Skip to main content

Information and Instructions To The User

Annex I of the EU Cyber Resilience Act is where the core technical and process requirements live. This is the checklist your software product (whether it's a game, an app, or a component) and your development practices need to measure up against. It's split into two main parts: Part I deals with the security properties your product itself must have when you release it, and Part II covers the ongoing vulnerability handling processes you need to maintain. Understanding these essential requirements is non-negotiable. This section breaks them down, one by one, so you know exactly what's expected for your software products under the CRA.