# Annex A (informative): Mapping between the present document and CRA essential requirements
The present document has been prepared under the Commission's standardisation request C(2025)618 [i.3] to provide one voluntary means of conforming to the requirements of Regulation (EU) 2024/2847 [i.1] known as the Cyber Resilience Act (CRA).
Once the present document is cited in the Official Journal of the European Union under that Regulation, compliance with the normative clauses of the present document given in table A.1 confers, within the limits of the scope of the present document, a presumption of conformity with the corresponding requirements of that Regulation and associated EFTA regulations.
| 1 | Secure design, development, production | Annex I, Part I, (1) | TR-SSDD, TR-LMII |
| 2 | No known exploitable vulnerabilities | Annex I, Part I, (2)(a) | TR-NKEV |
| 3 | Secure by default configuration | Annex I, Part I, (2)(b) | TR-SDEF |
| 4 | Secure updates | Annex I, Part I, (2)(c) | TR-SCUD |
| 5 | Authentication and access control mechanisms | Annex I, Part I, (2)(d) | TR-AUTH\* |
| 6 | Confidentiality of store and transmitted information | Annex I, Part I, (2)(e) | TR-CDST, TR-CDTX, TR-CRYP\* |
| 7 | Integrity protection for data and configuration | Annex I, Part I, (2)(f) | TR-IDST, TR-IDTX |
| 8 | Data minimization | Annex I, Part I, (2)(g) | TR-DMIN |
| 9 | Availability protection | Annex I, Part I, (2)(h) | TR-AVAI, TR-LMII |
| 10 | Minimize impact on other devices or services | Annex I, Part I, (2)(i) | TR-MINI, TR-SDEF, TR-AVAI, TR-SSDD, TR-LMII |
| 11 | Limit attack surface | Annex I, Part I, (2)(j) | TR-LMAS, TR-SSDD, TR-LMII |
| 12 | Exploit mitigation by limiting incident impact | Annex I, Part I, (2)(k) | TR-LMII, TR-AVAI, TR-SSD |
| 13 | Logging and monitoring mechanisms | Annex I, Part I, (2)(l) | TR-LOGG |
| 14 | Secure deletion and data transfer | Annex I, Part I, (2)(m) | TR-SCDL, TR-SDTR |
| 15 | Vulnerability handling | Annex I, Part II | TR-VULH |
\* _waiting on cross-vertical_
# Annex A (informative): Relationship between the present document and the requirements of EU Regulation (EU) 2024/2847 - the Cyber Resilience Act
<mark>Editor's Note: Even if informative, this Annex is mandatory in Harmonised Standards.</mark>
The present document has been prepared in response to the Commission's standardisation request C(2025)618 [\[i.3\]](#_ref_i.3) to provide, in additions to its other uses, one voluntary means of conforming to the essential requirements of Regulation (EU) 2024/2847 [\[i.2\]](#_ref_i.2) known as the Cyber Resilience Act (CRA).
Once the present document is cited in the Official Journal of the European Union under Regulation (EU) 2024/2847 [\[i.1\]](#_ref_i.1), conformance with the normative clauses of the present document given in the tables in Annex A confers, to products with digital elements in the scope of the present document, a presumption of conformity with the corresponding essential requirements of that Regulation and associated EFTA regulations.
**Table A.1: Correspondence between the European Stnadard and Annex I Part I of Regulation (EU) 2024/2847 **<aname="table_A.1"></a>
| Annex I, Part 1, (1) | "Products with digital elements shall be designed, developed and produced in | Clause 5 | C | See mapping table on the applicability of the technical cybersecurity |
| | such a way that they ensure an appropriate\ | | | requirements in clause 5.1 |
| | level of cybersecurity based on the risks." | | | |
> NOTE 1: The table cannot indicate direct relationship between the relevant legal requirement and **_other_** standards or normative clauses contained in **_other_** standards.
> NOTE 2: If the standard is developed according to the structure in the present skeleton document, then the number of the clauses in the table below don't need to be changed.
**Key to columns:**
**Requirement:**
**Description** A textual reference to the requirement.
**Requirements of Regulation** Identification of article(s) defining the requirement in the Regulation.
**Clause(s) of the present document** Identification of clause(s) defining the requirement in the present document unless another document is referenced explicitly.
<mark>Editor’s Note: When referencing clause(s) of the present document to evidence fulfilment of essential requirements, ensure full coverage of the essential requirement with regard to all elements of the legal definition thereof. To this end, validate referenced content against the definition after the fact to ensure no angle has been missed.</mark>
Presumption of conformity stays valid only as long as a reference to the present document is maintained in the list published in the Official Journal of the European Union. Users of the present document should consult frequently the latest list published in the Official Journal of the European Union.
Other Union legislation may be applicable to the product(s) falling within the scope of the present document.
# Annex B (informative): Relationship between the present document and any related ETSI standards (if any)