Directive (EU) 2024/2853Applies after 9 December 2026

Does the EU Product Liability Directive apply to software?

Yes. Directive (EU) 2024/2853, the new EU Product Liability Directive, defines a product to include software in Article 4(1), and applies to products placed on the market or put into service after 9 December 2026.

Key takeaways

  1. Directive (EU) 2024/2853 applies to products placed on the market or put into service after 9 December 2026, and Directive 85/374/EEC still applies to products placed on the market before that date.
  2. Software is a product under Article 4(1), whether it is stored on a device, accessed through a network or the cloud, or supplied as software-as-a-service (recital 13).
  3. Free and open-source software developed or supplied outside the course of a commercial activity is outside the directive (Article 2(2)).
  4. Safety-relevant cybersecurity requirements are one of the circumstances a court takes into account when it assesses whether a product is defective (Article 7(2)(f)).
  5. A manufacturer stays liable for a defect caused by a lack of software updates necessary to maintain safety, where the updates are within the manufacturer's control (Article 11(2)(c)).

Which products does the directive cover?

All movables, including electricity, digital manufacturing files, raw materials and software (Article 4(1)). The directive applies to products placed on the market or put into service after 9 December 2026 (Article 2(1)).

Recital 13 states that software is a product irrespective of the mode of its supply or usage, so firmware, applications, operating systems and AI systems are covered whether they run on a device, in the cloud or as software-as-a-service.

Free and open-source software developed or supplied outside the course of a commercial activity is excluded (Article 2(2)). Recital 14 adds that publishing such software on an open repository is not making it available on the market, unless that happens in the course of a commercial activity.

What changed from Directive 85/374/EEC?

Directive (EU) 2024/2853 repeals Directive 85/374/EEC with effect from 9 December 2026. The old directive continues to apply to products placed on the market or put into service before that date (Article 21).

Directive 85/374/EEC compared with Directive (EU) 2024/2853
TopicDirective 85/374/EECDirective (EU) 2024/2853
SoftwareNot named. A product means all movables and includes electricity (Article 2).Named. A product includes electricity, digital manufacturing files, raw materials and software (Article 4(1)).
Loss of dataNot a listed type of damage (Article 9).Destruction or corruption of data that are not used for professional purposes (Article 6(1)(c)).
Property damage thresholdA lower threshold of 500 ECU (Article 9(b)).No threshold in Article 6.
Financial ceilingA member state may cap total liability for death or personal injury caused by identical items with the same defect, at not less than 70 million ECU (Article 16).Liability may not be limited or excluded by a contractual provision or by national law (Article 15).
CybersecurityNot named.Relevant product safety requirements, including safety-relevant cybersecurity requirements, are a circumstance in assessing defectiveness (Article 7(2)(f)).
Disclosure of evidenceNo equivalent article.A court can order the defendant to disclose relevant evidence (Article 9). A failure to disclose triggers a presumption of defectiveness (Article 10(2)(a)).
Expiry period10 years from the date the producer put the product into circulation (Article 11).10 years, or 25 years where the latency of a personal injury prevented proceedings (Article 17).

How do software updates affect liability?

A manufacturer is normally not liable for a defect that probably came into being after the product was placed on the market (Article 11(1)(c)). Article 11(2) removes that exemption where the defect is due to a related service, to software including updates or upgrades, to a lack of software updates or upgrades necessary to maintain safety, or to a substantial modification, in each case provided it is within the manufacturer’s control.

Under Article 4(5), the manufacturer’s control includes the ability to supply software updates or upgrades, directly or through a third party. A product is not defective only because a better product, or an update for it, is later placed on the market (Article 7(3)).

How does the directive relate to the Cyber Resilience Act?

Directive (EU) 2024/2853 does not name the Cyber Resilience Act, Regulation (EU) 2024/2847. Two of its provisions matter to a manufacturer that falls under the CRA.

  • Article 7(2)(f) makes relevant product safety requirements, including safety-relevant cybersecurity requirements, a circumstance in assessing defectiveness.
  • Article 10(2)(b) presumes defectiveness where the claimant shows that the product does not comply with mandatory product safety requirements laid down in Union or national law that are intended to protect against the risk of the damage suffered.

Whether a given CRA requirement meets either test is for a national court to decide. Article 9 lets that court order the defendant to disclose relevant evidence, and Article 10(2)(a) presumes defectiveness where the defendant fails to do so.

A manufacturer that keeps its CRA technical documentation, risk assessment and vulnerability handling records current holds the evidence a court can order it to disclose. See the EU Cyber Resilience Act guide and the CRA timeline.

Frequently asked questions

Does the EU Product Liability Directive apply to software?

Yes. Article 4(1) of Directive (EU) 2024/2853 defines a product to include software. Recital 13 states that this holds whether the software is stored on a device, accessed through a communication network or cloud technologies, or supplied through a software-as-a-service model.

When does Directive (EU) 2024/2853 apply?

Directive (EU) 2024/2853 applies to products placed on the market or put into service after 9 December 2026 (Article 2(1)). Member states must transpose it by 9 December 2026 (Article 22). Directive 85/374/EEC continues to apply to products placed on the market or put into service before that date (Article 21).

Does the directive cover open-source software?

Not when the software is developed or supplied outside the course of a commercial activity (Article 2(2)). Recital 14 adds that providing such software on open repositories is not making it available on the market, unless that happens in the course of a commercial activity.

Can a manufacturer be liable for not shipping a security update?

Yes. Article 11(2)(c) removes the later-defect exemption where the defectiveness is due to a lack of software updates or upgrades necessary to maintain safety, provided the updates are within the manufacturer's control. Under Article 4(5), control includes the ability to supply software updates or upgrades.

Does the Product Liability Directive mention the Cyber Resilience Act?

No. Directive (EU) 2024/2853 does not name Regulation (EU) 2024/2847. The directive refers to safety-relevant cybersecurity requirements (Article 7(2)(f)) and to mandatory product safety requirements laid down in Union or national law (Article 10(2)(b)). Whether a given requirement meets those tests is for a national court.

Sources

This page summarises the text of Directive (EU) 2024/2853. It is not legal advice, and national transposition may add detail.

Last updated on 2026-09-26.

Keep the records a liability claim asks for

CVD Portal keeps the CRA risk assessment, technical documentation and vulnerability handling log in one place, with the date of every change.