Essential requirements

Annex I is the heart of the Regulation. It applies identically whatever the criticality class; what varies is how compliance is proven.

It reads in two parts, very different in nature.

Part I — Product security Part II — Vulnerability handling
Nature Properties of the product at placing on the market A process to run throughout the support period
Horizon A point in time Continuous, five to ten years
Evidence Design, tests, configuration Logs, SBOM, published advisories, measured intervals
Detail Product security Vulnerability handling

The proportionality principle

Part I requirements apply “as appropriate to the product”. That wording is not an escape hatch: it requires a documented cybersecurity risk assessment justifying, requirement by requirement, which are retained and which are ruled out.

A requirement ruled out without documented justification is non-compliance. A requirement ruled out with a reasoned risk assessment is a defensible design decision. The difference is one document.

The risk assessment is, in any case, an item expressly expected in the technical documentation.

What to produce

A traceability matrix, kept per product, with one row per requirement:

Column Content
Requirement Reference in Annex I
Applicable? Yes / No, with a pointer to the risk assessment
Control The technical or organisational measure covering it
Evidence The artefact attesting it — test, configuration, log, document
Tool What produces the evidence
Owner By name
Last verified Date

This matrix is the most useful working document of the programme: engineering uses it to know what to build, Legal to compile the file, and the auditor to verify.

The Regulation prescribes no technical solution. It prescribes outcomes. The presumption of conformity allows those outcomes to be met by applying harmonised standards, common specifications or certification schemes — see Conformity assessment.

Absent a published harmonised standard, conformity may still be demonstrated by other means: it simply takes longer to document, and it closes the module A route for class I products.

In this section

  • Cyber

    Product security (Annex I, Part I)

    The thirteen design requirements: secure default configuration, no known exploitable vulnerabilities, encryption, integrity, data minimisation, logging, secure erasure.

  • Cyber

    Vulnerability handling (Annex I, Part II)

    The eight process obligations: SBOM, remediation without delay, regular testing, publishing advisories, CVD policy, information sharing, secure and free distribution of fixes.