cra

Art. 13(5)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (19)

Techniques referencing this article

  • DE-0003.12Poison AI/ML Training for EvasionST0006
    triggers obligation
    moderate
    direct

    Training data and pretrained models are commonly sourced from third parties; (13)(5)'s component-due-diligence obligation triggers when a manufacturer integrates third-party ML pipelines exposed to poisoning.

  • DE-0012Component CollusionST0006
    addresses
    high
    direct

    Component collusion via supply-chain compromise is the precise risk (13)(5)'s due-diligence-on-third-party-components obligation triggers — manufacturers must ensure integrated components do not compromise product cybersecurity.

  • Manufacturer due-diligence on the supplier of the affected hardware/firmware is the upstream control that bounds the corruption surface beneath the software stack.

  • EX-0012.13Poison AI/ML Training DataST0004
    addresses
    high
    derived

    AI/ML training-data suppliers (data brokers, annotation services, pretrained-model vendors) fall within manufacturer due-diligence obligations on third-party component integration.

  • IA-0001Compromise Supply ChainST0003
    addresses
    high
    direct

    Manufacturer due-diligence on third-party component integration is the primary obligation that bounds supply-chain compromise; CRA Art. 13(5) explicitly requires manufacturers to exercise due diligence when integrating components, including verification that components do not compromise the product's cybersecurity.

  • Manufacturer due-diligence obligations apply to package registries, container base-image suppliers and CI/CD service providers that deliver software dependencies into the product build pipeline.

  • IA-0001.02Software Supply ChainST0003
    addresses
    high
    derived

    Software-supplier due-diligence is the upstream control on the build vendors, package signers and OTA distributors that software-supply-chain attacks ride through.

  • IA-0001.03Hardware Supply ChainST0003
    addresses
    high
    derived

    Hardware-supplier due-diligence under Art. 13(5) covers foundries, board houses and IC integrators where ASIC/FPGA Trojans, modified bootloaders and pre-delivery board manipulation are introduced.

  • SDR vendors and waveform suppliers fall under manufacturer due-diligence; the integrity expectations on vendor-supplied bitstreams and configuration profiles are part of supplier-integration vetting.

  • IA-0009Trusted RelationshipST0003
    addresses
    moderate
    derived

    Manufacturer due-diligence applies to third-party integration relationships (vendors, partners, support providers) whose connections trusted-relationship attacks ride through.

  • Manufacturer due-diligence covers mission-collaborator integration via federated identity providers and shared data portals when those create dependencies on the product.

  • IA-0009.02VendorST0003
    addresses
    high
    derived

    Vendor due-diligence is the canonical case for Art. 13(5): manufacturers must vet remote-administration suppliers and integration partners that hold persistent access to the product.

  • Manufacturer due-diligence on AIT facility, integrator and pad-side service providers covers exactly the touchpoints where ATLO compromise is introduced.

  • PER-0002.01Hardware BackdoorST0005
    addresses
    high
    derived

    Hardware backdoors enter through silicon, board and firmware suppliers; manufacturer due-diligence on those suppliers is the upstream control on test/scan-chain enablement and bootstrap-mode misuse.

  • PER-0002.02Software BackdoorST0005
    addresses
    moderate
    derived

    Software supply chains are the principal vehicle for backdoor introduction; manufacturer due-diligence frames the security expectations on supplier secure-development practices.

  • REC-0008Gather Supply Chain InformationST0001
    addresses
    moderate
    direct

    Manufacturer obligation to exercise due diligence when integrating components sourced from third parties is the upstream discipline that constrains supply-chain reconnaissance: a manufacturer with documented due-diligence cannot be surprised by what its supply-chain map reveals to an adversary.

  • REC-0008.01Hardware ReconST0001
    addresses
    moderate
    derived

    Manufacturer due-diligence on hardware-component integration includes verification of supplier provenance, anti-counterfeit screening and tamper-evident packaging — the operational mechanisms that constrain how hardware moves from foundry to final integration.

  • REC-0008.02Software ReconST0001
    addresses
    moderate
    derived

    Manufacturer due-diligence on software-component integration governs how vendor relationships, dependency manifests and provenance are vetted — the same pipeline software-factory reconnaissance attempts to enumerate.

  • REC-0008.04Business RelationshipsST0001
    addresses
    moderate
    derived

    Manufacturer due-diligence on supplier integration governs the contractual and operational mapping of relationships that business-recon adversaries enumerate; when manufacturers maintain documented due-diligence, the adversary's relationship-map asymmetry shrinks.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.