IN BRIEF
Use this checklist to organise work and identify open questions. Checking every item does not establish legal compliance.
01 / 03
Scope and ownership
- Describe the product, functions, connections and market route.
- Identify manufacturer, importer and distributor roles.
- Assess applicable exclusions and product category with legal review where needed.
02 / 03
Design and evidence
- Document cybersecurity risk assessment.
- Map Annex I requirements to design and verification evidence.
- Track components, vulnerabilities, updates and the support period.
- Prepare technical documentation, user information and conformity records.
03 / 03
Operate and revisit
- Establish vulnerability intake and response ownership.
- Prepare for applicable Article 14 notifications.
- Review the product file as versions and risks change.
REFERENCE DESK
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.
Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.