@@ -1434,6 +1434,7 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
***SU_UPDATES-1** The product shall have the ability to receive security updates.
***SU_UPDATES-2** The product shall have independent OS and application update procedures enabling the user to schedule the update following the operational needs and the High Availability targets.
***SU_UPDATES-3** The product shall by default attempt to install security updates at the time of first use to address all known exploitable vulnerabilities which were discovered after the product's placement on the market and before first use.
* This requirement applies to subset of products that are not updated by the OE.
***SU_UPDATES-4:** The product shall verify authenticity and integrity of the update package using a cryptographic signature verification prior to installation.
* This requirement applies to subset of products that are not updated by the OE
***SU_UPDATES-5:** The product shall maintain a monotonic version counter or equivalent mechanism to prevent installation of updates with an older version.