Chapter 2 — Research and development procurementProposed — COM(2026) 567
Article 30 — Cybersecurity
In brief
This article requires public buyers to ensure that products with digital elements developed or used in the procured R&D services comply with the essential cybersecurity requirements of the Cyber Resilience Act, including the ability to handle vulnerabilities effectively. Buyers may impose additional cybersecurity requirements, and may specify cybersecurity conditions in their procurement documents where linked to the subject matter of the contract.
Key points
For products with digital elements within the scope of the referenced Cyber Resilience Act, buyers must take the essential cybersecurity requirements, including vulnerability handling, into account in the R&D procurement process.
Buyers may add further cybersecurity requirements, including for national security or defence purposes, provided they are consistent with Union law and are necessary and proportionate.
Buyers may set cybersecurity requirements through specifications, selection, exclusion or award criteria, or contract performance conditions, respecting transparency, non-discrimination and proportionality.
Such requirements must be linked to the subject matter of the contract, and the NIS 2 Directive continues to apply where relevant.
Operators identified as high-risk suppliers for key ICT assets must be excluded from the procedure.
What it means in practice
Public buyers acquiring R&D services that involve connected or software-based products will need to build cybersecurity checks into their procedures, drawing on existing Union frameworks. Innovative firms, start-ups and SMEs offering such products should expect to demonstrate compliance with essential cybersecurity requirements and vulnerability-handling capacity, and may face additional, proportionate cybersecurity conditions or exclusion where identified as high-risk suppliers.
Anthony Bochon’s analysis
This provision is a textbook example of the Union legislator wiring one instrument into the existing cybersecurity acquis rather than reinventing it. By requiring compliance with the essential requirements of Annex I to the Cyber Resilience Act for products with digital elements, and by preserving the application of the NIS2 Directive, the article ensures that R&D procurement does not become a back door around the horizontal security-by-design obligations that now bind manufacturers. The explicit reference to the manufacturer’s ability to handle vulnerabilities effectively is, in my view, the operative point: it pulls vulnerability management into the award analysis rather than treating it as a post-market afterthought.
The carve-out in paragraph 2 for additional national-security and defence requirements, and the standing exclusion of high-risk ICT suppliers in paragraph 4, show the same economic-security logic that runs through Article 28. What I would watch is proportionality: because buyers may layer cybersecurity specifications, selection, exclusion and award criteria on top of the CRA baseline, they will need to tie each requirement clearly to the subject-matter of the contract to withstand scrutiny. My reading is that well-advised buyers will treat the CRA and NIS2 as the floor and reserve bespoke requirements for genuinely sensitive results.
Official text — Article 30 (COM(2026) 567)
1. For all products with digital elements used and developed as part of the research and
development services procured that fall within the scope of Regulation (EU)
2024/2847 of the European Parliament and of the Council 48, public buyers shall
ensure compliance with the essential cybersecurity requirements set out in Annex I to
that Regulation, including the manufacturers’ ability to handle vulnerabilities
effectively are taken into consideration in the R&D procurement process.
2. This Regulation shall not prevent public buyers from subjecting products with digital
elements referred to in paragraph 1 to additional cybersecurity requirements for the
R&D procurement or use of those products for specific purposes, including where
those products developed, obtained or used for national security or defence purposes,
provided that such requirements are consistent with Member States’ obligations laid
down in Union law and that they are necessary and proportionate for the achievement
of those purposes.
3. Without prejudice to paragraph 1, and without prejudice to Directive (EU)
2022/2555 of the European Parliament and of the Council 49 where applicable, public
buyers may specify in the procurement documents requirements relating to
cybersecurity for the research and development services procured and their intended
results. To that end, they may include specifications, selection criteria, exclusion
criteria, award criteria or conditions for the performance of contracts. Such
requirements shall be linked to the sub ject-matter of the R&D procurement contract
and comply with the principles of transparency, non -discrimination and
proportionality.
4. Public buyers shall at any time during an R&D procurement procedure exclude an
economic operator from participation in an R&D procurement procedure where the
operator has been identified as a high-risk supplier in relation to the provision of ICT
components or components that include ICT components to be used in key ICT
assets.
48 Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on
horizontal cybersecurity requirements for products with digital elements and amending Regulations
(EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) (OJ L,
2024/2847, 20.11.2024, ELI: http://data.europa.eu/eli/reg/2024/2847/oj).
49 Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on
measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No
910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive)
(OJ L 333, 27.12.2022, p. 80, ELI: http://data.europa.eu/eli/dir/2022/2555/oj).
SECTION 3
JOINT PROCUREMENT OF RESEARCH AND DEVELOPMENT SERVICES
Source: European Commission, proposal for a Regulation establishing the European Innovation Act, COM(2026) 567 final, 9 September 2026. Read the official proposal (PDF). Text may change during the legislative process.
Anthony Bochon’s analysis
This provision is a textbook example of the Union legislator wiring one instrument into the existing cybersecurity acquis rather than reinventing it. By requiring compliance with the essential requirements of Annex I to the Cyber Resilience Act for products with digital elements, and by preserving the application of the NIS2 Directive, the article ensures that R&D procurement does not become a back door around the horizontal security-by-design obligations that now bind manufacturers. The explicit reference to the manufacturer’s ability to handle vulnerabilities effectively is, in my view, the operative point: it pulls vulnerability management into the award analysis rather than treating it as a post-market afterthought.
The carve-out in paragraph 2 for additional national-security and defence requirements, and the standing exclusion of high-risk ICT suppliers in paragraph 4, show the same economic-security logic that runs through Article 28. What I would watch is proportionality: because buyers may layer cybersecurity specifications, selection, exclusion and award criteria on top of the CRA baseline, they will need to tie each requirement clearly to the subject-matter of the contract to withstand scrutiny. My reading is that well-advised buyers will treat the CRA and NIS2 as the floor and reserve bespoke requirements for genuinely sensitive results.