Skip to main content

FIT-CR-01 — Basic cryptography requirements

No hardcoded symmetric keys as sole encryption. Proven cryptographic primitives only. No deprecated algorithms. Best-practice configuration. No key reuse across purposes. Secure RNG. No development-phase credentials. No hardcoded credentials. Signed data always validated. Trust chains always validated.

PropertyValue
Section5.3.1 Basic cryptography requirements
Ownerplatform

Mapped Controls

ControlTitle
SID-CRYPTO-01PKCS#11 HSM Key Protection
SID-CRYPTO-03AES-256-GCM Encrypted Keystore
SID-CRYPTO-04COSE Sign1 and mDOC Cryptography
SID-CRYPTO-05Secure Random Number Generation

Source: Nordic EUDIW Certification System – Wallet Instance FitCEM PP Appendix