Skip to main content
Oficiálna stránka verejnej správy SR
Cyber Resilience Act · National Security Authority

Essential cybersecurity requirements

Last updated:

Essential cybersecurity requirements

Annex I has two parts. Part I covers product security properties at placement. Part II covers vulnerability-handling processes at placement and throughout support. Measures are selected through the risk assessment; this is not an identical feature checklist for every product.

Law — product properties

The product must be designed, developed and produced to provide cybersecurity appropriate to its risks. Based on the risk assessment and where applicable, it must:

  1. be placed on the market without known exploitable vulnerabilities;
  2. have a secure-by-default configuration, including reset to the original state; a different agreement is possible with a business user for a tailor-made product;
  3. where applicable, support automatic security updates enabled by default, with a clear and easy opt-out and notification of available updates;
  4. protect against unauthorised access through appropriate authentication, identity and access controls and enable reporting of possible unauthorised access;
  5. protect the confidentiality of stored, transmitted or otherwise processed data, for example through relevant encryption;
  6. protect the integrity of data, commands, programs and configuration against unauthorised manipulation or modification and report corruption;
  7. process only data that are adequate, relevant and limited to the intended purpose;
  8. protect availability of essential and basic functions, including resilience and mitigation against denial-of-service attacks;
  9. minimise its own negative impact on the availability of services provided by other devices or networks;
  10. limit attack surfaces, including external interfaces;
  11. reduce incident impact through appropriate exploitation-mitigation mechanisms and techniques;
  12. record or monitor relevant security activity and allow user control or opt-out where required;
  13. enable secure and easy removal, transfer and deletion of user data and settings and, where relevant, secure transfer to other products or systems.

Law — vulnerability handling

The manufacturer must:

  1. identify and document vulnerabilities and components, including a machine-readable SBOM covering at least top-level dependencies;
  2. address and remediate vulnerabilities without delay, including through security updates;
  3. perform effective and regular product security tests and reviews;
  4. once an update is available, publish the fixed-vulnerability description, affected-product identification, impact, severity and remediation guidance; publication may be delayed in duly justified cases where security risks outweigh benefits and users need an opportunity to patch;
  5. establish and enforce a coordinated vulnerability disclosure policy;
  6. facilitate reporting of potential product and component vulnerabilities and provide a contact address;
  7. provide mechanisms for secure, timely update distribution and, where applicable, automatic security updates;
  8. distribute available security updates without delay, free of charge and with clear user advice; a different agreement is possible with a business user for a tailor-made product.

Guidance — applying the requirements

Page sources: CRA Articles 6, 13(1)–(11), 27 and Annex I; Recitals 54–55. See the shared source register below.