Manufacturer shall implement only the recommended designs that are fit for the use-case.
As an example, when using TLS to protect the transport, only TLS v1.3 shall be used with one of the three cipher suites: TLS_AES_256_GCM_SHA384, TLS_AES_128_GCM_SHA256 or TLS_AES_128_CCM_SHA256.
For backwards compatibility, use of other combinations of options other what is recommended<ahref="_ref_1">[1]</a> shall be implemented with the following details listed in the technical documentation:
- What component requires lesser cryptogarphical implementation
- Statement about why the backwards compatibility is in place
- Transition plan towards recommended cryptographical impelmentation
- Transition timeline
## 5.3 Risk Mitigations
The following sections describe how technical security requirement in previous [Section 5.2](#52-technical-security-requirements-specifications) are mapped to the risk factors in [Section 4.5 Risk Factors](#45-risk-factors).