Article 27(1): Presumption of conformity
manufacturer · Article 27(1)
Presumption of conformity 1. Products with digital elements and processes put in place by the manufacturer which are in conformity with harmonised standards or parts thereof, the references of which have been published in the Official Journal of the European Union, shall be presumed to be in conformity with the essential cybersecurity requirements set out in Annex I covered by those standards or parts thereof. The Commission shall, in accordance with Article 10(1) of Regulation (EU) No 1025/2012, request one or more European standardisation organisations to draft harmonised standards for the essential cybersecurity requirements set out in Annex I to this Regulation. When preparing standardisation requests for this Regulation, the Commission shall strive to take into account existing European and international standards for cybersecurity that are in place or under development in order to simplify the development of harmonised standards, in accordance with Regulation (EU) No 1025/2012.
How to satisfy it: The presumption covers products AND the manufacturer's processes, but only via harmonised standards cited in the Official Journal. As of this corpus version none has been cited under this Regulation, so the presumption is available to nobody and conformity must be shown against Annex I directly. Track OJ citations as a dated series.
Article 27(1) on EUR-Lex · as of 2026-08-13 · Regulation (EU) 2024/2847