Essential cybersecurity requirements: properties of products
Binds
manufacturer
Applies from
Evidence
control, document
Annex I Part I (1): Appropriate level of cybersecurity based on the risks
manufacturer · Annex I Part I (1)
Products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks.
How to satisfy it: The umbrella requirement the thirteen properties instantiate. It is risk-based, so the Article 13(2) assessment determines how far each property below must go.
be made available on the market without known exploitable vulnerabilities;
How to satisfy it: Known AND exploitable, not merely known. A triaged, documented, non-exploitable vulnerability is a defensible position, but the triage must be evidenced.
be made available on the market with a secure by default configuration, unless otherwise agreed between manufacturer and business user in relation to a tailor-made product with digital elements, including the possibility to reset the product to its original state;
How to satisfy it: Carries an explicit carve-out for tailor-made products agreed with a business user. Both halves are required otherwise: a secure default, and a reset path back to it.
ensure that vulnerabilities can be addressed through security updates, including, where applicable, through automatic security updates that are installed within an appropriate timeframe enabled as a default setting, with a clear and easy-to-use opt-out mechanism, through the notification of available updates to users, and the option to temporarily postpone them;
How to satisfy it: Four distinct obligations in one point: updates possible, automatic by default where applicable, an easy opt-out, and notification with the option to postpone.
ensure protection from unauthorised access by appropriate control mechanisms, including but not limited to authentication, identity or access management systems, and report on possible unauthorised access;
How to satisfy it: 'including but not limited to' — an authentication mechanism alone does not discharge this. The reporting half is frequently missed.
protect the confidentiality of stored, transmitted or otherwise processed data, personal or other, such as by encrypting relevant data at rest or in transit by state of the art mechanisms, and by using other technical means;
How to satisfy it: Explicitly covers non-personal data, so a GDPR-scoped encryption posture does not automatically satisfy it.
protect the integrity of stored, transmitted or otherwise processed data, personal or other, commands, programs and configuration against any manipulation or modification not authorised by the user, and report on corruptions;
How to satisfy it: Covers commands, programs and configuration, not just data, and requires reporting on corruptions.
process only data, personal or other, that are adequate, relevant and limited to what is necessary in relation to the intended purpose of the product with digital elements (data minimisation);
How to satisfy it: A product-security requirement that reads like GDPR but is independent of it and applies to non-personal data.
protect the availability of essential and basic functions, also after an incident, including through resilience and mitigation measures against denial-of-service attacks;
How to satisfy it: Availability after an incident is part of the requirement, which pulls in recovery design rather than only DoS resistance.
minimise the negative impact by the products themselves or connected devices on the availability of services provided by other devices or networks;
How to satisfy it: Aimed at products that could be conscripted into harming third parties, for example as part of a botnet. Covers connected devices too.
provide security related information by recording and monitoring relevant internal activity, including the access to or modification of data, services or functions, with an opt-out mechanism for the user;
How to satisfy it: The user opt-out is part of the requirement, not an optional courtesy.
provide the possibility for users to securely and easily remove on a permanent basis all data and settings and, where such data can be transferred to other products or systems, ensure that this is done in a secure manner.
How to satisfy it: Covers both permanent erasure and secure transfer, and both must be secure.
Every quoted requirement on this page is verbatim Official Journal text. The surrounding guidance is Legalithm’s commentary and is not regulation. This page states the obligation and its legal basis; it is not legal advice, and the corpus has not been reviewed by counsel.