emendrix

Art. 53

Cybersecurity Act · 32019R0881 · every event for this act · on EUR-Lex

Conformity self-assessment

1 change recorded across 1 event, newest first.

in force 2025-02-04 MODIFIED+304 −98

Amended by Regulation (EU) 2025/37 32025R0037

applies from: unchanged

Paragraphs 1 through 3 now add references to managed security services alongside ICT products, ICT services and ICT processes, extending the same wording pattern used for self-assessment, the EU statement of conformity, and the related documentation and submission obligations.

Paragraph 3 also changes the description of the national cybersecurity certification authority referenced in Article 58 from being merely referred to in that Article to being designated pursuant to it.

Cited: Art. 53, v1 · Art. 53, v2

text before / after

32019R088102019R0881-20250204

Article 53 Conformity self-assessment 1. A European cybersecurity certification scheme may allow for the conformity self-assessment under the sole responsibility of the manufacturer or provider of ICT products, ICT services services, ICT processes or ICT processes. managed security services. Conformity self-assessment shall be permitted only in relation to ICT products, ICT services and services, ICT processes or managed security services that present a low risk corresponding to assurance level basic. 2. The manufacturer or provider of ICT products, ICT services or services, ICT processes or managed security services may issue an EU statement of conformity stating that the fulfilment of the requirements set out in the scheme has been demonstrated. By issuing such a statement, the manufacturer or provider of ICT products, ICT services or services, ICT processes or managed security services shall assume responsibility for the compliance of the ICT product, ICT service or service, ICT process or managed security service with the requirements set out in that scheme. 3. The manufacturer or provider of ICT products, ICT services or services, ICT processes or managed security services shall make the EU statement of conformity, technical documentation, and all other relevant information relating to the conformity of the ICT products products, ICT services, ICT processes or ICT managed security services with the scheme available to the national cybersecurity certification authority referred designated pursuant to in Article 58 for the period provided for in the corresponding European cybersecurity certification scheme. A copy of the EU statement of conformity shall be submitted to the national cybersecurity certification authority and to ENISA. 4. The issuing of an EU statement of conformity is voluntary, unless otherwise specified in Union law or Member State law. 5. EU statements of conformity shall be recognised in all Member States.