Independent information resource Product security · EU CRA
Product controls / 06

Essential cybersecurity requirements

A readable entry point to Annex I product properties and vulnerability-handling requirements.

IN BRIEF

Annex I has two parts: cybersecurity properties of products and vulnerability handling. The risk assessment informs how requirements are implemented for the product.

How to organise an Annex I review
PartFocusProduct evidence to consider
ICybersecurity propertiesRisk decisions, design and verification
IIVulnerability handlingProcesses, updates and response records

Illustrative evidence categories, not a substitute for the Annex I text.

01 / 02

Product properties

Annex I addresses appropriate security by design and default, reduction of exploitable vulnerabilities, protection from unauthorised access, confidentiality, integrity, availability and limiting attack surfaces, among other requirements. Read the exact Annex I language for applicability and qualifications.

  • Translate each applicable provision into a product decision.
  • Connect the decision to a risk and a verification method.
  • Record the implementation in technical documentation.
02 / 02

Vulnerability handling

Manufacturers need processes to identify and remediate vulnerabilities, manage components, provide security updates and coordinate disclosure. The Annex sets the specific requirements.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.