CRAAnnex I §2voice-validated
CRA AnnexI 2: Annex I §2
CRA
AL
Founder at SQUR · last verified 2026-10-06
Regulation text
Products with digital elements must protect the integrity of stored, transmitted, or otherwise processed data, commands, programs and configuration against any manipulation or modification not authorised by the user, and report on corruptions.
ATT&CK techniques this article tests · 0
| Technique | Why it maps | Confidence |
|---|
Defending mitigations · 0
| Mitigation | What it does | Confidence |
|---|
Underlying weaknesses · 6
| CWE | Why it persists | Confidence |
|---|---|---|
| CWE-284 | Improper access control allows unauthorized users to modify data, commands, programs, or configurations. CRA Annex I §2 requires protection against any manipulation not authorized by the user. | 90% |
| CWE-306 | Missing authentication for critical functions enables unauthorized manipulation of data, commands, programs, or configurations without proper verification. CRA Annex I §2 mandates protection against unauthorized manipulation. | 85% |
| CWE-345 | Insufficient verification of data authenticity allows attackers to introduce or modify data without detection. CRA Annex I §2 requires protection against manipulation and reporting on corruptions. | 90% |
| CWE-434 | Unrestricted upload of dangerous file types allows attackers to introduce malicious programs or configurations, leading to unauthorized manipulation. CRA Annex I §2 mandates protection against such manipulation. | 80% |
| CWE-502 | Deserialization of untrusted data can lead to arbitrary code execution, enabling unauthorized manipulation of programs and data. CRA Annex I §2 requires protection against such manipulation. | 75% |
| CWE-732 | Incorrect permission assignment for critical resources allows unauthorized users to modify sensitive files or configurations. CRA Annex I §2 mandates protection against manipulation not authorized by the user. | 85% |
What SQUR Covers
Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.
What SQUR Does Not Cover
Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.
Provenance
Mapped Q2.2026 using gemini-2.5-flash · €0.0176 compute · voice-rubric self-validated