Skip to content
EU

EU Cybersecurity Rules: Technical Categories for Important and Critical Digital Products

The European Commission has adopted Implementing Regulation (EU) 2025/2392, which defines the technical descriptions of categories of important and critical products with digital elements under the Cyber Resilience Act (Regulation (EU) 2024/2847). This regulation aims to strengthen cybersecurity across the EU by clarifying which products require stricter conformity assessments and, in some cases, mandatory third-party certification.

Key Points

  • Scope of Regulation
    The rules apply to products with digital elements whose core functionality falls under categories listed in Annexes III and IV of the Cyber Resilience Act. These include operating systems, VPNs, routers, smart home devices, and more.

  • Important Products
    Examples include:

    • Identity management systems and privileged access management tools
    • Standalone and embedded browsers
    • Password managers
    • Antivirus and antimalware software
    • VPN clients and servers
    • Network management systems
    • Smart home assistants and security devices
  • Critical Products
    These require the highest level of security assurance and may need European cybersecurity certification. Examples include:

    • Hardware security modules
    • Smart meter gateways
    • Smartcards and secure elements
  • Compliance Requirements
    Manufacturers must:

    • Conduct comprehensive cybersecurity risk assessments
    • Implement essential cybersecurity requirements proportionate to risk
    • Follow specific conformity assessment procedures for important or critical products

For any questions, clarifications, or further information regarding this consultation, please contact: Sofilyx Compliance

Section Title

Algeria Enforces New Rules for Approving Electronic Communications Equipment

Algeria has enforced a new decree regulating the approval of electronic communications equipment...

CRA Updates Qatar National Frequency Allocation Plan

The Communications Regulatory Authority (CRA) has issued an updated Qatar National Frequency...

Colombia Expands Flexibility in the 900 MHz Band to Boost Connectivity

Colombia’s National Spectrum Agency (ANE) has enabled flexible use of the 900 MHz band to expand...

EU Repeals RED Cybersecurity Delegated Regulation Ahead of Cyber Resilience Act (CRA) Implementation in 2027

The European Commission will repeal the RED Cybersecurity Delegated Regulation (EU) 2022/30 on 11...

Oman TRA Launches Self‑Declaration of Conformity Service to Accelerate Type Approval Procedures

Oman’s Telecommunications Regulatory Authority has launched a Self‑Declaration of Conformity service...

Paraguay Authorizes 3.700–3.800 MHz Band for IMT to Boost 5G Deployment

Paraguay’s telecom regulator, CONATEL, has officially designated the 3.700–3.800 MHz band for IMT...

Moldova Renames Its Communications Authority: ANRCETI Becomes ARCOM

Beginning January 2026, Moldova’s communications regulator adopts a new name: ARCOM. The change...

Chile Updates Technical Standard for Short‑Range Devices

SUBTEL has issued Resolution 2219, updating the technical standard for short‑range devices with...

FCC Approves New GVP Devices to Deliver Faster Wi‑Fi and Next‑Gen Connectivity

The FCC has adopted new rules allowing GVP devices to operate at higher power in the 6 GHz band...