
The CRA does not stop at general principles. Annex I, Part I sets out security characteristics that must be considered when designing, developing and placing a product with digital elements on the market.
Essential product characteristics
- No known exploitable vulnerabilities. When placed on the market, the product should be free from currently known vulnerabilities that can be exploited.
- Secure by default configuration. A manufacturer should not supply a product with an empty or easily guessed password. Security settings should be strong from the outset.
- Minimised attack surface. Unnecessary ports, functions and access points should not remain active.
- Protection of data confidentiality and integrity. Measures such as encryption, authentication and access control should be used according to the risk.
- Secure updates. The product should support the secure remediation of vulnerabilities and distribution of updates.
- Secure deletion of data. Users should be able to securely remove personal data and their own settings.
A common principle: security by design
Security should be built into the product from the beginning and throughout its entire lifecycle. Adding it only after an incident or shortly before a conformity assessment is not enough.
This is a brief explanation
The specific measures depend on the product, its intended purpose and its risks. When preparing the technical documentation, work with the full text of the requirements and the controlled CRA guide.