What does Annex I Part I, point (1) mean under the Cyber Resilience Act?
It is the general product-level requirement to ensure an appropriate level of cybersecurity based on the risks.
The Commission's March 2026 draft guidance explains that this point is meant to catch additional cybersecurity risks identified by the risk assessment that are not otherwise adequately addressed by the other specific Part I requirements. In most cases, complying with the other applicable Part I requirements will also satisfy point (1), but if additional relevant risks remain, the manufacturer still has to address them at product level.
Annex I Part I point (1) is the general product-level cybersecurity outcome, applied through the Article 13 risk assessment.
Draft points 148-150 explain how Part I point (1) addresses residual product-security risks not covered by more specific points.