the product with digital elements from performing one of its functions”
Software bill of materials (SBOM)
A formal record containing details and supply-chain relationships of the components included in the software elements of a product. Annex I requires one in a commonly used, machine-readable format covering at least the top-level dependencies.
“a formal record containing details and supply chain relationships of components included in the software elements of a product with digital elements”
“software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the products”
Severe incident
An incident having an impact on the security of the product that meets the severity threshold in Article 14(5), such as negatively affecting the product’s ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions (other limbs cover malicious code introduction). Severe incidents are reportable under Article 14.
“an incident having an impact on the security of the product with digital elements shall be considered to be severe where: (a) it negatively affects or is capable of negatively affecting the ability of a product with digital elements to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions”
Significant cybersecurity risk
A cybersecurity risk which, based on its technical characteristics, can be assumed to have a high likelihood of an incident leading to severe negative impact. It is the escalation trigger for importers and distributors towards market surveillance authorities.
“a cybersecurity risk which, based on its technical characteristics, can be assumed to have a high likelihood of an incident that could lead to a severe negative impact, including by causing considerable material or non-material loss or disruption”
Substantial modification
A change to the product after its placing on the market that affects its compliance with the essential cybersecurity requirements or changes the intended purpose it was assessed for. It reopens the obligations, including for products placed on the market before December 2027.
“a change to the product with digital elements following its placing on the market, which affects the compliance of the product with digital elements with the essential cybersecurity requirements set out in Part I of Annex I or which results in a modification to the intended purpose for which the product with digital elements has been assessed”
“Products with digital elements that have been placed on the market before 11 December 2027 shall be subject to the requirements set out in this Regulation only if, from that date, those products are subject to a substantial modification.”
Support period
The period during which a manufacturer must ensure vulnerabilities are handled effectively and in accordance with the essential cybersecurity requirements: at least five years, or the expected use time where the product is expected to be in use for less.
“the period during which a manufacturer is required to ensure that vulnerabilities of a product with digital elements are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I”
“the support period shall be at least five years”
“Where the product with digital elements is expected to be in use for less than five years, the support period shall correspond to the expected use time.”
Technical documentation
The documentation demonstrating how the product and the manufacturer’s processes comply with the essential cybersecurity requirements, drawn up before placing on the market and kept up to date during the support period. Its content is set out in Annex VII (Annex V is the EU declaration of conformity template).
“The technical documentation shall be drawn up before the product with digital elements is placed on the market and shall be continuously updated, where appropriate, at least during the support period.”
“CONTENT OF THE TECHNICAL DOCUMENTATION”
Orientation, not legal advice. Quoted spans come from Regulation (EU) 2024/2847 as published in the Official Journal and are re-verified against the live text by automated tests. Verify before relying on any item; for a binding assessment consult a qualified lawyer.