What does Article 13 require from a CRA cybersecurity risk assessment?
Article 13 requires the manufacturer to assess the cybersecurity risks associated with a product with digital elements and use the outcome during planning, design, development, production, delivery, and maintenance.
The assessment should show how the manufacturer is minimising cybersecurity risks, preventing incidents, and reducing incident impact, including effects on user health and safety where relevant. It should connect product assumptions, threats, mitigations, tests, and residual risks to the essential requirements in Annex I.
Article 13(2)-(3) establishes the risk assessment duty and lifecycle use.
Sections 4.1.1 and 4.1.2 explain that the assessment must support risk treatment and verification by market surveillance authorities.