Pre-1.0 accepted review fixes - #33
Draft
devashridatta-dotcom wants to merge 63 commits into
Draft
Conversation
This was referenced Sep 4, 2026
Annex I Part I(2)(d) requires appropriate control mechanisms including authentication and identity or access management, and reporting on possible unauthorized access. Section 3.4.1 covered default credentials only, which is why Annex B marked the requirement partial. The new section 3.4.13 states the requirement, and Annex B now traces there. Reference: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847#anx_I Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Annex I Part I(2)(e) requires the product to protect the confidentiality of stored, transmitted or otherwise processed data. Annex B traced the requirement to 3.4.3, which names TLS 1.2 or higher and encryption at rest. That is a related implementation, and the regulation itself presents encryption as an example rather than a requirement. The new section 3.4.14 states the requirement, and 3.4.3 is referenced as a related implementation control in the guidance. Reference: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847#anx_I Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…rams and configuration Annex I Part I(2)(f) requires the product to protect the integrity of stored, transmitted or otherwise processed data, and of commands, programs and configuration, against manipulation or modification not authorised by the user, and to report on corruptions. Annex B traced the requirement to 3.4.3 and 3.3.2, which are related implementations covering data in transit and release artifacts respectively. The new section 3.4.15 states the requirement, and both are referenced as related implementation controls in the guidance. We are missing a related implementation control covering the integrity of commands, programs and configuration in the running product, which is noted in the guidance. Reference: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847#anx_I Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Annex I Part I(2)(g) requires the product to process only data that are adequate, relevant and limited to what is necessary in relation to the intended purpose. Annex B traced the requirement to 7.2.5, which addresses telemetry only and is a related implementation rather than the requirement. The new section 3.4.16 states the requirement. The current related implementation control remains only partial, but can be built on later. Reference: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847#anx_I Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Annex I Part I(2)(h) requires the product to protect the availability of essential and basic functions, also after an incident, including through resilience and mitigation measures against denial-of-service attacks. Annex B traced the requirement to 3.4.2 and 4.3. Section 3.4.2 is the attack surface requirement under point (j) and supports availability only indirectly, and section 4.3 covers vulnerability disposition decisions rather than product availability, so the reference to 4.3 is removed. The new section 3.4.17 states the requirement. We are missing a related implementation control for it, which can be built on later. Reference: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847#anx_I Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…works Annex I Part I(2)(i) requires the product to minimise the negative impact by the product itself or connected devices on the availability of services provided by other devices or networks. Annex B recorded this as a checklist gap with no control. The new section 3.4.18 states the requirement, using the wording of the regulation. We are missing a related implementation control for it, which can be built on later. Reference: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847#anx_I Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Annex I Part I(2)(k) requires the product to be designed, developed and produced to reduce the impact of an incident using appropriate exploitation mitigation mechanisms and techniques. Annex B traced the requirement to 3.4.4, which names memory-safety mechanisms and compiler mitigations. That is one family of techniques and a related implementation rather than the requirement. The new section 3.4.19 states the requirement, and 3.4.4 is referenced as a related implementation control in the guidance. Reference: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847#anx_I Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…monitoring Annex I Part I(2)(l) requires the product to provide security related information by recording and monitoring relevant internal activity, including access to or modification of data, services or functions, with an opt-out mechanism for the user. Annex B recorded this as a checklist gap with no control. The new section 3.4.20 states the requirement, including the opt-out mechanism, which is part of the requirement rather than a limitation on it. We are missing a related implementation control for it, which can be built on later. Reference: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847#anx_I Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Annex I Part I(2)(m) requires the product to provide the possibility for users to securely and easily remove on a permanent basis all data and settings, and to ensure secure transfer where such data can be transferred to other products or systems. Annex B traced the requirement to 6.1.7, which is a related implementation control, and it is mentioned in the guidance too. Reference: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847#anx_I Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Annex I Part II(3) requires the manufacturer to apply effective and regular tests and reviews of the security of the product. Annex B traced the requirement to 3.4.5, 3.4.6 and 3.4.7, which are different types of tests, i.e. related controls. Deciding what tests are appropriate happens via the cybersecurity risk assessment 2.6. The related controls are referenced in the guidance. Reference: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847#anx_I Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The heading referred to CRA Annex I, Part I. That is removed, since the section is centered around secure development and testing rather than around a part of Annex I. The section covers many of the Part I points but not all of them, it covers Part II(3) through the security testing controls and now through 3.4.22, and 3.4.8 covers the retention obligation in Art. 13(13). The introduction is corrected accordingly. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Eleven controls were added in this round, taking the checklist from 182 to 193 items. The count appears in the Implementation Roadmap Phase 9 line and in the Self-Certification Summary, and both are updated. The README refers to the item count of CRA_Checklist_Requirement_latest.md, which is not changed here. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
I note that my comments in the Google Doc version seem not to have been integrated. The addition of SWHID to 3.1.6 has made it, but it ought to also be added to 3.3.1. Thanks! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This draft PR stages accepted review comments for the pre-1.0 release without changing the current RC1/main review baseline until the batch is approved.
For reviewers who want to read the whole proposed document at once:
Included in this review batch:
RC1/main remains unchanged while review is ongoing. This PR is for visibility and final approval before merging approved changes into Version 1.0.
Item #25 remains open for final OpenChain website/CMS publication work. Issue #26 is closed because the repository-maintained and GitHub Pages wording alignment is complete.