EU Regulation 2024/2847 - Annex I

    Security by Design
    December 2027

    By 11 December 2027, all products with digital elements placed on the EU market must meet the essential cybersecurity requirements set out in CRA Annex I - covering both product security properties and vulnerability handling processes.

    Annex I is divided into two parts: Part I sets out what the product itself must do; Part II sets out the processes manufacturers must maintain throughout the product lifecycle.

    Annex I, Part I

    Essential Cybersecurity Requirements - Product Properties

    Products with digital elements must be designed, developed, and produced in a way that ensures an appropriate level of cybersecurity. The following properties must be demonstrable through conformity assessment.

    No known exploitable vulnerabilities

    Products must be placed on the market free of known exploitable vulnerabilities. This requires a thorough vulnerability assessment before release, including review of all components and dependencies.

    Security by default

    Products must be delivered in the most secure configuration by default. Default credentials must be unique per device or require user-set credentials on first use. Unnecessary interfaces and features must be disabled by default.

    Minimal attack surface

    The product must be designed to minimise its attack surface. This includes reducing the number of open ports, disabling unnecessary services, and applying the principle of least privilege throughout.

    Confidentiality protection

    Data stored or transmitted by the product must be protected against unauthorised access using appropriate cryptography. Sensitive data must be encrypted at rest and in transit.

    Integrity protection

    The product must protect the integrity of its data, configuration, and software. This includes mechanisms to detect and report unauthorised modifications to the product or its data.

    Availability protection

    The product must be designed to maintain availability and resilience against availability attacks (DoS) to the extent possible. Critical functions must degrade gracefully under attack.

    Access control

    The product must implement appropriate access control mechanisms. This includes authentication, authorisation, and the ability to revoke access for compromised credentials.

    Limited external data exposure

    The product must collect only the data necessary for its function (data minimisation) and must not expose unnecessary data to external parties or services.

    Secure update mechanism

    The product must have a mechanism to receive and apply security updates securely. Updates must be authenticated, integrity-checked, and applied without requiring user action where possible.

    Security event logging

    The product must be capable of recording security-relevant events. Logs must be protected against tampering and available for inspection by authorised users and authorities.

    Annex I, Part II

    Vulnerability Handling Requirements - Process Obligations

    Part II requirements apply throughout the product support lifecycle, not just at the time of placing the product on the market. These process obligations must be maintained for the duration of the support period.

    Coordinated vulnerability disclosure

    Manufacturers must maintain and publish a coordinated vulnerability disclosure (CVD) policy that allows security researchers and users to report vulnerabilities. The policy must include contact information, timelines for response, and the process followed.

    Vulnerability identification and documentation

    Manufacturers must identify and document vulnerabilities in their products, including in third-party components. This requires maintaining awareness of the vulnerability landscape for all components used.

    SBOM maintenance

    Manufacturers must maintain a Software Bill of Materials (SBOM) in machine-readable format listing all components including third-party and open source dependencies, their versions, and their known vulnerabilities.

    Timely security updates

    Vulnerabilities must be addressed promptly. Security updates must be distributed without delay once a fix is available, and separately from feature updates where practicable.

    Security update process disclosure

    Manufacturers must disclose their process for identifying, assessing, and addressing vulnerabilities to users and to competent authorities on request.

    Post-market security monitoring

    Manufacturers must actively monitor for new vulnerabilities in their products throughout the product support period, including monitoring third-party component vulnerability disclosures.

    Software Bill of Materials (SBOM)

    The CRA introduces mandatory SBOM requirements for products with digital elements. This is a significant new obligation for most manufacturers.

    What must be in the SBOM

    • - All software components including third-party and open source
    • - Component versions and identifiers (PURL, CPE)
    • - Component suppliers and licences
    • - Known vulnerabilities at time of release
    • - Dependency relationships between components
    • - Cryptographic hashes for integrity verification

    Format and accessibility

    • - Machine-readable format required
    • - SPDX (ISO/IEC 5962) and CycloneDX are industry standards
    • - Must be available to market surveillance authorities on request
    • - Updated when components change
    • - Not required to be public, but must be producible promptly
    • - Links to known CVEs for each component expected

    Support Obligations and CE Marking

    5-Year Minimum Support Period

    Manufacturers must provide security updates for the longer of: the expected product lifetime, or a minimum of 5 years from the date the product is placed on the market.

    - Security updates must be free of charge

    - Must be clearly separated from feature updates where possible

    - Updates must be applied automatically unless user opts out

    - End-of-support date must be communicated at least 12 months in advance

    - Users must be notified when no further security updates will be available

    CE Marking Process

    The CE marking signals that a product meets CRA essential requirements and has undergone the appropriate conformity assessment for its product category.

    - Determine product category (default / Class I / Class II)

    - Complete appropriate conformity assessment

    - Prepare EU Declaration of Conformity (DoC)

    - Retain DoC and technical documentation for 10 years

    - Affix CE marking to product, packaging, or documentation

    - Register product in ENISA database (for Class I and II)

    Which conformity assessment applies to your product?

    See the CRA scope page for product categories and assessment requirements

    CRA scope →