Self-containment as the single design principle
An ordinary PDF is allowed to lean on its environment. It may reference a font by name and assume the reader has it. It may describe colour in a way that depends on the display. It may link to a file on a network share. Each of those is a bet that something outside the file will still be there and still behave the same way. Archiving is the business of not making bets.
PDF/A therefore requires that fonts be embedded — every glyph actually used must travel inside the file, so nothing is substituted decades later when the original typeface is unavailable. It requires device-independent colour, meaning colour must be specified in a way that is unambiguous rather than left to whatever the rendering device assumes, typically by embedding an ICC profile. It forbids external dependencies: no references to files outside the document, no reliance on fetched resources.
It also forbids encryption outright. This surprises people, but it follows directly: a file whose bytes can only be read with a key is a file that becomes unreadable the moment the key is lost, and an archive cannot accept that. For the same reason PDF/A bars JavaScript, launch actions and embedded multimedia that would need an external player — anything whose behaviour is not fully determined by the file itself.
Finally it requires XMP identification metadata: an embedded XMP packet declaring which PDF/A part and conformance level the file claims. That declaration is what makes a file self-describing and what a validator checks first.