Commit e6fc1615 authored by Valerie Aurora's avatar Valerie Aurora
Browse files

Update Annex A to revised structure

closes #104
parent fd11d83f
Loading
Loading
Loading
Loading
+97 −25
Original line number Diff line number Diff line
@@ -2108,31 +2108,103 @@ Fail otherwise.



# Annex A (informative): Mapping between the present document and CRA essential requirements

The present document has been prepared under the Commission's standardisation request C(2025)618 [i.3] to provide one voluntary means of conforming to the requirements of Regulation (EU) 2024/2847 [i.1] known as the Cyber Resilience Act (CRA).

Once the present document is cited in the Official Journal of the European Union under that Regulation, compliance with the normative clauses of the present document given in table A.1 confers, within the limits of the scope of the present document, a presumption of conformity with the corresponding requirements of that Regulation and associated EFTA regulations.

| No. | Description                                          | CRA Esentail Requirements  | Cybersecurity Requirements(s)           |
|-----|------------------------------------------------------|----------------------------|-----------------------------------------|
| 1   | Secure design, development, production               | Annex I, Part I, (1)       | TR-SSDD, TR-LMII                        |
| 2   | No known exploitable vulnerabilities                 | Annex I, Part I, (2)(a)    | TR-NKEV                                 |
| 3   | Secure by default configuration                      | Annex I, Part I, (2)(b)    | TR-SDEF                                 |
| 4   | Secure updates                                       | Annex I, Part I, (2)(c)    | TR-SCUD                                 |
| 5   | Authentication and access control mechanisms         | Annex I, Part I, (2)(d)    | TR-AUTH\*                               |
| 6   | Confidentiality of store and transmitted information | Annex I, Part I, (2)(e)    | TR-CDST, TR-CDTX, TR-CRYP\*             |
| 7   | Integrity protection for data and configuration      | Annex I, Part I, (2)(f)    | TR-IDST, TR-IDTX                        |
| 8   | Data minimization                                    | Annex I, Part I, (2)(g)    | TR-DMIN                                 |
| 9   | Availability protection                              | Annex I, Part I, (2)(h)    | TR-AVAI, TR-LMII                        |
| 10  | Minimize impact on other devices or services         | Annex I, Part I, (2)(i)    | TR-MINI, TR-SDEF, TR-AVAI, TR-SSDD, TR-LMII     |
| 11  | Limit attack surface                                 | Annex I, Part I, (2)(j)    | TR-LMAS, TR-SSDD, TR-LMII               |
| 12  | Exploit mitigation by limiting incident impact       | Annex I, Part I, (2)(k)    | TR-LMII, TR-AVAI, TR-SSD                |
| 13  | Logging and monitoring mechanisms                    | Annex I, Part I, (2)(l)    | TR-LOGG                                 |
| 14  | Secure deletion and data transfer                    | Annex I, Part I, (2)(m)    | TR-SCDL, TR-SDTR                        |
| 15  | Vulnerability handling                               | Annex I, Part II           | TR-VULH                                 |

\* _waiting on cross-vertical_
# Annex A (informative): Relationship between the present document and the requirements of EU Regulation (EU) 2024/2847 - the Cyber Resilience Act

<mark>Editor's Note: Even if informative, this Annex is mandatory in Harmonised Standards.</mark>

The present document has been prepared in response to the Commission's standardisation request C(2025)618 [\[i.3\]](#_ref_i.3) to provide, in additions to its other uses, one voluntary means of conforming to the essential requirements of Regulation (EU) 2024/2847 [\[i.2\]](#_ref_i.2) known as the Cyber Resilience Act (CRA).

Once the present document is cited in the Official Journal of the European Union under Regulation (EU) 2024/2847 [\[i.1\]](#_ref_i.1), conformance with the normative clauses of the present document given in the tables in Annex A confers, to products with digital elements in the scope of the present document, a presumption of conformity with the corresponding essential requirements of that Regulation and associated EFTA regulations.  

**Table A.1: Correspondence between the European Stnadard and Annex I Part I of Regulation (EU) 2024/2847 **<a name="table_A.1"></a>

+-------------------------+----------------------------------------------------------------------------------+-----------------------------------+-----+-----------------------------------------------------------------------+
| Description             | Requirements of Regulation                                                       | Clause(s) of the present document | U/C | Condition                                                             |
+:========================+:=================================================================================+:==================================+:====+:======================================================================+
| Annex I, Part 1, (1)    | "Products with digital elements shall be designed, developed and produced in     | Clause 5                          | C   | See mapping table on the applicability of the technical cybersecurity |
|                         | such a way that they ensure an appropriate\                                      |                                   |     | requirements in clause 5.1                                            |
|                         | level of cybersecurity based on the risks."                                      |                                   |     |                                                                       |
+-------------------------+----------------------------------------------------------------------------------+-----------------------------------+-----+-----------------------------------------------------------------------+
| Annex I, Part 1, (2)(a) | "Products with digital elements shall be made available on the market without    | Clause 5.2                        | U/C |                                                                       |
|                         | known exploitable vulnerabilities."                                              |                                   |     |                                                                       |
+-------------------------+----------------------------------------------------------------------------------+-----------------------------------+-----+-----------------------------------------------------------------------+
| Annex I, Part 1, (2)(b) | "Products with digital elements shall be made available on the market with a     | Clause 5.3                        | U/C |                                                                       |
|                         | secure by default configuration, unless otherwise agreed between manufacturer    |                                   |     |                                                                       |
|                         | and business user in relation to a tailor-made product with digital elements,    |                                   |     |                                                                       |
|                         | including the possibility to reset the product to its original state."           |                                   |     |                                                                       |
+-------------------------+----------------------------------------------------------------------------------+-----------------------------------+-----+-----------------------------------------------------------------------+
| Annex I, Part 1, (2)(c) | "Products with digital elements shall ensure that vulnerabilities can be         | Clause 5.4                        | U/C |                                                                       |
|                         | addressed through security updates, including, where applicable, through         |                                   |     |                                                                       |
|                         | automatic security updates that are installed within an appropriate timeframe    |                                   |     |                                                                       |
|                         | enabled as a default setting, with a clear and easy-to-use opt-out mechanism,    |                                   |     |                                                                       |
|                         | through the notification of available updates to users, and the option to        |                                   |     |                                                                       |
|                         | temporarily postpone them"                                                       |                                   |     |                                                                       |
+-------------------------+----------------------------------------------------------------------------------+-----------------------------------+-----+-----------------------------------------------------------------------+
| Annex I, Part 1, (2)(d) | "Products with digital elements shall ensure protection from unauthorised access | Clause 5.5                        | U/C |                                                                       |
|                         | by appropriate control mechanisms, including but not limited to authentication,  |                                   |     |                                                                       |
|                         | identity or access management systems, and report on possible unauthorised       |                                   |     |                                                                       |
|                         | access"                                                                          |                                   |     |                                                                       |
+-------------------------+----------------------------------------------------------------------------------+-----------------------------------+-----+-----------------------------------------------------------------------+
| Annex I, Part 1, (2)(e) | "Products with digital elements shall protect the confidentiality of stored,     | Clause 5.6                        | U/C |                                                                       |
|                         | transmitted or otherwise processed data, personal or other, such as by           |                                   |     |                                                                       |
|                         | encrypting relevant data at rest or in transit by best practice mechanisms, and  |                                   |     |                                                                       |
|                         | by using other technical means."                                                 |                                   |     |                                                                       |
+-------------------------+----------------------------------------------------------------------------------+-----------------------------------+-----+-----------------------------------------------------------------------+
| Annex I, Part 1, (2)(f) | "Products with digital elements shall protect the integrity of stored,           | Clause 5.7                        | U/C |                                                                       |
|                         | transmitted or otherwise processed data, personal or other, commands, programs   |                                   |     |                                                                       |
|                         | and configuration against any manipulation or modification not authorised by the |                                   |     |                                                                       |
|                         | user, and report on corruptions."                                                |                                   |     |                                                                       |
+-------------------------+----------------------------------------------------------------------------------+-----------------------------------+-----+-----------------------------------------------------------------------+
| Annex I, Part 1, (2)(g) | "Products with digital elements shall process only data, personal or other, that | Clause 5.8                        | U/C |                                                                       |
|                         | are adequate, relevant and limited to what is necessary in relation to the       |                                   |     |                                                                       |
|                         | intended purpose of the product with digital elements (data minimisation)."      |                                   |     |                                                                       |
+-------------------------+----------------------------------------------------------------------------------+-----------------------------------+-----+-----------------------------------------------------------------------+
| Annex I, Part 1, (2)(h) | "Products with digital elements shall protect the availability of essential and  | Clause 5.9                        | U/C |                                                                       |
|                         | basic functions, also after an incident, including through resilience and        |                                   |     |                                                                       |
|                         | mitigation measures against denial-of-service attacks."                          |                                   |     |                                                                       |
+-------------------------+----------------------------------------------------------------------------------+-----------------------------------+-----+-----------------------------------------------------------------------+
| Annex I, Part 1, (2)(i) | "Products with digital elements shall minimise the negative impact by the        | Clause 5.10                       | U/C |                                                                       |
|                         | products themselves or connected products on the availability of services        |                                   |     |                                                                       |
|                         | provided by other products or networks."                                         |                                   |     |                                                                       |
+-------------------------+----------------------------------------------------------------------------------+-----------------------------------+-----+-----------------------------------------------------------------------+
| Annex I, Part 1, (2)(j) | "Products with digital elements shall be designed, developed and produced to     | Clause 5.11                       | U/C |                                                                       |
|                         | limit attack surfaces, including external interfaces."                           |                                   |     |                                                                       |
+-------------------------+----------------------------------------------------------------------------------+-----------------------------------+-----+-----------------------------------------------------------------------+
| Annex I, Part 1, (2)(k) | "Products with digital elements shall be designed, developed and produced to     | Clause 5.12                       | U/C |                                                                       |
|                         | reduce the impact of an incident using appropriate exploitation mitigation       |                                   |     |                                                                       |
|                         | mechanisms and techniques."                                                      |                                   |     |                                                                       |
+-------------------------+----------------------------------------------------------------------------------+-----------------------------------+-----+-----------------------------------------------------------------------+
| Annex I, Part 1, (2)(l) | "Products with digital elements shall provide security related information by    | Clause 5.13                       | U/C |                                                                       |
|                         | recording and monitoring relevant internal activity, including the access to or  |                                   |     |                                                                       |
|                         | modification of data, services or functions, with an opt-out mechanism for the   |                                   |     |                                                                       |
|                         | user."                                                                           |                                   |     |                                                                       |
+-------------------------+----------------------------------------------------------------------------------+-----------------------------------+-----+-----------------------------------------------------------------------+
| Annex I, Part 1, (2)(m) | "Products with digital elements shall provide the possibility for users to       | Clause 5.14                       | U/C |                                                                       |
|                         | securely and easily remove on a permanent basis all data and settings and, where |                                   |     |                                                                       |
|                         | such data can be transferred to other products or systems, ensure that this is   |                                   |     |                                                                       |
|                         | done in a secure manner."                                                        |                                   |     |                                                                       |
+-------------------------+----------------------------------------------------------------------------------+-----------------------------------+-----+-----------------------------------------------------------------------+
| Annex I, Part 2         |                                                                                  | Clause 5.15                       | U   |                                                                       |
+-------------------------+----------------------------------------------------------------------------------+-----------------------------------+-----+-----------------------------------------------------------------------+

> NOTE 1: The table cannot indicate direct relationship between the relevant legal requirement and **_other_** standards or normative clauses contained in **_other_** standards.

> NOTE 2: If the standard is developed according to the structure in the present skeleton document, then the number of the clauses in the table below don't need to be changed.

**Key to columns:**

**Requirement:**

**Description** A textual reference to the requirement.

**Requirements of Regulation** Identification of article(s) defining the requirement in the Regulation.

**Clause(s) of the present document** Identification of clause(s) defining the requirement in the present document unless another document is referenced explicitly.  

<mark>Editor’s Note: When referencing clause(s) of the present document to evidence fulfilment of essential requirements, ensure full coverage of the essential requirement with regard to all elements of the legal definition thereof. To this end, validate referenced content against the definition after the fact to ensure no angle has been missed.</mark>

Presumption of conformity stays valid only as long as a reference to the present document is maintained in the list published in the Official Journal of the European Union. Users of the present document should consult frequently the latest list published in the Official Journal of the European Union.
Other Union legislation may be applicable to the product(s) falling within the scope of the present document.

# Annex B (informative): Relationship between the present document and any related ETSI standards (if any)