CRAAnnex I §3voice-validated
CRA AnnexI 3: Annex I §3
CRA
AL
Founder at SQUR · last verified 2026-10-06
Regulation text
Manufacturers must identify and document vulnerabilities and components contained in products, including by drawing up an SBOM, address and remediate vulnerabilities without delay, including by providing security updates, apply effective and regular tests, share security-relevant information with the wider security community, and provide a coordinated vulnerability disclosure policy.
ATT&CK techniques this article tests · 0
| Technique | Why it maps | Confidence |
|---|
Defending mitigations · 0
| Mitigation | What it does | Confidence |
|---|
Underlying weaknesses · 7
| CWE | Why it persists | Confidence |
|---|---|---|
| CWE-1004 | 1. Regular testing and vulnerability identification should detect sensitive data stored improperly. 2. Remediation addresses such storage flaws. | 80% |
| CWE-1021 | 1. Effective testing identifies weaknesses in authentication mechanisms. 2. Remediation ensures proper restriction of excessive attempts. | 80% |
| CWE-1078 | 1. Regular testing and vulnerability identification can uncover HTTP request smuggling vulnerabilities. 2. Timely remediation prevents exploitation of these flaws. | 80% |
| CWE-1104 | 1. Identifying vulnerabilities includes detecting broken cryptographic algorithms. 2. Regular testing validates cryptographic implementations. | 90% |
| CWE-1114 | 1. Regular testing identifies inappropriate encoding for output. 2. Remediation ensures secure output handling. | 80% |
| CWE-1116 | 1. Vulnerability identification and testing detect cleartext use in security-sensitive contexts. 2. Remediation ensures proper encryption for sensitive data. | 90% |
| CWE-1119 | 1. Regular testing and vulnerability identification detect insecure communication protocols. 2. Remediation ensures the use of secure protocols. | 90% |
What SQUR Covers
Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.
What SQUR Does Not Cover
Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.
Provenance
Mapped Q2.2026 using gemini-2.5-flash · €0.0171 compute · voice-rubric self-validated