Annex I: Essential cybersecurity requirements
Summary
Annex I is the central requirements list. Part I concerns product characteristics; Part II concerns vulnerability handling including SBOM.
Core point
Annex I Part I contains cybersecurity requirements for characteristics of products with digital elements. Part II contains vulnerability handling requirements, including a software bill of materials in a commonly used machine-readable format showing at least top-level dependencies.
In practice
Product, security and build processes should use Annex I Parts I and II as an ongoing checklist.
Sources
- Anhang I Teil I, CELEX 32024R2847
- Anhang I Teil II, CELEX 32024R2847
- MD/reference/VERIFICATION-3.1.md §Pflichten und Klassifizierung
Related articles
These contents are general, automatically processed information based on Regulation (EU) 2024/2847 and do not replace legal advice in individual cases. No legal services within the meaning of the RDG. Data basis as of: 07/08/2026.