Guide

Breakdown of the 22 Cyber Resilience Act Requirements

An engineer-friendly breakdown of Annex I: the core security and vulnerability handling requirements of the CRA.

March 2026 · 14 min read

The Two Pillars of CRA Annex I

Annex I is divided into two parts: Essential Cybersecurity Requirements (Product capabilities) and Vulnerability Handling Requirements (Manufacturer processes).

Part I: Product Capabilities

Your product must physically or digitally possess these traits:

  • Risk-appropriate security: Designed to withstand expected threats.
  • Secure by Default: Ships in the most secure configuration possible.
  • Access Control: Strong authentication and principle of least privilege.
  • Data Protection: Encryption of PII and sensitive configurations.
  • Integrity: Protection against unauthorized modifications.
  • Telemetry: Minimal data collection, strictly necessary for security.

Part II: Vulnerability Handling

You must possess these operational capabilities:

  • SBOM generation: Machine-readable dependency tracking.
  • Patch delivery: Timely security updates offered free of charge.
  • Public VDP: A published vulnerability disclosure policy.

Check which requirements apply to your specific product by using our Requirements Explorer.

Get the CRA deadline calendar

A one-page PDF showing every CRA date that matters for your product team. Free — no spam, unsubscribe anytime.

Related articles

Ready to Take Action?

Start your CRA compliance journey with our free assessment tool.

Need help with CRA? Ask the assistant.
Need help with CRA? Ask the assistant.