Recital 38 + Article 10(f) make clear that a cybersecurity defect that compromises the safety of a product is a 'defect' for PLD purposes. A product with digital elements that fails to receive necessary security updates - where the manufacturer is required to provide such updates under EU law (notably the CRA Annex I Part 2 essential vulnerability handling requirements) - and the failure causes safety damage, is a defective product. This creates a direct civil-liability hook for cybersecurity-as-safety: the absence of patches that the manufacturer ought to have supplied is a PLD defect even though the cyber-physical failure occurred years post-market. The 10-year long-stop runs from initial placement-on-market but cybersecurity-related substantial modifications or software updates that introduce defects can trigger a fresh modifier-liability long-stop under Article 16(3) + Article 4(18). Coordination: CRA imposes essential cybersecurity requirements + vulnerability handling for products with digital elements but does not create civil-liability rights; PLD provides the civil-liability pathway. GPSR Article 6 also recognises cybersecurity as a safety criterion for assessment.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.