**Objective:**The product user can remove all of his data from the product.
**Preparation:**
@@ -4110,6 +4110,33 @@ Outcomes:
* Logs, configuration files, or audit traces demonstrating the implementation of the requirement;
### 6.15.2 DRT_DELETE-2
**Objective:** If applicable, the product user can import or export data with a secure channel.
**Preparation:**
1. Have the product initialised and available with the default configuration and required credentials.
2. Study the technical documentation
3. Change the product state in a way that generates stored data and generate outside the product a data set
**Activities:**
1. Export the previously in-product generated data and verify that a secure protocol as out of CON_CRYPTO-1 is deployed
2. Import the externally present data set and verify that a secure protocol as out of CON_CRYPTO-1 is deployed
**Verdict:**
1. Pass, if for import and export a protocol as of **CON_CRYPTO-1** is deployed
2. Fail otherwise.
**Supporting Evidence:**
* Relevant vendor or design documentation describing the applied measures;
* Test reports showing the steps performed and results obtained;
* Screenshots, captures, or console outputs confirming the correct execution or protection behaviour;
* Logs, configuration files, or audit traces demonstrating the implementation of the requirement;
# Annex A (informative): Relationship between the present document and the requirements of EU Regulation (EU) 2024/2847 - the Cyber Resilience Act
The present document has been prepared in response to the Commission's standardisation request C(2025)618 [\[i.3\]](#_ref_i.3) to provide, in addition to its other uses, one voluntary means of conforming to the essential requirements of Regulation (EU) 2024/2847 [\[i.2\]](#_ref_i.2) known as the Cyber Resilience Act (CRA).