On this page
- Translate Annex I into product-specific security requirements.
- Retain release-specific proof, not only policy documents.
- Treat secure defaults, updates, access control, and data protection as design evidence.
- Connect vulnerability decisions to corrective releases and user communication.
Product security starts with risk
Annex I sets essential cybersecurity requirements for product properties. The appropriate implementation depends on the product’s cybersecurity risk assessment and intended and reasonably foreseeable use. Evidence should explain the chosen design, not merely list tools.
Evidence the released state
For each release, preserve the source revision, build definition, dependency resolution, SBOM, security test output, known issues, approvals, and update artifacts. The aim is to reconstruct what was shipped and the security reasoning applied at that time.
Vulnerability handling is a lifecycle control
Component identification, vulnerability intake, remediation, testing, coordinated disclosure, distribution of security updates, and public disclosure after a fix all form part of a coherent process. That loop is described step by step in CRA vulnerability handling; owners and deadlines should be explicit wherever it runs.
Do not confuse readiness assistance with conformity
Automated evidence collection can identify gaps and maintain technical records. Product classification, applicable harmonised standards, conformity-assessment route, declaration of conformity, and CE marking require accountable manufacturer decisions and, in some cases, a notified body.
Frequently asked questions
Does the CRA mandate a particular scanner?
No. The regulation establishes outcomes and processes. Tools can support those outcomes, but evidence should explain scope, configuration, results, decisions, and corrective action.
Must every software product use third-party assessment?
No. Many products may use internal control, while important and critical product categories can require different routes. Classification must be assessed for the product’s core functionality.