EU Cyber Resilience Act
Placing on the market, classification and conformity routes – EU Cyber Resilience Act

EU Cyber Resilience Act Art. 8(1): Critical products and European cybersecurity certification

For products whose core functionality matches an Annex IV category, the Commission may require by delegated act a European cybersecurity certificate at assurance level at least substantial under a scheme adopted under Regulation (EU) 2019/881. Until such an act applies, a critical product must use one of the third-party routes of Article 32(3). The delegated act gives at least six months of transition.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Placing on the market, classification and conformity routes – EU Cyber Resilience Act

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.