From this date every product with digital elements placed on the EU market must meet the essential cybersecurity requirements (secure defaults, no known exploitable vulnerabilities, security updates for the support period, SBOM), pass a conformity assessment and carry CE marking. Importers and distributors must check compliance.
Who is affected
Manufacturers, importers and distributors of software and connected hardware sold in the EU, including small SaaS vendors that ship client software, IoT makers and app developers.
Sizes: micro, small, medium, large · Sectors: Software / SaaS, Hardware / electronics, Manufacturing · Applies if: We make connected hardware / devices; We sell online
What to do
Classify each product (default, important class I/II, or critical) to know whether self-assessment is enough. Implement a secure development lifecycle, vulnerability handling and update policy, and generate an SBOM. Prepare technical documentation, the EU declaration of conformity and user security information. Define the product's support period (at least 5 years by default).
Any manufacturer that sells software or connected hardware in the EU, including small software vendors and open-source projects run commercially. Non-commercial open source is largely exempt.