@@ -1434,7 +1434,9 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
***SU_UPDATES-2** The product shall have independent OS and application update procedures enabling the user to schedule the update following the operational needs and the High Availability targets.
***SU_UPDATES-3** The product shall by default attempt to install security updates at the time of first use to address all known exploitable vulnerabilities which were discovered after the product's placement on the market and before first use.
***SU_UPDATES-4:** The product shall verify authenticity and integrity of the update package using a cryptographic signature verification prior to installation.
* This requirement applies to subset of products that are not updated by the OE
***SU_UPDATES-5:** The product shall maintain a monotonic version counter or equivalent mechanism to prevent installation of updates with an older version.
* This requirement applies to subset of products that are not updated by the OE
***SU_UPDATES-6:** The product shall provide a mechanism to restore the system to the operational state after a failed update.
***SU_UPDATES-7:** The product shall provide a way for the system user to postpone or re-schedule the application update.
* This requirement applies to the subset of products that operate in an operational environment that allows for postponement or rescheduling of application updates.