@@ -2366,17 +2366,17 @@ The product shall, by default, use State-of-the-Art cryptography algorithms list
#### K.1.2.1 Assessment objective:
The purpose of this assessment case is (the conceptual assessment) whether the implemented algorithms are identified as CRY-SOTA.
##### K.1.2.2 Assessment preparation:
#### K.1.2.2 Assessment preparation:
- Preconditions for the test: If applicable, the product is in the default- configuration. Otherwise, the product is in the delivery state, where it is available on the market in accordance with CRA Annex I part 1(2) (b).
##### K.1.2.3 Assessment activities:
#### K.1.2.3 Assessment activities:
- For every security mechanism the list of used algorithms, which are reachable over an external interface and identified as CRY- SOTA shall be documented.
##### K.1.2.4 Supporting Evidence:
#### K.1.2.4 Supporting Evidence:
- description of the performed test
- all test records of the performed test
##### K.1.2.5 Assignment of verdict:
#### K.1.2.5 Assignment of verdict:
- The verdict PASS shall be assigned if evidence has been provided.
- The verdict FAIL shall be assigned otherwise
If the verdict in K.1.2.1 has been assigned FAIL, the following assessment has to be performed additionally:
@@ -2384,21 +2384,21 @@ If the verdict in K.1.2.1 has been assigned FAIL, the following assessment has t
##### K.1.2.5.1 Assessment objective:
If for a certain security mechanism and use case no CRY-SOTA algorithm is applicable, evidence shall be
provided in the documentation that a suitable algorithm has been implemented for this evidence instead.
###### K.1.2.5.2 Assessment preparation:
##### K.1.2.5.2 Assessment preparation:
- Preconditions for the test: If applicable, the product is in the default configuration state. Otherwise, the product is in the delivery state, where it is available on the market in accordance with CRA Annex I part 1(2) (b).
###### K.1.2.5.3 Assessment activities:
##### K.1.2.5.3 Assessment activities:
For every security mechanism and for every used algorithm, which is reachable over an interface of the product and identified as not included in CRY- SOTA, the documentation shall provide evidence:
- that this algorithm is applicable and suitable for the respective use case
- that no CRY-SOTA algorithm is applicable // DO WE KEEP THIS? (GDC)
###### K.1.2.5.4 Supporting Evidence:
##### K.1.2.5.4 Supporting Evidence:
- 1. Identification of the certain algorithm by reference in further algorithm catalogues as national cryptographic catalogues 2 or vertical use case specific cryptographic algorithm catalogues
- 2. No entry of known exploitable vulnerabilities provided in ENISA “European Vulnerability Database.
- Description of the performed test
- all test records of the performed test
###### K.1.2.5.5 Assignment of verdict:
##### K.1.2.5.5 Assignment of verdict:
- The verdict PASS shall be assigned if respective evidence has been provided,
- The verdict FAIL shall be assigned otherwise.
@@ -2411,34 +2411,36 @@ algorithm will not stay SOTA anymore within the intended lifetime of the product
> NOTE 4: To maintain SOTA for cryptographic algorithm within the intended lifetime of the product concepts to consider are crypto agility additional to the capability of updating cryptographic algorithms on the product in accordance to Secure Update and Secure Communication mechanism.
> NOTE 5: The [ACM] listing has two classes of SOTA algorithms; Legacy mechanisms with an expiry date as defined in ACM, and Recommended mechanisms with no set expiry date.
> NOTE 5: Formal verification can use mathematical proofs and /or rigorous methods to prove an algorithm's correctness, ensuring it meets its formal specification for all valid inputs, unlike testing which only samples cases. This process involves creating formal models, using techniques like theorem proving or model checking, and is crucial for critical systems like cryptography finding hard-to-spot bugs and guaranteeing security/reliability.
> NOTE 6: For products or components of products that cannot have their cryptographic algorithms updated for example if the implementation or part uses a hardware-based root of trust, it is important that the intended lifetime of the equipment does not exceed the recommended usage lifetime of the cryptographic algorithms used by the product. Thereby the implementation of an algorithm can include the specific implementation of their parameters
> NOTE 6: The [ACM] listing has two classes of SOTA algorithms; Legacy mechanisms with an expiry date as defined in ACM, and Recommended mechanisms with no set expiry date.
> NOTE 7: If a component storing the algorithm or corresponding parameters of a main product is replaced
> NOTE 7: For products or components of products that cannot have their cryptographic algorithms updated for example if the implementation or part uses a hardware-based root of trust, it is important that the intended lifetime of the equipment does not exceed the recommended usage lifetime of the cryptographic algorithms used by the product. Thereby the implementation of an algorithm can include the specific implementation of their parameters
> NOTE 8: If a component storing the algorithm or corresponding parameters of a main product is replaced
by a new component, the product is considered as a new product according to the New Legislative Framework
Blue Guide4, if the replacement provides a substantial modification to the main product
### K.2.1 Assessment criteria
#### K.2.2.1 Assessment objective:
#### K.2.1.1 Assessment objective:
The purpose of this assessment case is (the conceptual assessment) whether the product is prepared to update
cryptographic algorithms for the supported security mechanism.
###### K.2.2.1.1 Assessment preparation:
#### K.2.1.2 Assessment preparation:
- Preconditions for the test: If applicable, the product is in the default- configuration. Otherwise, the
product is in the delivery state, where it is available on the market in accordance with CRA Annex I
part 1(2) (b).
###### K.2.2.1.2 Assessment activities:
#### K.2.1.3 Assessment activities:
- For every used SOTA algorithm, which is reachable over an interface, the life span of the algorithm is
documented, as well its property, if the algorithm is considered as legacy or recommended algorithm.5
documented, as well its property, if the algorithm is considered as legacy or recommended algorithm.
- If the life span of the product exceeds the life span of a legacy algorithm, the algorithm is marked as
updatable by a recommended algorithm in the documentation.
- If an algorithm is identified as SOTA recommended, no further action is required.
###### K.2.2.1.3 Supporting Evidence:
#### K.2.1.4 Supporting Evidence:
- Description /documentation of the performed test.
- All test records of the performed test.
###### K.2.2.1.4 Assignment of verdict:
#### K.2.1.5 Assignment of verdict:
- The verdict PASS shall be assigned if respective evidence has been provided,