Ecodesign Regulation for Servers and Data Storage Products, Firmware and Security Updates
Commission Regulation (EU) 2019/424, Annex II, point 1.2.3
In force since .
A product security requirements rule binding public and private bodies.
- Obligation class
- Security
As of .
What it requires
- It reaches you if you place a server or an online data storage product on the market (Article 1(1)); the Regulation does not apply to servers intended for embedded applications, small scale servers, servers with more than four processor sockets, server appliances, large servers, fully fault tolerant servers, network servers, small data storage products or large data storage products (Article 1(2)). Make the latest available version of the firmware available, free of charge or at a fair, transparent and non-discriminatory cost, from two years after the placing on the market of the first product of a model and for a minimum period of eight years after the placing on the market of the last product of that model (Annex II, point 1.2.3, applying from under Article 3).
- Make the latest available security update to the firmware available, free of charge, from the time a product model is placed on the market until at least eight years after the placing on the market of the last product of that model (Annex II, point 1.2.3).
Who enforces it
Enforcement body
The market surveillance authorities of the Member States, which apply the verification procedure in Annex IV when performing the market surveillance checks referred to in Article 3(2) of Directive 2009/125/EC (Article 5).
What this law does
Article 1(1) of Commission Regulation (EU) 2019/424 establishes ecodesign requirements for the placing on the market and putting into service of servers and online data storage products. Article 1(2) excludes servers intended for embedded applications, small scale servers, servers with more than four processor sockets, server appliances, large servers, fully fault tolerant servers, network servers, small data storage products and large data storage products.
Article 3 requires servers and online data storage products to comply with Annex II, point 1.2.3, from . Annex II, point 1.2.3, requires the latest available version of the firmware to be made available from two years after the placing on the market of the first product of a model for a minimum period of eight years after the placing on the market of the last product of that model, free of charge or at a fair, transparent and non-discriminatory cost.
It also requires the latest available security update to the firmware to be made available free of charge from the time a product model is placed on the market until at least eight years after the placing on the market of the last product of that model. Annex I, point (34), defines firmware as system, hardware, component, or peripheral programming provided with the product to provide basic instructions for hardware to function inclusive of all applicable programming and hardware updates.
Article 5 requires Member States to apply the verification procedure in Annex IV when performing the market surveillance checks referred to in Article 3(2) of Directive 2009/125/EC. Article 10 provides that the Regulation enters into force on the twentieth day following that of its publication in the Official Journal.
When LexLint raises it
When your app profile says your app distributes a software product.