Corpus overview

Structured extraction and assessment of the requirement clauses of 17 draft ETSI harmonized vertical standards under the Cyber Resilience Act. Parsed from the compiled source text; one duplicated document block excluded.

Noteworthy findings

Standards in scope

Product classStandardVersion ReqsAvg cxApplicability model

Coverage of CRA Annex I Part I

Requirement count per standard and essential requirement. Zero cells are marked; they indicate ERs a vertical standard does not address with its own clauses (which may be intentional scoping or a gap). Requirements addressing several ERs in one combined clause (e.g. Routers) are credited to each. Click a cell to open matching clauses in the Register.

DENSITY1 ~10 30+ 0 · not addressed

Thinnest essential requirements corpus-wide

Cross-standard overlap

Edges connect standards sharing textually similar requirements (TF-IDF cosine ≥ 0.70); edge width is the number of similar pairs. Node size is requirement count. Drag nodes; click a node to open its clauses in the Register.

Near-duplicate requirement clusters

Groups of requirements from different standards with cosine similarity ≥ 0.80. Candidates for consolidation into horizontal standards.

Requirement complexity

Composite score (0–10) from clause length, conditional constructs (where / if / unless / except), cross-references (annexes, tables, external standards, other requirement IDs), and multi-obligation structure. High scores predict assessment effort and interpretation disputes.

Score distribution

Average complexity by standard

Most complex individual requirements

IDStandardScoreWordsCondsXrefsTitle / excerpt

Requirements register

Full-text search across 1,404 extracted requirements. Search matches IDs, requirement text, notes, topics and technologies (e.g. TLS, SBOM, fuzz, parental). Click a row for the full clause.

IDStandardER RequirementCx