CRA Annex I — cybersecurity requirements and evidence overview
An overview of CRA product security and vulnerability handling, linked manufacturer duties, reporting paths, retention and evidence for a product-specific assessment.
By CenitiaUpdated
Annex I is a risk-based set of product-security and vulnerability-handling requirements. Part I point 2 uses letters (a)–(m), not separate points (3)–(13). Match each applicable requirement to implementation and test evidence for the final configuration.
Cybersecurity and vulnerability handling
Part I point 1 establishes risk-based appropriate cybersecurity. Point 2(a)-(m) addresses known exploitable vulnerabilities, secure defaults, updates, access control, confidentiality, integrity, data minimisation, availability, network effects, attack surface, exploitation mitigation, logging, and secure permanent erasure/easy secure transfer of data. Apply requirements on the statutory risk-based conditions. Part II covers vulnerability identification/documentation including SBOM, remediation, testing, disclosure, contact, secure distribution and timely security updates. A proposed control or file count is not evidence that the control was tested.
Manufacturer duties, lifetime and retention
Document cybersecurity risk assessment and technical evidence; do not infer conformity from an AI draft. Article 13(8): determine support with expected use and reasonable user expectations; normally at least five years, or shorter where expected use is shorter. Consider longer expected use. Article 13(13): retain technical documentation and DoC for ten years after placing on the market or the support period, whichever is longer. Annex VII specifies technical-documentation content.
Two reporting paths and final triggers
Manufacturers report actively exploited vulnerabilities and severe security incidents through the Single Reporting Platform. Both have 24-hour early warnings and 72-hour notifications from awareness. Article 14(2)(c): vulnerability final report within 14 days after a corrective or mitigating measure becomes available. Article 14(4)(c): severe-incident final report within one month after the 72-hour notification. Severity criteria are Article 14(5), not Annex VI. Do not invent a fixed monthly progress-report duty. Manufacturer reporting applies from 11 September 2026. The ENISA platform is operational.
Penalty categories
Article 64(2) covers specified Annex I and Articles 13/14 non-compliance, with a maximum of EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher. Other categories have different limits. Article 64(10)(a) contains a micro/small enterprise exception concerning failure to meet the early-warning deadline, not exemption from reporting duties. Maximum penalties are not automatic fines or proof of personal liability for every signer.
Evidence to keep with the product
Record the intended purpose, responsible economic operator, target market, first placing date and exact hardware/firmware configuration. For each applicable requirement, link the actual test or assessment record, dated standard/specification, scope and reviewer decision. Proposed controls and supplier marketing statements are not evidence that the final configuration has passed an assessment.
Separate an open question from a completed assessment. A report outside the laboratory's relevant scope, a different firmware build or an unverified exemption needs a reasoned decision before it supports a declaration. Keep original evidence and the issued declaration alongside any AI-assisted working draft.
Using Cenitia for this work
Cenitia assists with a limited regulatory catalogue and draft documents. The manufacturer must confirm applicability, actual applied specifications and completed assessment procedures. AI scores are quality signals, not a probability of conformity. Source monitoring raises a review prompt when validated source text changes; it does not automatically verify amendments, update the corpus or monitor every national rule and OJ standard edition. Public QR verification records issuance, not product certification.
Review status
This guide was substantively corrected by Cenitia on 2 October 2026 using the primary references below. It is an editorial summary, not an authoritative legal quotation or an independently signed expert opinion. Product-specific and licensed-standard questions remain subject to a real technical review.
Primary references
FAQ
Frequently asked questions
Does an AI draft or QR verification prove conformity?
No. The manufacturer must establish scope and satisfy applicable requirements using actual evidence. QR verification records issuance, not product certification.
What information must be checked for this product?
Confirm intended use, role, market/date, final configuration, dated specifications, assessment route and evidence scope. Record unresolved questions and a real reviewer decision.
Continue reading
Related guides
tutorial
Coordinated Vulnerability Disclosure Policy for Hardware Manufacturers
Build a usable hardware vulnerability disclosure policy with intake owners, safe testing boundaries and a security.txt example.
4 min read
reference
CRA for existing products already on the EU market: the Article 69 transitional rules
CRA Article 69 explained: grandfathering for products placed on the EU market before 11 December 2027, substantial modification test, Article 14 reporting carve-back.
14 min read
comparison
ISO/IEC 27001 vs CRA — when to certify both
ISO/IEC 27001:2022 is an organisational ISMS standard; the EU Cyber Resilience Act is a product-level regulation. Where they overlap, where they don't, and why you need both.
9 min read
tutorial
CRA December 2027 readiness — scope, assessment and evidence checks
Key checks before CRA main product obligations apply: legacy products and modifications, support and retention, assessment route, declaration and technical evidence.
3 min read
Put this into practice
Free tools & references
- CRA Readiness CheckerScore your product against the Cyber Resilience Act essential requirements.Open tool →
- EU Directive SelectorDescribe your product and find which EU directives and regulations apply.Open tool →
New to the terminology? Browse the compliance glossary — plain-English, citation-backed definitions of every term above.