@@ -58,14 +58,6 @@ In the present document "**shall**", "**shall not**", "**should**", "**should no
# Introduction
<mark>Editor’s Note: "Introduction" clause should introduce the structure of the document, motivating the purpose of each subclause and clearly stating which parts of the standard are normative and which parts are informative.</mark>
<mark>Editor’s Note: The clause should furthermore explain how the standard should be used. Readers should be given a concrete path to ensuring conformity of their product by guiding them through the document. This path may start with identification of the product at hand within the product context clause, move on to the security analysis annex to determine applicable technical requirements, proceed with implementing those technical requirements, and then finally end with conformity assessment criteria to evaluate proper implementation.</mark>
<mark>Editor’s Note: Moreover, the “Introduction” clause should clarify the general role of vertical standards in the CRA landscape of resources supporting manufacturers, explaining which relevant content is not contained therein and shall instead be sourced from the CRA itself, legal guidance for the CRA, and related standards (adjacent and overlapping verticals, prEN 40000-1-4, prEN 40000-1-2, prEN 40000-1-3).</mark>
<mark>Editor’s Note: Ready to use text is provided below that may be included in all CRA Vertical standards or replaced by more relevant or specific content in each vertical. You may also only use the parts of the text that are relevant for each standard.</mark>
The present document provides the technical cybersecurity requirements for the products in scope, following a risk-based approach in support of the Cyber Resilience Act (CRA) [\[i.1\]](#_ref_i.1). The technical cybersecurity requirements are thereby proportionate to the intended purpose, reasonably foreseeable use, deployment context, and threat exposure of the products.
[Clause 4](#4-product-context) does not contain technical requirements; it describes the product context that is considered for the application of the present document.
@@ -84,8 +76,6 @@ Clause 4 also defines Use Cases (UCs) that represent the main deployment scenari
[Annex R](#annex-r-normative-additional-provisions-for-products-relying-on-remote-data-processing-solutions-rdps) provides supplementary requirements and assessment provisions where a product relies on remote data processing solutions (RDPS) for the provision or support of one or more product functions.
Further information on guidance for the application of the present document is provided in Annex G.
# 1 Scope
The present document specifies technical requirements and corresponding assessment criteria for network management systems related to cybersecurity. The products with digital elements in scope, thereafter "NMS":
# Annex G: Guidelines on the implementation of the present document (informative):
<mark>Editor’s note: This Annex is optional and may be referred to from the Introduction of the document to provide more information on how to implement the standard.</mark>
# Annex K (normative): Generic cryptographic requirements and assessment