Cyber Resilience Act
Intended purpose
Legal definition Art. 3(23) CRA
“the use for which a product with digital elements is intended by the manufacturer, including the specific context and conditions of use, as specified in the information supplied by the manufacturer in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation”
Intended purpose is the use a manufacturer has envisaged for a product with digital elements. The Cyber Resilience Act (CRA) defines it in Article 3, point (23), which makes it a legal reference point rather than a product description. Scope, risk assessment and the reach of a manufacturer’s obligations all take their bearings from it.
The manufacturer sets it, but not freely. The definition names the sources it follows from: the instructions for use, promotional or sales materials and statements, and the technical documentation. It also covers the specific context and conditions of use. Intended purpose therefore captures not only what the product does, but the environment and the conditions under which it is meant to do it.
Scope turns on it
Under Article 2(1), the CRA applies to products with digital elements made available on the market whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network.
The word carrying the weight is “or”. A data connection inherent in the foreseeable use is enough on its own. A device that ships with an interface is therefore in scope even where the documentation says nothing about it.
It shapes the risk assessment
Article 13(2) requires manufacturers to carry out a cybersecurity risk assessment and to take its outcome into account in the planning, design, development, production, delivery and maintenance phases. Article 13(3) fixes what that assessment must contain at minimum: an analysis of cybersecurity risks based on the intended purpose and reasonably foreseeable use, such as the operational environment or the assets to be protected, taking into account how long the product is expected to be in use.
More than a document depends on this. The security requirements in Annex I, Part I, point (2)(a) to (m) apply only “where applicable”, and what applies follows from that assessment. Intended purpose therefore decides indirectly which of the Essential cybersecurity requirements a product has to meet. Where one of them does not apply, Article 13(4) requires a clear justification in the Technical documentation.
In one place the effect is direct: Annex I, Part I, point (2)(g) limits data processing to what is necessary in relation to the intended purpose. Read the other way round, recital 55 names limiting the intended purpose to trusted environments as one way of addressing a risk that cannot be absorbed technically.
Three notions that belong together
Article 3 distinguishes three kinds of use, and obligations reach past the first:
- Intended purpose (point (23)) is the use the manufacturer states.
- Reasonably foreseeable use (point (24)) need not match it, but is likely to result from foreseeable human behaviour, from technical operations or from interactions.
- Reasonably foreseeable misuse (point (25)) is not in accordance with the intended purpose, yet may result from foreseeable behaviour or from interaction with other systems.
Article 6, point (a) allows a product to be made available on the market only where it meets the requirements in Annex I, Part I, provided that it is properly installed, maintained and used for its intended purpose or under conditions which can reasonably be foreseen, and that, where applicable, the necessary security updates have been installed. A narrowly drawn intended purpose therefore does not shrink responsibility down to itself.
Where it has to be written down
Intended purpose reappears at three points that belong to market access:
- Annex II, point (4) requires it to be communicated to users, together with the security environment provided by the manufacturer, the product’s essential functionalities and information about its security properties.
- Annex II, point (5) adds any known or foreseeable circumstance tied to use in accordance with the intended purpose or to reasonably foreseeable misuse that may lead to a Significant cybersecurity risk.
- Annex VII, point (1)(a) requires it as part of the general product description in the technical documentation.
Two further provisions fall back on it. Under Article 13(8), the support period must be set with regard to the nature of the product, including its intended purpose. And where the Commission mandates certification for critical products under Article 8(1), the assurance level it requires must take account of the intended purpose, including the critical dependency of essential entities under the NIS-2 Directive on those products.
Changing it is a threshold
Under Article 3, point (30), a Substantial modification is a change to the product after it has been placed on the market that affects compliance with the requirements in Annex I, Part I or results in a modification to the intended purpose for which the product has been assessed. A change of purpose therefore stands on equal footing with a technical deviation. Note the reference point: the purpose the product was assessed against, not the one currently advertised.
Recital 41 considers it appropriate in that case that conformity is verified and that, where applicable, the product undergoes a new conformity assessment. Where a third party was involved in the conformity assessment, the same recital says any change that might lead to a substantial modification should be notified to it. Article 22 goes further: anyone other than the manufacturer, importer or distributor who carries out a substantial modification and makes the product available is treated as a Manufacturer. That covers the part of the product affected by the modification, or the entire product where the modification bears on its cybersecurity as a whole.
Practical questions
-
Yes, and not merely as a matter of diligence. Article 3, point (23) lists promotional or sales materials and statements among the sources the intended purpose follows from. If a brochure promises a deployment the risk assessment does not cover, that deployment becomes part of the intended purpose and the assessment is incomplete. In practice, one agreed wording used by product management, documentation and sales is the cheapest way to keep them aligned.
-
It depends on how close to hand the deviating use is. A use resulting from reasonably foreseeable behaviour or from technical interactions belongs in the risk assessment under Article 13(3), even though it is not the intended purpose. For reasonably foreseeable misuse, Annex II, point (5) requires you to inform users about the significant cybersecurity risks it may create. A use nobody could have anticipated falls outside. Where exactly that line runs, the CRA does not say.
-
Not every one does. Recital 39 of the CRA expressly treats a Security update that lowers cybersecurity risk without modifying the intended purpose as something other than a substantial modification. The same normally goes for minor changes such as a visual enhancement, a new interface language or new pictograms. A feature update that modifies the originally intended functions or the type or performance of the product, and that was not foreseen in the initial risk assessment, is a substantial modification. Whether it ships on its own or bundled with a security update makes no difference.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.