@@ -526,51 +526,28 @@ See [\[i.3\]](#_ref_i.3) for formal definitions of micro, small, and medium-size
The present document has been prepared in response to the Commission's standardisation request C(2025)618 [\[i.3\]](#_ref_i.3) to provide, in additions to its other uses, one voluntary means of conforming to the essential requirements of Regulation (EU) 2024/2847 [\[i.2\]](#_ref_i.2) known as the Cyber Resilience Act (CRA).
Once the present document is cited in the Official Journal of the European Union under Regulation (EU) 2024/2847 [\[i.2\]](#_ref_i.2), conformance with the normative clauses of the present document given in the tables in [annex A](#_annex.a) confers, to products with digital elements in the scope of the present document, a presumption of conformity with the corresponding essential requirements of that Regulation and associated EFTA regulations.
Once the present document is cited in the Official Journal of the European Union under Regulation (EU) 2024/2847 [\[i.2\]](#_ref_i.2), conformance with the normative clauses of the present document given in the tables in [Annex A](#_annex.a) confers, to products with digital elements in the scope of the present document, a presumption of conformity with the corresponding essential requirements of that Regulation and associated EFTA regulations.
**Table A.1: Correspondence between the European Standard and Annex I Part I of Regulation (EU) 2024/2847**<spanid="table_A.1"></span>
| Secure deletion and data transfer | SCDL, SDTR |
| Vulnerability handling | VULH |
> NOTE 1: The table cannot indicate direct relationship between the relevant legal requirement and **_other_** standards or normative clauses contained in **_other_** standards.
> NOTE 2: If the standard is developed according to the structure in the present skeleton document, then the number of the clauses in the table below don't need to be changed.
> NOTE 3: The last two columns shall be either filled with details and the reference of the table(s) mapping the applicability of the technical cybersecurity requirements, or deleted all together.
**Key to columns:**
**Requirement:**
**Description** A textual reference to the requirement.
**Requirements of Regulation** Identification of article(s) defining the requirement in the Regulation.
**Clause(s) of the present document** Identification of clause(s) defining the requirement in the present document unless another document is referenced explicitly.
**Requirement Conditionality:**
**U/C** Indicates whether the requirement is unconditionally applicable (U) or is conditional upon the manufacturer's claimed functionality of the equipment (C).
**Condition** Explains the conditions when the requirement is or is not applicable for a requirement which is classified “conditional”.
| **Description** | **Essential Requirements of Regulation (EU) 2024/2847** | **Clause(s) of the present document** |
| Annex I, Part 1, (1) | "Products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks." | Clause 5.2 |
| Annex I, Part 1, (2)(a) | "Products with digital elements shall be made available on the market without known exploitable vulnerabilities." | Clause 5.3 |
| Annex I, Part 1, (2)(b) | "Products with digital elements shall be made available on the market with a secure by default configuration, unless otherwise agreed between manufacturer and business user in relation to a tailor-made product with digital elements, including the possibility to reset the product to its original state." | Clause 5.4 |
| Annex I, Part 1, (2)(c) | "Products with digital elements shall ensure that vulnerabilities can be addressed through security updates, including, where applicable, through automatic security updates that are installed within an appropriate timeframe enabled as a default setting, with a clear and easy-to-use opt-out mechanism, through the notification of available updates to users, and the option to temporarily postpone them" | Clause 5.5 |
| Annex I, Part 1, (2)(d) | "Products with digital elements shall ensure protection from unauthorised access by appropriate control mechanisms, including but not limited to authentication, identity or access management systems, and report on possible unauthorised access" | Clause 5.6 |
| Annex I, Part 1, (2)(e) | "Products with digital elements shall protect the confidentiality of stored, transmitted or otherwise processed data, personal or other, such as by encrypting relevant data at rest or in transit by best practice mechanisms, and by using other technical means." | Clause 5.7 |
| Annex I, Part 1, (2)(f) | "Products with digital elements shall protect the integrity of stored, transmitted or otherwise processed data, personal or other, commands, programs and configuration against any manipulation or modification not authorised by the user, and report on corruptions." | Clause 5.8 |
| Annex I, Part 1, (2)(g) | "Products with digital elements shall process only data, personal or other, that are adequate, relevant and limited to what is necessary in relation to the intended purpose of the product with digital elements (data minimisation)." | Clause 5.9 |
| Annex I, Part 1, (2)(h) | "Products with digital elements shall protect the availability of essential and basic functions, also after an incident, including through resilience and mitigation measures against denial-of-service attacks." | Clause 5.10 |
| Annex I, Part 1, (2)(i) | "Products with digital elements shall minimise the negative impact by the products themselves or connected products on the availability of services provided by other products or networks." | Clause 5.11 |
| Annex I, Part 1, (2)(j) | "Products with digital elements shall be designed, developed and produced to limit attack surfaces, including external interfaces." | Clause 5.12 |
| Annex I, Part 1, (2)(k) | "Products with digital elements shall be designed, developed and produced to reduce the impact of an incident using appropriate exploitation mitigation mechanisms and techniques." | Clause 5.13 |
| Annex I, Part 1, (2)(l) | "Products with digital elements shall provide security related information by recording and monitoring relevant internal activity, including the access to or modification of data, services or functions, with an opt-out mechanism for the user." | Clause 5.14 |
| Annex I, Part 1, (2)(m) | "Products with digital elements shall provide the possibility for users to securely and easily remove on a permanent basis all data and settings and, where such data can be transferred to other products or systems, ensure that this is done in a secure manner." | Clause 5.15 |
Presumption of conformity stays valid only as long as a reference to the present document is maintained in the list published in the Official Journal of the European Union. Users of the present document should consult frequently the latest list published in the Official Journal of the European Union.
Other Union legislation may be applicable to the product(s) falling within the scope of the present document.
# Annex B (informative): Security analysis <span id="_annex.b"></span>