Menu

Filter by
content
PONT Data&Privacy

0




ANNEX II

INFORMATION AND INSTRUCTIONS FOR THE USER

The product with digital elements shall be accompanied by at least:

1. 

the name, registered trade name, or registered trademark of the manufacturer, and the postal address, email address, or other digital means of communication, as well as, if available, the website where the manufacturer can be contacted;

2. 

the central point of contact where information about vulnerabilities of the product with digital elements can be reported and received, and where the manufacturer's policy on coordinated disclosure of vulnerabilities can be found;

3. 

name and type and any additional information that enables the unique identification of the product with digital elements;

4. 

the intended purpose of the product with digital elements, including the security environment provided by the manufacturer, as well as the essential functions and information about the security features of the product;

5. 

any known or foreseeable circumstance related to the use of the product with digital elements in accordance with its intended purpose or in a situation of reasonably foreseeable misuse, which could lead to significant cybersecurity risks;

6. 

where applicable, the internet address at which the EU declaration of conformity can be consulted;

7. 

the type of technical security support offered by the manufacturer and the end date of the support period during which users can expect vulnerabilities to be addressed and security updates to be provided;

8. 

detailed instructions or an internet address relating to such detailed instructions and information about:

a) 

the necessary measures during initial commissioning and throughout the entire service life of the product with digital elements to ensure its safe use;

b) 

how changes to the product involving digital elements may affect data security;

c) 

how security-related updates can be installed;

d) 

the safe decommissioning of the product with digital elements, including information on how user data can be securely deleted;

e) 

how the default setting that enables the automatic installation of security updates, as required by Part I, point 2(c) of Annex I, can be disabled;

f) 

if the product with digital elements is intended to be integrated into other products with digital elements, the information necessary for the integrator to comply with the essential cybersecurity requirements set out in Annex I and the documentation requirements set out in Annex VII.

9. 

if the manufacturer decides to make the software bill of materials available to the user, information about where the software bill of materials can be consulted.