@@ -769,7 +769,8 @@ The multi-authority PKI is intended to combine multiple authorities in a single
The technical requirements of the present document apply under the product context described in Clause 4, which shall be in accordance with its intended use. The equipment shall comply with all applicable technical requirements of the present document at all times when operating in such product context.
The applicability of the requirements to the Use Cases / Security Profiles are defined below:
See the applicability fields associated with each technical cybersecurity requirement in the following Clause 5 subsections.
## 5.2 No known exploitable vulnerabilities
@@ -2172,7 +2173,7 @@ Once the present document is cited in the Official Journal of the European Union
|No |Description |Requirements of Regulation |Clause(s) of the present document |U/C |Condition |
|---|---|---|---|---|---|
|1| Annex I, Part 1, (1)|“Products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks.” | Clause 5 | C | See mapping table on the applicability of the technical cybersecurity requirements in clause 5.1|
|1| Annex I, Part 1, (1)|“Products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks.” | Clause 5 | C | See applicability field associated to each technical cybersecurity requirements in clause 5.|
|2|Annex I, Part 1, (2)(a)|“Products with digital elements shall be made available on the market without known exploitable vulnerabilities.”|Clause 5.2|U/C| |
|3| Annex I, Part 1, (2)(b)| “Products with digital elements shall be made available on the market with a secure by default configuration, unless otherwise agreed between manufacturer and business user in relation to a tailor-made product with digital elements, including the possibility to reset the product to its original state.”| Clause 5.3| U/C| |
|4| Annex I, Part 1, (2)(c)| “Products with digital elements shall ensure that vulnerabilities can be addressed through security updates, including, where applicable, through automatic security updates that are installed within an appropriate timeframe enabled as a default setting, with a clear and easy-to-use opt-out mechanism, through the notification of available updates to users, and the option to temporarily postpone them”| Clause 5.4| U/C| |