The Two Pillars of CRA Annex I
Annex I is divided into two parts: Essential Cybersecurity Requirements (Product capabilities) and Vulnerability Handling Requirements (Manufacturer processes).
Part I: Product Capabilities
Your product must physically or digitally possess these traits:
- Risk-appropriate security: Designed to withstand expected threats.
- Secure by Default: Ships in the most secure configuration possible.
- Access Control: Strong authentication and principle of least privilege.
- Data Protection: Encryption of PII and sensitive configurations.
- Integrity: Protection against unauthorized modifications.
- Telemetry: Minimal data collection, strictly necessary for security.
Part II: Vulnerability Handling
You must possess these operational capabilities:
- SBOM generation: Machine-readable dependency tracking.
- Patch delivery: Timely security updates offered free of charge.
- Public VDP: A published vulnerability disclosure policy.
Check which requirements apply to your specific product by using our Requirements Explorer.
Get the CRA deadline calendar
A one-page PDF showing every CRA date that matters for your product team. Free — no spam, unsubscribe anytime.
Related articles
Ready to Take Action?
Start your CRA compliance journey with our free assessment tool.