cra

Annex I, Part I, (2)(a)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (5)

Techniques referencing this article

  • EX-0009Exploit Code FlawsST0004
    addresses
    high
    direct

    Manufacturer obligation that products be made available without known exploitable vulnerabilities is the primary defense against code-flaw exploitation; CRA Annex I, Part I, (2)(a) directly governs this attack class at the product-property level.

  • EX-0009.01Flight SoftwareST0004
    addresses
    high
    derived

    Manufacturer obligation that products be made available without known exploitable vulnerabilities applies directly to flight-software command/telemetry handlers, table loaders and file-transfer services that this technique targets.

  • Known-vulnerability exploitation directly engages the (2)(a) obligation that products be available without known exploitable vulnerabilities.

  • PER-0002BackdoorST0005
    addresses
    high
    derived

    Manufacturer obligation that products be made available without known exploitable vulnerabilities covers backdoors planted during development; backdoors are exploitable vulnerabilities by construction.

  • PER-0002.02Software BackdoorST0005
    addresses
    high
    derived

    Software backdoors are exploitable vulnerabilities; manufacturers must not place products on the market with such defects under (2)(a).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.