Confidentiality and Integrity Under the CRA: One Mechanism, Two Obligations
CRA Annex I requirements 2(e) and 2(f) both protect data — but confidentiality and integrity are separate obligations that just happen to share a mechanism like TLS. Here's why treating them as one and the same is how compliance gaps get missed.
Access Control Under the CRA: More Than Just a Login Screen
Part #6 of our Human Written CRA series unpacks Annex I Part I requirement 2(d): from MFA and machine-to-machine TLS to unauthorized access reporting, surface reduction, and substantial modification triggers.