Essential cybersecurity requirements
Annex I has two parts. Part I covers product security properties at placement. Part II covers vulnerability-handling processes at placement and throughout support. Measures are selected through the risk assessment; this is not an identical feature checklist for every product.
Law — product properties
The product must be designed, developed and produced to provide cybersecurity appropriate to its risks. Based on the risk assessment and where applicable, it must:
- be placed on the market without known exploitable vulnerabilities;
- have a secure-by-default configuration, including reset to the original state; a different agreement is possible with a business user for a tailor-made product;
- where applicable, support automatic security updates enabled by default, with a clear and easy opt-out and notification of available updates;
- protect against unauthorised access through appropriate authentication, identity and access controls and enable reporting of possible unauthorised access;
- protect the confidentiality of stored, transmitted or otherwise processed data, for example through relevant encryption;
- protect the integrity of data, commands, programs and configuration against unauthorised manipulation or modification and report corruption;
- process only data that are adequate, relevant and limited to the intended purpose;
- protect availability of essential and basic functions, including resilience and mitigation against denial-of-service attacks;
- minimise its own negative impact on the availability of services provided by other devices or networks;
- limit attack surfaces, including external interfaces;
- reduce incident impact through appropriate exploitation-mitigation mechanisms and techniques;
- record or monitor relevant security activity and allow user control or opt-out where required;
- enable secure and easy removal, transfer and deletion of user data and settings and, where relevant, secure transfer to other products or systems.
Law — vulnerability handling
The manufacturer must:
- identify and document vulnerabilities and components, including a machine-readable SBOM covering at least top-level dependencies;
- address and remediate vulnerabilities without delay, including through security updates;
- perform effective and regular product security tests and reviews;
- once an update is available, publish the fixed-vulnerability description, affected-product identification, impact, severity and remediation guidance; publication may be delayed in duly justified cases where security risks outweigh benefits and users need an opportunity to patch;
- establish and enforce a coordinated vulnerability disclosure policy;
- facilitate reporting of potential product and component vulnerabilities and provide a contact address;
- provide mechanisms for secure, timely update distribution and, where applicable, automatic security updates;
- distribute available security updates without delay, free of charge and with clear user advice; a different agreement is possible with a business user for a tailor-made product.
Guidance — applying the requirements
- Record each item as applicable, inapplicable with justification, or partly covered with a remediation plan.
- Do not equate meeting a standard with automatic CRA conformity. A harmonised standard can create a presumption only for the requirements it covers.
- Link each requirement to a design decision, acceptance criterion, test, result and owner.
- Include hardware, firmware, software, in-scope cloud functionality, build/release systems and third-party components.
- For every release, verify that the product has no known exploitable vulnerability affecting its security when placed on the market.
Page sources: CRA Articles 6, 13(1)–(11), 27 and Annex I; Recitals 54–55. See the shared source register below.