Title:Cybersecurity (CYBER); CRA; Cybersecurity requirements for network management systems
Spec Number:304 621
Version:v1.0.1
Version:v1.0.2
Date:2026-07-20
Release:1
Work Item:DEN/CYBER-EUS-009
@@ -1500,9 +1500,7 @@ These requirements apply to the product, regardless of the product's use case an
### 5.6.1 Machine users
***AAC_MACHINE-1** The product shall:
1. provide authentication for machine users which does not involve passwords, such as certificates, tokens with an expiration date, mutual TLS with per-subject certificates, signed short-lived assertions/credentials like client assertions or workload identity, or equivalent asymmetric-key-based authentication, and
2. exclude static shared secrets and long-lived bearer tokens as authentication methods for machine users.
***AAC_MACHINE-1** The product shall provide authentication for machine users such as certificates or tokens with a lifetime that is appropriate to the use case.
***AAC_MACHINE-2** The product shall minimize access for the machine user to privileged interfaces like APIs.