EU Product Liability Directive (Directive (EU) 2024/2853)
PLD: Software, AI and Cybersecurity Defect Coordination

EU Product Liability Directive (Directive (EU) 2024/2853) PLD-Art.10-Cyber: Cybersecurity-related defect (PLD Article 10(f) + Recital 38) - coordination with CRA + GPSR

Recital 38 + Article 10(f) make clear that a cybersecurity defect that compromises the safety of a product is a 'defect' for PLD purposes. A product with digital elements that fails to receive necessary security updates - where the manufacturer is required to provide such updates under EU law (notably the CRA Annex I Part 2 essential vulnerability handling requirements) - and the failure causes safety damage, is a defective product. This creates a direct civil-liability hook for cybersecurity-as-safety: the absence of patches that the manufacturer ought to have supplied is a PLD defect even though the cyber-physical failure occurred years post-market. The 10-year long-stop runs from initial placement-on-market but cybersecurity-related substantial modifications or software updates that introduce defects can trigger a fresh modifier-liability long-stop under Article 16(3) + Article 4(18). Coordination: CRA imposes essential cybersecurity requirements + vulnerability handling for products with digital elements but does not create civil-liability rights; PLD provides the civil-liability pathway. GPSR Article 6 also recognises cybersecurity as a safety criterion for assessment.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CRA-Art.13_AnnexI Manufacturer obligations and essential requirements (Article 13 + Annex I)
  • CRA-Art.14_16 Reporting obligations and the single reporting platform (Articles 14 and 16)
  • GPSR-Art.5_6_7_8 General safety requirement and assessment criteria (Articles 5-8)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PLD: Software, AI and Cybersecurity Defect Coordination

Query this from an agent

The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.