Cyber Resilience Act

Union harmonisation legislation

Legal definition Art. 3(32) CRA

“Union legislation listed in Annex I to Regulation (EU) 2019/1020 and any other Union legislation harmonising the conditions for the marketing of products to which that Regulation applies”
Regulation (EU) 2024/2847, Art. 3(32) CRA

Union harmonisation legislation is the collective name for those EU legal acts that set the conditions under which a product may be marketed in the Union. The Cyber Resilience Act (CRA) does not invent the term in Article 3, point (32). It borrows it from the body of product law it is joining.

The definition comes in two halves. The first points to a list, namely Annex I to Regulation (EU) 2019/1020, which enumerates the acts concerned one by one. The second is a catch-all for any other Union legislation harmonising the conditions for the marketing of products to which Regulation (EU) 2019/1020 applies. The term is therefore not frozen at its 2019 state.

What the list contains

Annex I to Regulation (EU) 2019/1020 is long and old. It opens with a 1969 directive on crystal glass and now runs to more than seventy legal acts. For products with digital elements the ones that matter most are:

  • Directive 2014/53/EU on radio equipment
  • Directive 2014/30/EU on electromagnetic compatibility
  • Directive 2014/35/EU on electrical equipment designed for use within certain voltage limits
  • Directive 2006/42/EC on machinery
  • Directive 2009/48/EC on the safety of toys
  • Regulation (EU) 2017/745 on medical devices

That lineage explains why the CRA does not invent its own machinery. Conformity assessment, the declaration of conformity, CE marking and market surveillance have been practised in this body of law for decades, and the CRA builds on them.

The CRA is on the list itself

Article 66 adds a point 72 to Annex I of Regulation (EU) 2019/1020: Regulation (EU) 2024/2847, which is the CRA. Two things follow. Regulation (EU) 2019/1020 applies to products with digital elements that fall within the scope of the CRA, as Article 52(1) states again in so many words. And the CRA is from now on included wherever another legal act fixes the term by reference to Annex I to Regulation (EU) 2019/1020.

Where the term bites in the CRA

In several places it decides how far a rule reaches:

  • CE marking. Article 3, point (31), defines it as a marking by which the manufacturer indicates that the product and the manufacturer’s processes conform to the essential cybersecurity requirements set out in Annex I and to other applicable Union harmonisation legislation providing for its affixing. Article 30(5) draws the consequence. Where the product is also covered by other such legislation that likewise provides for CE marking, the single mark indicates that those requirements are met too.
  • Notified bodies. Under Article 3, point (29), a notified body is a conformity assessment body designated under Article 43 of the CRA and other relevant Union harmonisation legislation. Article 39(7), point (c), requires its personnel to know that legislation.
  • Market surveillance. Under Article 52(6) the market surveillance authority cooperates, where relevant, with other market surveillance authorities designated for other products on the basis of Union harmonisation legislation other than the CRA, and exchanges information with them regularly.
  • Legacy certificates. Under Article 69(1), EU type-examination certificates and approval decisions issued regarding cybersecurity requirements for products subject to other Union harmonisation legislation stay valid until 11 June 2028, unless they expire earlier or that other legislation provides otherwise.
  • Test software. Article 4(3) permits unfinished software to be made available for a limited period for testing. Article 4(4) carves out safety components as referred to in Union harmonisation legislation other than the CRA.
  • Guidance. Under Article 26(2), point (c), the Commission must address in its guidance manufacturers who are subject to the CRA and at the same time to other Union harmonisation legislation or to other related Union legal acts.

The term also works indirectly, through standardisation. A harmonised standard is by definition a European standard produced at the Commission’s request for the application of Union harmonisation legislation. It carries the main route to the presumption of conformity under Article 27(1); Article 27(5) and Article 27(8) open the same route through common specifications and through European cybersecurity certification schemes.

One declaration for all the acts

The most useful provision in day-to-day terms is Article 28(3). Where a product is subject to more than one Union legal act each requiring an EU declaration of conformity, a single declaration is drawn up for all of them, and it must identify the acts concerned together with their publication references. Recital 88 makes clear that this single declaration may take the form of a dossier assembled from the individual declarations.

Not every EU legal act qualifies

What counts is the purpose. Union harmonisation legislation regulates the conditions for marketing products. Acts that regulate the duties of entities, or the processing of data, do not qualify even where they deal with cybersecurity. Consistently with that, the NIS2 Directive does not appear in Annex I to Regulation (EU) 2019/1020.

The converse also holds: being on the list does not mean the CRA applies alongside. Article 2(2), points (a) and (b), removes from the scope, entirely, products to which Regulation (EU) 2017/745 on medical devices and Regulation (EU) 2017/746 on in vitro diagnostics apply, and Article 2(4) does the same for equipment within the scope of Directive 2014/90/EU on marine equipment. All three are themselves listed in Annex I to Regulation (EU) 2019/1020.

The trap in Article 11

Article 11 uses the same words in a different sense. It puts “Union harmonisation legislation” in quotation marks and refers, for that phrase, to Article 3, point (27), of Regulation (EU) 2023/988 on general product safety rather than to Article 3, point (32), of the CRA. Anyone working out how far the general product safety rules remain applicable alongside the CRA has to look the definition up there.

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.