@@ -802,8 +802,8 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
### 5.3.3 SDBC - Cryptography
- REFERENCE: REQ-PKI-SBDC-03
- REQUIREMENT: All cryptographic mechanisms shall be configured by default in conformity to Annex K requirements.
- RATIONALE: XXX
- REQUIREMENT: All cryptographic mechanisms shall be configured by default in conformity to the general state of the art as defined in Annex K.
- RATIONALE: Cf. Annex K rational.
- APPLICABILITY: All use cases.
### 5.3.4 SDBC - Certificates
@@ -885,7 +885,7 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
- REFERENCE: REQ-PKI-CON-02
- REQUIREMENT: Where the private key is stored in a cryptographically protected way, the cryptographic mechanisms shall conform to the general state of the art as defined in Annex K.
- RATIONALE: The use of recognized and validated cryptographic algorithms is mandatory for a PKI and thus a PKI product to ensure trust. Known weak or insufficiently validated algorithms are not allowed.
- RATIONALE: Cf. Annex K rational.
- APPLICABILITY: UC2, UC3, UC4 and UC5
- REFERENCE: REQ-PKI-CON-03
@@ -912,7 +912,7 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
- APPLICABILITY: XXXX
- REFERENCE: REQ-PKI-CON-07
- REQUIREMENT: The product shall implement cryptographic mechanisms as defined in Annex K and L to encrypt and decrypt, and sign and verify content.
- REQUIREMENT: The cryptographic mechanisms used to sign and verify content shall conform to the general state of the art, as defined in Annex K.
- RATIONALE: XXX
- NOTE: If the product is intended for a specific environment with a defined set of agreed cryptographic mechanisms, the product has to be able to be used in accordance with those cryptographic requirements.
- APPLICABILITY: XXXX
@@ -926,7 +926,7 @@ This clause addresses the requirements in the CRA [\[i.1\]](#_ref_i.1) Annex 1 P
### 5.6.2 Secure storage and communications
- REFERENCE: REQ-PKI-INT-06
- REQUIREMENT: The product shall implement cryptographic mechanisms as defined in Annex K and L to encrypt and decrypt content.
- REQUIREMENT: The cryptographic mechanisms used to encrypt and decrypt content shall conform to the general state of the art, as defined in Annex K.
- RATIONALE:
- APPLICABILITY: All use cases where the product implements encryption mechanisms either for data storage or external communications.
- NOTE: If the product is intended for a specific environment with a defined set of agreed cryptographic mechanisms, the product has to be able to be used in accordance with those cryptographic requirements.
@@ -3641,9 +3641,11 @@ Note for Gisela, Clauses have been renumbered for consistency.
The product shall, by default, use State-of-the-Art cryptography algorithms listed in (CRY-SOTA), to be used for the supported security mechanism of the product where applicable.
- RATIONALE: Cryptographic mechanisms are the foundation of trust, integrity, and authenticity in digital systems. Using state-of-the-art cryptographic algorithms and protocols ensures protection against known vulnerabilities and cryptographic attacks. Failure to conform to CRY-SOTA risks compromising the integrity of signed content, enabling spoofing, tampering, or repudiation attacks, and undermining the overall security posture of the system.
> NOTE 1: The use of security mechanism e.g. authentication, access control, secure communication, secure storage and secure update are described in the main text of this standard.
> NOTE 2: Cryptographic algorithm primitives (in short, algorithms e.g. public- and private-key encryption algorithms, hash functions, authentication codes, digital signatures) are classified as CRY-SOTA if they are listed in the _ref_i.9 document and are suitable for the implementation of supported security mechanisms of the product.
> NOTE 2: Cryptographic algorithm primitives (in short, algorithms e.g. public- and private-key encryption algorithms, hash functions, authentication codes, digital signatures) are classified as CRY-SOTA if they are listed in the [\[i.9\]](#_ref_i.9) document and are suitable for the implementation of supported security mechanisms of the product.
> NOTE 3 Supporting evidence options that an algorithm, which is not included in CRY-SOTA, is applicable and suitable for the respective use case, are listed in the related assessment criteria ( K.1.2.1) clause.