What are the CRA's Essential Cybersecurity Requirements?
The CRA splits the into two parts:
- Part I of Annex I covers the cybersecurity properties the product itself must have
- Part II of Annex I covers the the manufacturer must put in place
A useful compliance map links each applicable Part I outcome and each Part II process to a product control, an owner, test or review evidence, the affected product versions, and the technical-documentation record. The records at least the top-level software dependencies for component and vulnerability handling. A Part I requirement treated as not applicable still needs the Article 13(4) justification.
Article 6 ties market availability to Annex I conformity; Annex I separates product properties from vulnerability-handling requirements.