An EU consumer law that sets conformity and warranty requirements for digital goods sold within or into the EU. It replaces the idea that software can be sold as is and requires sellers to keep products fit for purpose, secure, and supported with bug and vulnerability fixes for at least two years.
Expanded Definition
Directive (EU) 2019/771 is the EU’s sales-law baseline for digital goods and goods with digital elements sold to consumers. It shifts the expectation away from “sold as is” and toward ongoing conformity, meaning the product must continue to match its description, perform its intended functions, and remain supplied with updates that preserve security and usability. For security teams, that matters because vulnerability handling is no longer only a support issue. It becomes part of the product’s legal conformity over its lifecycle.
The directive sits alongside, but is not the same as, cybersecurity frameworks such as the NIST Cybersecurity Framework 2.0. NIST helps organisations structure risk management; Directive (EU) 2019/771 determines what consumers can expect from the product after sale. Definitions vary across vendors and legal interpretations when a digital feature depends on cloud services, app stores, or third-party integrations, so legal and engineering teams often have to interpret conformity obligations together.
The most common misapplication is treating post-sale fixes as optional product support, which occurs when teams separate vulnerability remediation from contractual conformity obligations.
Examples and Use Cases
Implementing Directive (EU) 2019/771 rigorously often introduces lifecycle maintenance cost, requiring organisations to weigh product release velocity against the obligation to keep consumer software conformant and secure.
- A smart home device ships with an app that later needs security patches. The vendor must keep issuing updates so the product remains usable and safe for the period promised at sale.
- A consumer subscription service adds a new feature set, but a later update breaks an advertised function. The issue is not just a bug ticket; it may be a conformity failure under the directive.
- A mobile app relies on authentication APIs and remote services. If those dependencies change, the seller may still need to preserve the product’s stated behaviour through support and fixes.
- A connected toy or appliance is found to have a vulnerability. The obligation to provide remedies can extend beyond a one-time patch if the security issue affects conformity with the product’s expected use.
- Security and product counsel may map product update commitments against guidance from the NIST Cybersecurity Framework 2.0 to clarify ownership of post-sale risk treatment.
Why It Matters for Security Teams
For security leaders, this directive turns vulnerability management into a commercial and legal continuity problem. If patching is delayed, poorly scoped, or unsupported, the organisation risks not only exposure but also breach of conformity obligations, warranty disputes, and consumer claims. That is especially important for products with embedded software, remote management features, or cloud-connected components, where the security boundary is wider than the device itself.
The identity connection is indirect but real: consumer authentication, account recovery, update channels, and device enrolment can all become part of whether the product remains fit for purpose. In practice, teams need traceable evidence that security fixes were delivered and that product behaviour stayed aligned with what was marketed and contracted. NIST guidance can help structure the control environment, but it does not replace the directive’s legal standard. Organisations typically encounter the full cost of this obligation only after a consumer dispute, regulator inquiry, or major vulnerability disclosure, at which point the directive becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022, DORA and NIS2 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.SC-01 | CSF 2.0 supply chain governance supports lifecycle accountability for shipped digital products. |
| NIST SP 800-53 Rev 5 | SI-2 | System flaw remediation maps to patching duties that keep consumer software conformant. |
| ISO/IEC 27001:2022 | A.8.8 | Management of technical vulnerabilities supports secure update obligations after product sale. |
| DORA | DORA reinforces resilience and ICT risk controls relevant to software continuity expectations. | |
| NIS2 | NIS2 highlights security-by-design and incident handling obligations relevant to update duty. |
Assign owners for post-sale security maintenance and track conformity obligations across the product lifecycle.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org