OBL-ART13-01Binding

Ensure product security throughout its lifecycle (secure by design)

対象者
Manufacturer
出典引用
Art. 13(1)Art. 13(2)Annex I Part I §1
製品クラス
default, important-class-i, important-class-ii, critical
Last reviewed

わかりやすい説明

Your product must be built with security in mind from day one. This means identifying security risks before you ship, making security decisions during design (not as an afterthought), and continuing to address security throughout the product's supported life. Think of it as "security by design" — you need a documented process, not just good intentions.

Legal text

Article 13(1) of Regulation (EU) 2024/2847 requires that manufacturers of products with digital elements shall ensure that the products are designed, developed, and produced in accordance with the essential cybersecurity requirements set out in Annex I Part I.

Article 13(2) further requires that manufacturers shall carry out an assessment of the cybersecurity risks associated with the product with digital elements, taking into account the risks to security and safety of users.

Key requirements

  1. Risk assessment at the design stage — identify and document security risks
  2. Secure development process — apply Annex I Part I requirements throughout
  3. Default secure configuration — no default insecure states
  4. Attack surface minimisation — disable unnecessary functions and ports
  5. Lifecycle security — security addressed at design, development, and production

Evidence you may need

  • Product cybersecurity risk assessment (documented)
  • Secure development lifecycle policy
  • Architecture and design documents showing security decisions
  • Test records demonstrating Annex I compliance
Ensure product security throughout its lifecycle (secure by design) — CRAコンプライアンスハブ