Skip to main content
Oficiálna stránka verejnej správy SR
Cyber Resilience Act · National Security Authority
Explaining the CRACurrent

What Must a Product Comply with under the CRA? Annex I, Part I

Published: For: Manufacturers and development teams

Ilustračná grafika k základným požiadavkám kybernetickej bezpečnosti produktov podľa CRA

The CRA does not stop at general principles. Annex I, Part I sets out security characteristics that must be considered when designing, developing and placing a product with digital elements on the market.

Essential product characteristics

A common principle: security by design

Security should be built into the product from the beginning and throughout its entire lifecycle. Adding it only after an incident or shortly before a conformity assessment is not enough.

This is a brief explanation

The specific measures depend on the product, its intended purpose and its risks. When preparing the technical documentation, work with the full text of the requirements and the controlled CRA guide.