Cybersecurity Risk Assessment

The cybersecurity risk assessment explains how the CRA product-security requirements apply to one product with digital elements. It connects the product's intended purpose, foreseeable use, conditions of use, assets, risks, security measures, and technical documentation.

Risk assessment role

For the purpose of complying with paragraph 1, manufacturers shall undertake an assessment of the cybersecurity risks associated with a product with digital elements and take the outcome of that assessment into account during the planning, design, development, production, delivery and maintenance phases of the product with digital elements with a view to minimising cybersecurity risks, preventing incidents and minimising their impact, including in relation to the health and safety of users.

Regulation (EU) 2024/2847, Article 13(2)

The assessment is not a one-time form. Article 13 ties it to the product lifecycle and requires it to be updated as appropriate during the support period.

What the assessment explains

Article 13(3) names the minimum logic. The assessment must consider intended purpose, reasonably foreseeable use, conditions of use, the operational environment, assets to be protected, and expected use time.

  • which Annex I Part I requirements apply to the product;
  • how those product requirements are implemented;
  • how the general risk-based cybersecurity requirement in Annex I Part I point (1) is applied;
  • how the Annex I Part II vulnerability-handling requirements are applied;
  • why a requirement is not applicable, when that is the manufacturer's conclusion.

Technical documentation link

Article 13(4) puts the cybersecurity risk assessment into the technical documentation. Annex VII then requires the documentation to include an assessment of the cybersecurity risks against which the product is designed, developed, produced, delivered, and maintained.

Scope of analysis

Product facts, use, environment, assets, threats, vulnerabilities, and misuse scenarios.

Security measures

Product properties, security controls, update design, and vulnerability-handling measures.

Lifecycle updates

Product changes, new vulnerabilities, new evidence, and support period changes can require reassessment.

Evidence file

The conclusion belongs in the technical documentation and supports conformity assessment.

Standard support

The draft prEN 40000-1-2 page explains the current horizontal principles document for cyber-resilience risk management. It can help structure the work, but the legal duty still comes from Article 13 and Annex I.

Sources