Annex I, Part I ยท Regulation (EU) 2024/2847

What are the CRA essential cybersecurity requirements?

Verified against the Official Journal text on

Annex I, Part I is the risk-based design checklist. Products must be designed, developed, and produced to ensure an appropriate level of cybersecurity based on the risks. Where applicable, they must ship without known exploitable vulnerabilities, with a secure default configuration, and able to receive security updates. They must control access, protect the confidentiality and integrity of data, minimise the data processed, protect availability against denial-of-service, limit the attack surface, log security-relevant activity, and let users securely erase their data. Which of these apply follows from your Article 13 cybersecurity risk assessment.

Basis: Annex I Part I, Art. 13(1), Art. 13(3)

Judgment call: The property requirements in Part I, point (2) apply "where applicable" and "on the basis of the cybersecurity risk assessment", so which ones bind a given product is itself a documented, risk-based judgment.

The overarching duty: security appropriate to the risk Annex I Part I (1), Art. 13(1)

Everything in Part I sits under one general duty. Products with digital elements must be designed, developed, and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks. This is the requirement that always applies, and Article 13(1) makes it a manufacturer obligation at the point of placing the product on the market. It is deliberately outcome-focused: "appropriate to the risk" rather than a fixed list of controls for every product.

The risk assessment decides what applies Art. 13(2), Art. 13(3), Annex I Part I (2)

The specific property requirements are not a blanket checklist. They apply on the basis of the cybersecurity risk assessment and "where applicable". Article 13(2) and (3) require you to assess the cybersecurity risks based on the intended purpose, reasonably foreseeable use, and conditions of use, and to document that assessment. The assessment must indicate whether and how the Part I, point (2) requirements apply to your product and how they are implemented.

So the honest answer to "which requirements apply to me" is: the ones your documented risk assessment says apply. Where a requirement does not apply, you record a clear justification in the technical documentation rather than simply skipping it.

The property requirements, one by one Annex I Part I (2)

Part I, point (2) lists the concrete design properties. Read them as a menu that the risk assessment turns on or off for your product, not as thirteen boxes every product must tick regardless of context. In plain terms, they cover the following.

  • Ship without known exploitable vulnerabilities. (Annex I Part I (2)(a))
  • Ship with a secure by default configuration, with the ability to reset to the original state. (Annex I Part I (2)(b))
  • Let vulnerabilities be addressed through security updates, including automatic updates by default where applicable, with an easy opt-out and the option to postpone. (Annex I Part I (2)(c))
  • Protect against unauthorised access with appropriate control mechanisms such as authentication and access management, and report possible unauthorised access. (Annex I Part I (2)(d))
  • Protect the confidentiality of data, for example by encrypting relevant data at rest or in transit with state-of-the-art mechanisms. (Annex I Part I (2)(e))
  • Protect the integrity of data, commands, programs, and configuration against unauthorised change. (Annex I Part I (2)(f))
  • Process only data that is adequate, relevant, and limited to what is necessary (data minimisation). (Annex I Part I (2)(g))
  • Protect the availability of essential and basic functions, including resilience against denial-of-service attacks. (Annex I Part I (2)(h))
  • Minimise the negative impact of the product on the availability of services of other devices or networks. (Annex I Part I (2)(i))
  • Be designed to limit attack surfaces, including external interfaces. (Annex I Part I (2)(j))
  • Reduce the impact of an incident using appropriate exploitation mitigation mechanisms and techniques. (Annex I Part I (2)(k))
  • Record and monitor relevant internal activity (access to or modification of data, services, or functions), with an opt-out for the user. (Annex I Part I (2)(l))
  • Let users securely and permanently remove all data and settings, and support secure transfer where data can move to other products. (Annex I Part I (2)(m))

How this connects to the rest of the CRA Annex I, Art. 13

Part I is only half of Annex I. The property requirements here sit alongside the vulnerability handling requirements of Part II, which cover what you do about vulnerabilities across the support period. Together they are the "essential cybersecurity requirements" that the conformity assessment, technical documentation, declaration of conformity, and CE marking all exist to demonstrate. Getting Part I right is the design side; Part II is the ongoing operational side.

What you must do

  • Design, develop, and produce the product to ensure an appropriate level of cybersecurity based on the risks, meeting the applicable Part I property requirements. (Art. 13(1), Annex I Part I)
  • Carry out and document a cybersecurity risk assessment that determines which Part I requirements apply and how they are implemented, and justify any that do not apply. (Art. 13(2), Art. 13(3))

Frequently asked

Do all the essential requirements apply to every product?

The overarching duty to ensure cybersecurity appropriate to the risk always applies. The specific property requirements in Part I, point (2) apply "where applicable" on the basis of your documented cybersecurity risk assessment, so not every one binds every product. (Annex I Part I, Art. 13(3))

Does the CRA require encryption?

It requires protecting the confidentiality of stored, transmitted, or processed data where applicable, for example by encrypting relevant data at rest or in transit with state-of-the-art mechanisms. Whether it applies to your product follows from the risk assessment. (Annex I Part I (2)(e))

What does "secure by default" mean here?

Shipping the product with a secure default configuration, including the ability to reset it to its original state, unless otherwise agreed with a business user for a tailor-made product. It is one of the named property requirements in Annex I, Part I. (Annex I Part I (2)(b))

Where do I record which requirements apply?

In the cybersecurity risk assessment, which becomes part of the technical documentation. The assessment must indicate whether and how the point (2) requirements apply, and any requirement that does not apply needs a clear justification. (Art. 13(3), Art. 13(4))

These requirements only apply if you are in scope

The free Vexwatch Scope Checker confirms whether the CRA applies to your product and whether you carry the manufacturer duties behind the essential requirements, before you start a risk assessment.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.