@@ -2085,6 +2085,13 @@ Once the present document is cited in the Official Journal of the European Union
|1| Annex I, Part 1, (1)|“Products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks.” | Clause 5 | C | See mapping table on the applicability of the technical cybersecurity requirements in clause 5.1|
|2|Annex I, Part 1, (2)(a)|“Products with digital elements shall be made available on the market without known exploitable vulnerabilities.”|Clause 5.2|U/C| |
|3| Annex I, Part 1, (2)(b)| “Products with digital elements shall be made available on the market with a secure by default configuration, unless otherwise agreed between manufacturer and business user in relation to a tailor-made product with digital elements, including the possibility to reset the product to its original state.”| Clause 5.3| U/C| |
|4| Annex I, Part 1, (2)(c)| “Products with digital elements shall ensure that vulnerabilities can be addressed through security updates, including, where applicable, through automatic security updates that are installed within an appropriate timeframe enabled as a default setting, with a clear and easy-to-use opt-out mechanism, through the notification of available updates to users, and the option to temporarily postpone them”| Clause 5.4| U/C| |
|5| Annex I, Part 1, (2)(d)| “Products with digital elements shall ensure protection from unauthorised access by appropriate control mechanisms, including but not limited to authentication, identity or access management systems, and report on possible unauthorised access”| Clause 5.5 | U/C | |
|6| Annex I, Part 1, (2)(e)| “Products with digital elements shall protect the confidentiality of stored, transmitted or otherwise processed data, personal or other, such as by encrypting relevant data at rest or in transit by best practice mechanisms, and by using other technical means.”| Clause 5.6 | U/C | |
|7| Annex I, Part 1, (2)(f)| “Products with digital elements shall protect the integrity of stored, transmitted or otherwise processed data, personal or other, commands, programs and configuration against any manipulation or modification not authorised by the user, and report on corruptions.” | Clause 5.7 | U/C | |
|8| Annex I, Part 1, (2)(g)| “Products with digital elements shall process only data, personal or other, that are adequate, relevant and limited to what is necessary in relation to the intended purpose of the product with digital elements (data minimisation).”| Clause 5.8| U/C | |
|9| Annex I, Part 1, (2)(h)| “Products with digital elements shall protect the availability of essential and basic functions, also after an incident, including through resilience and mitigation measures against denial-of-service attacks.”| Clause 5.9| U/C| |
|10| Annex I, Part 1, (2)(i)| “Products with digital elements shall minimise the negative impact by the products themselves or connected products on the availability of services provided by other products or networks.” | Clause 5.10 | U/C | |
|(2)| in relation to the risks posed to products with digital elements, address and remediate vulnerabilities without delay, including by providing security updates; where technically feasible, new security updates shall be provided separately from functionality updates; | 6.1
|(3)| Apply effective and regular tests and reviews of the security of the product with digital elements; | 6.1