CRAAnnex I §1voice-validated

CRA AnnexI 1: Annex I §1

CRA

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

Products with digital elements must protect the confidentiality of stored, transmitted, or otherwise processed data, personal or other, by encrypting relevant data at rest or in transit by state-of-the-art mechanisms and by using other technical means.

ATT&CK techniques this article tests · 0

TechniqueWhy it mapsConfidence

Defending mitigations · 0

MitigationWhat it doesConfidence

Underlying weaknesses · 7

CWEWhy it persistsConfidence
CWE-3111. Missing encryption of sensitive data directly violates CRA Annex I §1's requirement for encrypting relevant data at rest, leading to confidentiality breaches.
100%
CWE-3191. Cleartext transmission of sensitive information directly violates CRA Annex I §1's requirement for encrypting relevant data in transit, compromising confidentiality.
100%
CWE-3271. Use of a broken or risky cryptographic algorithm fails to provide adequate protection, directly undermining the 'state-of-the-art mechanisms' required by CRA Annex I §1.
90%
CWE-2001. Exposure of sensitive information to an unauthorized actor is a direct failure to protect confidentiality, as mandated by CRA Annex I §1.
90%
CWE-2841. Improper access control allows unauthorized access to systems or data, bypassing confidentiality measures and violating CRA Annex I §1.
80%
CWE-5221. Insufficiently protected credentials can lead to unauthorized decryption or access to confidential data, undermining the technical means required by CRA Annex I §1.
80%
CWE-7981. Use of hard-coded credentials can be exploited to gain unauthorized access to systems or data, compromising confidentiality and violating CRA Annex I §1.
70%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0187 compute · voice-rubric self-validated