Requirements that bend to risk
Annex I does not read like a checklist, and treating it as one produces both over-engineering and gaps.
Part I opens with a governing sentence: products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks. Article 13(2) then requires the manufacturer to undertake a cybersecurity risk assessment and feed its findings through planning, design, development, production, delivery and maintenance. Article 13(3) requires that assessment to be documented and kept updated during the support period.
So the thirteen properties in Part I apply to the extent the risk assessment says they are relevant, and to the depth it justifies. An air-gapped industrial controller and a consumer doorbell reach different answers on encryption in transit, and both can be compliant.
One point does not bend. Point (a) requires the product to be made available without known exploitable vulnerabilities, full stop.

