Do CRA harmonised standards replace the manufacturer's cybersecurity risk assessment?
No. The cybersecurity risk assessment remains the starting point for deciding which CRA essential requirements are relevant to the product.
The Commission FAQ says that even when a harmonised standard is used, the manufacturer remains responsible for assessing product risks, selecting suitable standards or other specifications, and checking whether the standard covers all relevant risks.
Commission FAQ section 4.1.7 directly addresses the relationship between harmonised standards and the manufacturer risk assessment.
Article 13(2) and Annex VII require the manufacturer's cybersecurity risk assessment and its inclusion in technical documentation.