Requirements

Annex I: the essential requirements, explained

The heart of the CRA in engineer-friendly terms — the security-by-design properties, and the vulnerability-handling duties.

Annex I is where the CRA stops being abstract. It sets out the essential cybersecurity requirements every in-scope product must meet, in two parts: Part I is about the security properties of the product itself, and Part II is about the processes a manufacturer must run to handle vulnerabilities over time. Crucially, the requirements are risk-based — you apply them in proportion to your product's cybersecurity risk assessment, so not every clause weighs the same for every product.

Part I — Security properties of the product

These describe how a well-secured product should behave. Paraphrased and grouped for clarity, a product should:

Be secure by design and by default

Protect access and data

Stay available and resilient

Be observable and updatable

Read it as a checklist, apply it as a risk decision. For each property, ask: what is the risk here for this product, and what is a proportionate way to satisfy it? Document the reasoning — that record is part of your technical documentation.

Part II — Vulnerability handling over the support period

Part II recognises that no product stays secure by itself. Over the product's support period, the manufacturer must run an ongoing process. Paraphrased, you must:

The SBOM connection

A software bill of materials is the thread that ties much of Part II together. If you do not know what components — and which versions — are inside your product, you cannot tell whether the latest disclosed vulnerability affects you, and you cannot demonstrate that you are managing that risk. A good SBOM lets you answer "are we affected?" in minutes rather than weeks, and it is increasingly what customers and auditors expect to see.

How manufacturers usually demonstrate compliance

Annex I states what must be achieved, not the exact how. In practice, manufacturers meet the requirements by leaning on recognised engineering practices and, where available, harmonised standards: following these gives a presumption of conformity for the parts they cover. (Note that formal standards documents are themselves copyrighted; you obtain them from the relevant standards bodies — this article describes the requirements in our own words, not the standards' text.)

Turn Annex I into a working plan: ComplyCRA presents Annex I as a structured self-assessment, records your justification for each requirement, generates and scans your SBOM for known vulnerabilities, and rolls everything into a readiness score. Open ComplyCRA →

This article paraphrases the requirements in plain language for orientation and is not legal advice. The binding wording is in Annex I of Regulation (EU) 2024/2847.

← CRA timeline & key dates All CRA Insights →