Skip to content

Pre-1.0 accepted review fixes - #33

Draft
devashridatta-dotcom wants to merge 63 commits into
mainfrom
review/open-comments-pre-v1
Draft

Pre-1.0 accepted review fixes#33
devashridatta-dotcom wants to merge 63 commits into
mainfrom
review/open-comments-pre-v1

Conversation

@devashridatta-dotcom

@devashridatta-dotcom devashridatta-dotcom commented Sep 3, 2026

Copy link
Copy Markdown
Collaborator

This draft PR stages accepted review comments for the pre-1.0 release without changing the current RC1/main review baseline until the batch is approved.

For reviewers who want to read the whole proposed document at once:

  • Full proposed checklist: CRA_Checklist_Requirement_pre_v1_review.md
  • Release-target checklist on this branch: CRA_Checklist_Requirement_latest.md
  • Review guide: PRE_V1_REVIEW.md

Included in this review batch:

RC1/main remains unchanged while review is ongoing. This PR is for visibility and final approval before merging approved changes into Version 1.0.

Item #25 remains open for final OpenChain website/CMS publication work. Issue #26 is closed because the repository-maintained and GitHub Pages wording alignment is complete.

willebra and others added 12 commits September 7, 2026 16:40
Annex I Part I(2)(d) requires appropriate control mechanisms including
authentication and identity or access management, and reporting on
possible unauthorized access. Section 3.4.1 covered default credentials
only, which is why Annex B marked the requirement partial. The new
section 3.4.13 states the requirement, and Annex B now traces there.

Reference: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847#anx_I

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Annex I Part I(2)(e) requires the product to protect the confidentiality
of stored, transmitted or otherwise processed data. Annex B traced the
requirement to 3.4.3, which names TLS 1.2 or higher and encryption at
rest. That is a related implementation, and the regulation itself
presents encryption as an example rather than a requirement. The new
section 3.4.14 states the requirement, and 3.4.3 is referenced as a
related implementation control in the guidance.

Reference: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847#anx_I

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…rams and configuration

Annex I Part I(2)(f) requires the product to protect the integrity of
stored, transmitted or otherwise processed data, and of commands,
programs and configuration, against manipulation or modification not
authorised by the user, and to report on corruptions. Annex B traced
the requirement to 3.4.3 and 3.3.2, which are related implementations
covering data in transit and release artifacts respectively. The new
section 3.4.15 states the requirement, and both are referenced as
related implementation controls in the guidance. We are missing a
related implementation control covering the integrity of commands,
programs and configuration in the running product, which is noted in
the guidance.

Reference: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847#anx_I

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Annex I Part I(2)(g) requires the product to process only data that are
adequate, relevant and limited to what is necessary in relation to the
intended purpose. Annex B traced the requirement to 7.2.5, which
addresses telemetry only and is a related implementation rather than
the requirement. The new section 3.4.16 states the requirement. The
current related implementation control remains only partial, but can be
built on later.

Reference: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847#anx_I

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Annex I Part I(2)(h) requires the product to protect the availability of
essential and basic functions, also after an incident, including through
resilience and mitigation measures against denial-of-service attacks.
Annex B traced the requirement to 3.4.2 and 4.3. Section 3.4.2 is the
attack surface requirement under point (j) and supports availability
only indirectly, and section 4.3 covers vulnerability disposition
decisions rather than product availability, so the reference to 4.3 is
removed. The new section 3.4.17 states the requirement. We are missing
a related implementation control for it, which can be built on later.

Reference: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847#anx_I

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…works

Annex I Part I(2)(i) requires the product to minimise the negative
impact by the product itself or connected devices on the availability of
services provided by other devices or networks. Annex B recorded this as
a checklist gap with no control. The new section 3.4.18 states the
requirement, using the wording of the regulation. We are missing a
related implementation control for it, which can be built on later.

Reference: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847#anx_I

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Annex I Part I(2)(k) requires the product to be designed, developed and
produced to reduce the impact of an incident using appropriate
exploitation mitigation mechanisms and techniques. Annex B traced the
requirement to 3.4.4, which names memory-safety mechanisms and compiler
mitigations. That is one family of techniques and a related
implementation rather than the requirement. The new section 3.4.19
states the requirement, and 3.4.4 is referenced as a related
implementation control in the guidance.

Reference: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847#anx_I

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…monitoring

Annex I Part I(2)(l) requires the product to provide security related
information by recording and monitoring relevant internal activity,
including access to or modification of data, services or functions, with
an opt-out mechanism for the user. Annex B recorded this as a checklist
gap with no control. The new section 3.4.20 states the requirement,
including the opt-out mechanism, which is part of the requirement rather
than a limitation on it. We are missing a related implementation
control for it, which can be built on later.

Reference: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847#anx_I

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Annex I Part I(2)(m) requires the product to provide the possibility for
users to securely and easily remove on a permanent basis all data and
settings, and to ensure secure transfer where such data can be
transferred to other products or systems. Annex B traced the requirement
to 6.1.7, which is a related implementation control, and it is mentioned
in the guidance too.

Reference: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847#anx_I

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Annex I Part II(3) requires the manufacturer to apply effective and
regular tests and reviews of the security of the product. Annex B traced
the requirement to 3.4.5, 3.4.6 and 3.4.7, which are different types of
tests, i.e. related controls. Deciding what tests are appropriate happens
via the cybersecurity risk assessment 2.6. The related controls are
referenced in the guidance.

Reference: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202402847#anx_I

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The heading referred to CRA Annex I, Part I. That is removed, since the
section is centered around secure development and testing rather than
around a part of Annex I. The section covers many of the Part I points
but not all of them, it covers Part II(3) through the security testing
controls and now through 3.4.22, and 3.4.8 covers the retention
obligation in Art. 13(13). The introduction is corrected accordingly.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Eleven controls were added in this round, taking the checklist from 182
to 193 items. The count appears in the Implementation Roadmap Phase 9
line and in the Self-Certification Summary, and both are updated. The
README refers to the item count of CRA_Checklist_Requirement_latest.md,
which is not changed here.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@umm0 umm0 linked an issue Sep 9, 2026 that may be closed by this pull request
@umm0 umm0 mentioned this pull request Sep 10, 2026
14 tasks
@webmink

webmink commented Sep 10, 2026

Copy link
Copy Markdown

I note that my comments in the Google Doc version seem not to have been integrated. The addition of SWHID to 3.1.6 has made it, but it ought to also be added to 3.3.1. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update checklist document for version 1.0 release

3 participants