Early warning
Submit basic facts, affected products or versions, known exploitation and initial mitigation.
Build a compliance evidence chain around horizontal standards, product-specific vertical drafts, vulnerability reporting and secure development across the full product lifecycle.
Reports mainly concern actively exploited vulnerabilities and serious incidents affecting product security, users or network services.
Submit basic facts, affected products or versions, known exploitation and initial mitigation.
Add vulnerability nature, severity, impact scope, indicators, measures taken and remediation plan.
Explain root cause, impact, exploitation, corrective measures, security update and user communication.
Provide investigation conclusion, handling process, impact assessment and measures to prevent recurrence.
Horizontal standards help manufacturers build reusable requirement libraries, development processes and evidence templates for products with digital elements.
Unifies terms such as product, component, asset, vulnerability, risk, support period, security update and supply-chain role.
Translates risk-oriented, secure-by-design and secure-by-default principles into lifecycle practices.
Defines intake, validation, severity rating, fixing, coordinated disclosure and records as a basis for PSIRT and CRA reporting.
Converts CRA Annex I requirements into testable controls around identity, access, confidentiality, integrity, logging, updates and resilience.
Status note: Final references, clauses and harmonized status should always be locked to the latest official publications before project delivery.
Vertical drafts refine verification priorities for browsers, operating systems, routers, smart home products, wearables and other concrete categories.
Web isolation, certificate validation, download protection, extension permissions, privacy data and automatic update.
Master key protection, credential encryption, autofill boundaries, synchronization, recovery and leakage risks.
Engine integrity, signature updates, quarantine handling, trusted update and privileged execution risks.
Tunnel protocol, key management, authentication, traffic leakage, default configuration and client updates.
Exposed services, protocol implementation, interface authorization, input handling and attack surface minimization.
Privilege separation, secure boot, patching, logging, credential protection and secure defaults.
Management interface, segmentation, firmware update, initial credential, configuration backup and exposure risks.
Default policy, rule integrity, administrator privileges, audit logging, updates and secure failure behavior.
Voice and account data, wake-up control, third-party skills, linkage authorization and cloud communication.
Cameras, locks and alarms with remote access, account sharing, privacy protection and alert reliability.
Children's data, guardian authorization, audio/video functions, location data, defaults and remote control.
Health and location data, mobile pairing, wireless interfaces, account security, cloud sync and loss scenarios.
Compliance should not be a last-minute document task. Each development stage should produce traceable security inputs, review gates and evidence.
Identify product boundary, digital components, target markets, supply-chain roles and support period.
Output: applicability list and responsibility matrixMap assets, data flow, trust boundaries, attacker capability, foreseeable misuse and lifecycle risks.
Output: threat model and risk treatment planTurn authentication, authorization, encryption, logging, updates and interface protection into verifiable requirements.
Output: requirements and architecture reviewApply coding rules, code review, secret handling, dependency governance, supplier evidence and SBOM maintenance.
Output: code review, SBOM and supplier evidenceCombine SAST, DAST, dependency scanning, fuzzing, interface testing, penetration testing and remediation retest.
Output: test plan, findings and retest reportComplete risk acceptance, secure-default check, technical documentation, user guidance and release approval.
Output: technical file and release sign-offCollect vulnerability intelligence and feedback, complete triage, fixes, disclosure, reporting and user notification.
Output: reporting and communication recordsProvide security updates during the support period and communicate end-of-support and secure retirement.
Output: update records and EOL planShare product type, architecture, software components, target markets and development stage for a tailored roadmap.