emendrix

Art. 51

Cybersecurity Act · 32019R0881 · every event for this act · on EUR-Lex

Security objectives of European cybersecurity certification schemes for ICT products, ICT services and ICT processes

1 change recorded across 1 event, newest first.

in force 2025-02-04 MODIFIED+95 −0

Amended by Regulation (EU) 2025/37 32025R0037

applies from: unchanged

The heading now adds the phrase "for ICT products, ICT services and ICT processes" after "European cybersecurity certification schemes".

The opening sentence of Article 51 similarly adds the words "for ICT products, ICT services or ICT processes" after the reference to a European cybersecurity certification scheme, while the list of security objectives in points (a) to (j) remains unchanged.

Cited: Art. 51, v2 · Art. 51, v1

text before / after

32019R088102019R0881-20250204

Article 51 Security objectives of European cybersecurity certification schemes for ICT products, ICT services and ICT processes A European cybersecurity certification scheme for ICT products, ICT services or ICT processes shall be designed to achieve, as applicable, at least the following security objectives: (a) to protect stored, transmitted or otherwise processed data against accidental or unauthorised storage, processing, access or disclosure during the entire life cycle of the ICT product, ICT service or ICT process; (b) to protect stored, transmitted or otherwise processed data against accidental or unauthorised destruction, loss or alteration or lack of availability during the entire life cycle of the ICT product, ICT service or ICT process; (c) that authorised persons, programs or machines are able only to access the data, services or functions to which their access rights refer; (d) to identify and document known dependencies and vulnerabilities; (e) to record which data, services or functions have been accessed, used or otherwise processed, at what times and by whom; (f) to make it possible to check which data, services or functions have been accessed, used or otherwise processed, at what times and by whom; (g) to verify that ICT products, ICT services and ICT processes do not contain known vulnerabilities; (h) to restore the availability and access to data, services and functions in a timely manner in the event of a physical or technical incident; (i) that ICT products, ICT services and ICT processes are secure by default and by design; (j) that ICT products, ICT services and ICT processes are provided with up-to-date software and hardware that do not contain publicly known vulnerabilities, and are provided with mechanisms for secure updates.