@@ -1064,7 +1064,7 @@ High requirement level shall implement all requirements in the defined set of re
| | MON_LOG | medium |
| | MON_LOG | high |
| all | MON_METRICS | all |
| all | RST_ | all |
| all | DRT_DELETE | all |
## 5.2 Appropriate level of cybersecurity
@@ -1652,10 +1652,12 @@ What metrics and logs can be collected is defined in more detail in [5.9 Data mi
## 5.15 Factory reset and data portability
<mark>_Proposed ESR code: RST_</mark>
This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 Part 1 (2) (m).
Due to complexity, and indstry wide use of various protocols and best practices, the support for data transfer is not required.
***DRT_DELETE-1** The product shall provide a function to remove all data and settings and restore to its secure-by-default state.
# 6 Assessment criteria for compliance with technical requirements
The assessment has the purpose to verify that the requirements of the present standard are met in consideration of the use case and the thereout resulting risks.
@@ -3928,6 +3930,33 @@ Outcomes:
## 6.15 Factory reset and data portability
### 6.15.1 DRT_DELETE-1
**Objective:** Remove <br/>
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials.
2. Study the technical documentation
**Activities:**
1. Change the product state in a way, that generates storable information to all data storage solutions.
2. Perform deletion as instructed.
3. Investigate the data storage used in product.
**Verdict:**
1. Pass, if generated data was removed from all storage solutions.
2. Fail otherwise.
**Supporting Evidence:**
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
* Logs, configuration files, or audit traces demonstrating the implementation of the requirement;
# Annex A (informative): Relationship between the present document and the requirements of EU Regulation (EU) 2024/2847 - the Cyber Resilience Act
<mark>Editor's Note: Even if informative, this Annex is mandatory in Harmonised Standards.</mark>