Understanding CRA Requirements (Annex I)
The CRA requirements are defined in Annex I of the Cyber Resilience Act and are divided into two parts:
Part I: Security Requirements
14 requirements covering how your product must be designed and built to be secure.
- Secure by default
- Access control
- Data protection
- Minimal attack surface
Part II: Vulnerability Handling
8 requirements covering how you must manage security vulnerabilities throughout the product lifecycle.
- Vulnerability identification
- Disclosure process
- Patching and updates
- SBOM maintenance
Want to explore each requirement in detail with implementation guidance?
Open Requirements Explorer →Part I: Security Requirements (Product Design)
These requirements apply to how your product is designed, developed, and configured:
Risk-Based Security Design
Products with digital elements shall be designed, developed, and produced to ensure an appropriate level of cybersecurity based on the risks (Annex I Part I, point 1).
No Known Exploitable Vulnerabilities
Products must be made available on the market without known exploitable vulnerabilities.
Secure by Default
Products must be designed and manufactured with appropriate security by default, not requiring user configuration to be secure.
Protection Against Unauthorized Access
Products must protect against unauthorized access through appropriate mechanisms like authentication and access control.
Data Confidentiality
Products must protect the confidentiality of stored, transmitted, and processed data using encryption or other appropriate means.
Data Integrity
Products must protect the integrity of data against unauthorized manipulation or alteration.
Data Minimization
Products must only process data that is adequate and relevant for the intended purpose.
Availability Protection
Products must ensure essential functions remain available, including resilience against DoS attacks.
Minimize Negative Impact
Products must be designed to minimize negative impact on other devices and networks.
Reduce Attack Surfaces
Products must reduce attack surfaces including external interfaces to a minimum.
Incident Impact Mitigation
Products must include mechanisms to reduce the impact of security incidents.
Security Information Recording
Products must record/log security-relevant events and make information accessible to users.
Secure Updates
Products must support secure update mechanisms to address vulnerabilities in a timely manner.
Secure Data Removal
Products must let users securely and permanently remove all data and settings, and any data transferred to another product or system must be transferred securely.
Part II: Vulnerability Handling Requirements
These requirements govern how manufacturers must handle security vulnerabilities:
Identify and Document Vulnerabilities
Manufacturers must identify and document vulnerabilities in their products, including through third-party components.
Address Vulnerabilities Without Delay
Once identified, vulnerabilities must be addressed and remediated promptly.
Apply Effective Testing
Regular security testing must be performed throughout the product lifecycle.
Disclose Patch Information
Information about fixed vulnerabilities must be publicly disclosed after the update is available.
Implement Coordinated Disclosure Policy
A vulnerability disclosure policy must be in place for receiving reports from security researchers.
Build Your VDP →Share Vulnerability Information
Share information about vulnerabilities to help other operators and ENISA.
Distribute Security Updates
Security updates must be made available free of charge and distributed securely.
Provide SBOM
A machine-readable Software Bill of Materials must be compiled and maintained.
SBOM Guide →Which Requirements Apply to Your Product?
The toolkit evaluates all 22 CRA requirements, but applicability and implementation rigor vary based on your product classification:
Explore Requirements in Detail
Use our interactive Requirements Explorer to see implementation guidance, evidence needed, and track your compliance progress for each requirement.