@@ -66,25 +66,21 @@ In the present document "**shall**", "**shall not**", "**should**", "**should no
The present document provides the technical cybersecurity requirements for the products in scope, following a risk-based approach in support of the Cyber Resilience Act (CRA) [\[i.1\]](#_ref_i.1). The technical cybersecurity requirements are thereby proportionate to the intended purpose, reasonably foreseeable use, deployment context, and threat exposure of the products.
Clause 4 does not contain technical requirements; it describes the product architecture and intended purpose in their context.
[Clause 4](#4-product-context) does not contain technical requirements; it describes the product architecture and intended purpose in their context.
Clause 4 also defines Use Cases (UCs) that represent the main deployment scenarios reflecting the intended purpose and reasonably foreseeable use of the product, which serve as the basis for identifying relevant cybersecurity risks.
Clause 5 specifies technical cybersecurity requirements for the product to mitigate the identified risks, including their applicability conditions.
[Clause 5](#5-technical-requirements-for-the-products) specifies technical cybersecurity requirements for the product to mitigate the identified risks, including their applicability conditions.
Clause 6 specifies the assessment criteria and compliance verification procedures with the requirements of Clause 5.
[Clause 6](#6-assessment-criteria-for-compliance-with-technical-requirements) specifies the assessment criteria and compliance verification procedures with the requirements of Clause 5.
Annex A maps the technical requirements of the present document with the essential requirements of the CRA [\[i.1\]](#_ref_i.1) regulation.
[Annex A](#annex-a-informative-relationship-between-the-present-document-and-the-requirements-of-eu-regulation-eu-20242847---the-cyber-resilience-act) maps the technical requirements of the present document with the essential requirements of the CRA [\[i.1\]](#_ref_i.1) regulation.
Annex B informs about the methodology used to assess the security risks of the products in their context. Where a product does not clearly correspond to one of the defined Use Cases of Clause 4, the risk assessment methodology of Annex B may be used to determine the applicable cybersecurity requirements.
[Annex B](#annex-b-informative-security-analysis) informs about the methodology used to assess the security risks of the products in their context. Where a product does not clearly correspond to one of the defined Use Cases of Clause 4, the risk assessment methodology of Annex B may be used to determine the applicable cybersecurity requirements.
<mark>Editor’s Note: Where the functionality of the product relies on cryptography, then Annex K shall be included and instantiated in the CRA Vertical standard to provide presumption of conformity with regards to cryptographic mechanisms embarked in the product.</mark>
[Annex K](#annex-k-normative-generic-cryptographic-requirements-and-assessment) supports the definition of the cryptographic requirements and assessment criteria used by the present document.
Annex K supports the definition of the cryptographic requirements and assessment criteria used by the present document.
<mark>Editor’s Note: The following annexes are optional (may or may not be included in the vertical):</mark>
Annex R provides supplementary requirements and assessment provisions where a product relies on remote data processing solutions (RDPS) for the provision or support of one or more product functions.
[Annex R](#annex-r-normative-additional-provisions-for-products-relying-on-remote-data-processing-solutions-rdps) provides supplementary requirements and assessment provisions where a product relies on remote data processing solutions (RDPS) for the provision or support of one or more product functions.
> NOTE: Annex R may be used by vertical standards where RDPS-specific security considerations are relevant and are not already addressed by the core requirements of the concerned standard.