Skip to content

Annex I Requirements

CRA Annex I defines the essential cybersecurity requirements that every product with digital elements must meet. These are organized into two sections.

These requirements apply to the product itself.

Ref Requirement Fleet Coverage
I.2(a) No known exploitable vulnerabilities SBOM + vuln enrichment, 11 detectors
I.2(b) Secure by default configuration CONFIG-* detectors
Ref Requirement Fleet Coverage
I.3(a) Protect confidentiality (encryption in transit/at rest) CRYPTO-, NET-, STOR-* detectors + CBOM
I.3(b) Protect from unauthorized access AUTH-, NET-SVC- detectors
I.3(c) Protect availability NET-SVC-02 (rate limiting), RDPS-AVAIL-*
I.3(d) Protect stored data STOR-*, CRYPTO-02 (key management)
I.3(e) Minimize negative impact of exploitation INPUT-, UPLOAD- detectors
I.3(f) Minimize attack surfaces INPUT-*, NET-SVC-04 (unnecessary endpoints)
I.3(g) Secure updates UPD-* detectors (integrity, versioning, rollback)
I.3(h) Record/monitor relevant activity LOG-* detectors (events, protection, format)

These requirements apply to the manufacturer’s processes.

Ref Requirement Fleet Coverage
II.1 Identify and document vulnerabilities VH-ID-* (security.txt, intake channels)
II.2 Address vulnerabilities through security updates VH-REM-* (SLAs, fix verification)
II.3 Apply effective remediation Remediation tracking API
II.4 Inform users of vulnerabilities VH-DIST-* (advisories, notifications)
II.5 Coordinated vulnerability disclosure VH-DISC-* (policy, CVE, timeline)
II.6 Notify ENISA VH-REG-* (24h early warning, 72h full notification)
II.8 Regular testing and review SUPPLY-02 (CI scanning)

Fleet maps these Annex I requirements into a structured catalog:

Feature Category (13 categories)
└── Feature (54 features)
├── Risk (163 risks, each linking to Annex I)
└── Requirement (401 requirements)
├── Assessment Method
└── Evidence Type: Auto | Semi | Doc | Test
  1. Network Communications — DB connections, API calls, exposed services
  2. Authentication & Identity — User auth, API tokens, sessions
  3. Data Storage — Local storage, cloud storage, encryption at rest
  4. Cryptography — Algorithms, key management, PRNG
  5. Input Handling — Injection, XSS, path traversal, uploads
  6. Secure Update Mechanism — Delivery, integrity, versioning, firmware
  7. Security Logging & Monitoring — Events, protection, format, retention
  8. Third-Party Components — SBOM, OSS due diligence, commercial, SaaS
  9. Configuration & Deployment — Secure defaults
  10. Vulnerability Handling — Identification, triage, remediation, disclosure
  11. AI Components — Model integrity, prompt injection, data exposure
  12. Remote Data Processing — RDPS classification, data protection
  13. Hardware & Physical Security — Component inventory, interfaces, secure boot