CRAAnnex I §2voice-validated

CRA AnnexI 2: Annex I §2

CRA

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

Products with digital elements must protect the integrity of stored, transmitted, or otherwise processed data, commands, programs and configuration against any manipulation or modification not authorised by the user, and report on corruptions.

ATT&CK techniques this article tests · 0

TechniqueWhy it mapsConfidence

Defending mitigations · 0

MitigationWhat it doesConfidence

Underlying weaknesses · 6

CWEWhy it persistsConfidence
CWE-284Improper access control allows unauthorized users to modify data, commands, programs, or configurations. CRA Annex I §2 requires protection against any manipulation not authorized by the user.
90%
CWE-306Missing authentication for critical functions enables unauthorized manipulation of data, commands, programs, or configurations without proper verification. CRA Annex I §2 mandates protection against unauthorized manipulation.
85%
CWE-345Insufficient verification of data authenticity allows attackers to introduce or modify data without detection. CRA Annex I §2 requires protection against manipulation and reporting on corruptions.
90%
CWE-434Unrestricted upload of dangerous file types allows attackers to introduce malicious programs or configurations, leading to unauthorized manipulation. CRA Annex I §2 mandates protection against such manipulation.
80%
CWE-502Deserialization of untrusted data can lead to arbitrary code execution, enabling unauthorized manipulation of programs and data. CRA Annex I §2 requires protection against such manipulation.
75%
CWE-732Incorrect permission assignment for critical resources allows unauthorized users to modify sensitive files or configurations. CRA Annex I §2 mandates protection against manipulation not authorized by the user.
85%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0176 compute · voice-rubric self-validated