CRAArt. 13voice-validated
CRA Art13: Art. 13
CRA
AL
Founder at SQUR · last verified 2026-10-06
Regulation text
Products with digital elements must be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks. Includes secure-by-default configuration, protection against unauthorised access, confidentiality and integrity protection, processing only adequate data, resilience against denial of service, monitoring of internal activity, and recovery to a secure state after incidents.
ATT&CK techniques this article tests · 0
| Technique | Why it maps | Confidence |
|---|
Defending mitigations · 6
| Mitigation | What it does | Confidence |
|---|---|---|
| M1038 | 1. Secure-by-default configuration, as mandated by Article 13, establishes a default deny posture for unauthorized actions and network traffic. 2. This limits the attack surface significantly. | 90% |
| M1047 | 1. Monitoring of internal activity, required by Article 13, relies on comprehensive auditing to detect suspicious behavior. 2. Auditing provides visibility into system events for incident response. | 80% |
| M1040 | 1. Confidentiality protection, a core requirement of Article 13, is achieved through data encryption. 2. Encryption safeguards sensitive data both at rest and in transit. | 90% |
| M1022 | 1. Recovery to a secure state after incidents, as per Article 13, necessitates robust data backup procedures. 2. Backups ensure data integrity and availability following disruptive events. | 90% |
| M1049 | 1. Resilience against denial of service and protection against unauthorised access are enhanced by network segmentation. 2. Segmentation limits the blast radius of attacks and isolates critical components. | 80% |
| M1026 | 1. Protection against unauthorised access and secure-by-default configuration are supported by privileged account management. 2. This restricts access to critical functions and data to authorized personnel only. | 80% |
Underlying weaknesses · 5
| CWE | Why it persists | Confidence |
|---|---|---|
| CWE-284 | 1. 'Protection against unauthorised access' is a key requirement of Article 13. This directly mitigates improper access control weaknesses. 2. Flawed access controls allow unauthorized users to perform actions. | 90% |
| CWE-311 | 1. 'Confidentiality protection' is explicitly required by Article 13. This addresses weaknesses related to missing encryption of sensitive data. 2. Unencrypted data is vulnerable to disclosure. | 90% |
| CWE-400 | 1. 'Resilience against denial of service' is a direct mandate of Article 13. This addresses uncontrolled resource consumption weaknesses. 2. Excessive resource use can lead to system unavailability. | 90% |
| CWE-778 | 1. 'Monitoring of internal activity' is required by Article 13. This addresses weaknesses related to insufficient logging, hindering detection. 2. Poor logging prevents effective incident analysis and response. | 80% |
| CWE-787 | 1. 'Integrity protection' is a core requirement of Article 13. Out-of-bounds writes directly compromise data integrity. 2. Such vulnerabilities can lead to arbitrary code execution or data corruption. | 80% |
What SQUR Covers
Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.
What SQUR Does Not Cover
Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.
Provenance
Mapped Q2.2026 using gemini-2.5-flash · €0.0182 compute · voice-rubric self-validated · 2 hallucination(s) dropped at validation