Definition

Essential cybersecurity requirements

Annex I requirements on product properties (Part I) and on vulnerability handling (Part II) that every product must meet.

The requirements set out in Annex I. Part I covers product properties: secure-by-default configuration, protection against unauthorised access, confidentiality and integrity of data, minimisation of attack surfaces, resilience, logging, and secure updates. Part II covers vulnerability handling: identifying and documenting components in an SBOM, remediating vulnerabilities without delay, testing, disclosing fixed vulnerabilities, a coordinated vulnerability disclosure policy, information sharing, secure update distribution and free security updates.

Reference: Art. 6 and Annex I · Regulation (EU) 2024/2847 on EUR-Lex

Updated 2026-09-12 · Paraphrase for orientation, not legal advice.

In practice

Related terms

See the term as a workflow.

Vellaci turns each of these definitions into a record with an owner, a timestamp and evidence.