Annex I has two parts: cybersecurity properties of products and vulnerability handling. The risk assessment informs how requirements are implemented for the product.
| Part | Focus | Product evidence to consider |
|---|---|---|
| I | Cybersecurity properties | Risk decisions, design and verification |
| II | Vulnerability handling | Processes, updates and response records |
Illustrative evidence categories, not a substitute for the Annex I text.
Product properties
Annex I addresses appropriate security by design and default, reduction of exploitable vulnerabilities, protection from unauthorised access, confidentiality, integrity, availability and limiting attack surfaces, among other requirements. Read the exact Annex I language for applicability and qualifications.
- Translate each applicable provision into a product decision.
- Connect the decision to a risk and a verification method.
- Record the implementation in technical documentation.
Vulnerability handling
Manufacturers need processes to identify and remediate vulnerabilities, manage components, provide security updates and coordinate disclosure. The Annex sets the specific requirements.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.