Essential requirements
Annex I is the heart of the Regulation. It applies identically whatever the criticality class; what varies is how compliance is proven.
It reads in two parts, very different in nature.
| Part I — Product security | Part II — Vulnerability handling | |
|---|---|---|
| Nature | Properties of the product at placing on the market | A process to run throughout the support period |
| Horizon | A point in time | Continuous, five to ten years |
| Evidence | Design, tests, configuration | Logs, SBOM, published advisories, measured intervals |
| Detail | Product security | Vulnerability handling |
The proportionality principle
Part I requirements apply “as appropriate to the product”. That wording is not an escape hatch: it requires a documented cybersecurity risk assessment justifying, requirement by requirement, which are retained and which are ruled out.
A requirement ruled out without documented justification is non-compliance. A requirement ruled out with a reasoned risk assessment is a defensible design decision. The difference is one document.
The risk assessment is, in any case, an item expressly expected in the technical documentation.
What to produce
A traceability matrix, kept per product, with one row per requirement:
| Column | Content |
|---|---|
| Requirement | Reference in Annex I |
| Applicable? | Yes / No, with a pointer to the risk assessment |
| Control | The technical or organisational measure covering it |
| Evidence | The artefact attesting it — test, configuration, log, document |
| Tool | What produces the evidence |
| Owner | By name |
| Last verified | Date |
This matrix is the most useful working document of the programme: engineering uses it to know what to build, Legal to compile the file, and the auditor to verify.
The link to the presumption of conformity
The Regulation prescribes no technical solution. It prescribes outcomes. The presumption of conformity allows those outcomes to be met by applying harmonised standards, common specifications or certification schemes — see Conformity assessment.
Absent a published harmonised standard, conformity may still be demonstrated by other means: it simply takes longer to document, and it closes the module A route for class I products.
In this section
Cyber
Product security (Annex I, Part I)
The thirteen design requirements: secure default configuration, no known exploitable vulnerabilities, encryption, integrity, data minimisation, logging, secure erasure.
Cyber
Vulnerability handling (Annex I, Part II)
The eight process obligations: SBOM, remediation without delay, regular testing, publishing advisories, CVD policy, information sharing, secure and free distribution of fixes.