Data & Privacy
AI & Trust
Cybersecurity
Digital Services & Media
CHAPTER I
GENERAL PROVISIONSArticles 1 — 12
CHAPTER II
OBLIGATIONS OF ECONOMIC OPERATORS AND PROVISIONS IN RELATION TO FREE AND OPEN-SOURCE SOFTWAREArticles 13 — 26
CHAPTER III
CONFORMITY OF THE PRODUCT WITH DIGITAL ELEMENTSArticles 27 — 34
CHAPTER IV
NOTIFICATION OF CONFORMITY ASSESSMENT BODIESArticles 35 — 51
CHAPTER V
MARKET SURVEILLANCE AND ENFORCEMENTArticles 52 — 60
CHAPTER VI
DELEGATED POWERS AND COMMITTEE PROCEDUREArticles 61 — 62
CHAPTER VII
CONFIDENTIALITY AND PENALTIESArticles 63 — 65
CHAPTER VIII
TRANSITIONAL AND FINAL PROVISIONSArticles 66 — 71
ANNEXES
Class I
Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers
Standalone and embedded browsers
Password managers
Software that searches for, removes, or quarantines malicious software
Products with digital elements with the function of virtual private network (VPN)
Network management systems
Security information and event management (SIEM) systems
Boot managers
Public key infrastructure and digital certificate issuance software
Physical and virtual network interfaces
Operating systems
Routers, modems intended for the connection to the internet, and switches
Microprocessors with security-related functionalities
Microcontrollers with security-related functionalities
Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalities
Smart home general purpose virtual assistants
Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems
Internet connected toys covered by Directive 2009/48/EC of the European Parliament and of the Council that have social interactive features (e.g. speaking or filming) or that have location tracking features
Personal wearable products to be worn or placed on a human body that have a health monitoring (such as tracking) purpose and to which Regulation (EU) 2017/745 or (EU) No 2017/746 do not apply, or personal wearable products that are intended for the use by and for children
Class II
Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments
Firewalls, intrusion detection and prevention systems
Tamper-resistant microprocessors
Tamper-resistant microcontrollers