What does the CRA require from a manufacturer's cybersecurity risk assessment?
The CRA requires manufacturers to carry out a cybersecurity risk assessment for each product with digital elements and to use the outcome of that assessment throughout the product lifecycle.
It is the basis for deciding how the manufacturer will plan, design, develop, produce, deliver and maintain the product so that it meets the CRA's essential cybersecurity requirements.
Article 13(2)-(3)
section 4.1.1