Who it binds
Primarily manufacturers, meaning whoever develops a product or has it developed and markets it under their name, including open-source stewards in a lighter regime; importers and distributors carry verification duties. Products are classed by risk: a default class with self-assessment, important products in two classes with stricter assessment, and critical products that may require European certification. Software as a service is out unless it is part of remote data processing that a product depends on.
The obligations
Annex I sets the essential requirements: secure-by-default configuration, protection against unauthorized access, confidentiality and integrity, attack-surface limitation, security updates, and a vulnerability handling process with a software bill of materials, coordinated disclosure and a policy for reporting. The support period is set by the product’s expected lifetime, five years at minimum for most products. Actively exploited vulnerabilities and severe incidents are reported to ENISA and the national CSIRT with an early warning within 24 hours, a notification within 72 hours and a final report within 14 days.
What it changes for a security program
For a manufacturer, product security stops being an engineering preference and becomes a compliance obligation with evidence: a risk assessment per product, a documented vulnerability handling process, a tested update mechanism and technical documentation the market surveillance authority can request. For a buyer, the CE marking and the manufacturer’s vulnerability policy become inputs to third-party risk, and a product that has left its support period becomes a security exception with an expiry.