What does RDPS status change for CRA risk assessment and conformity assessment?
When remote processing qualifies as RDPS, it is part of the product with digital elements for CRA assessment. The manufacturer's cybersecurity risk assessment must cover the whole product, including in-scope RDPS and supporting functions.
The manufacturer should still avoid over-scoping. The draft guidance says conformity assessment should focus on the parts of the remote system where data necessary for product functions is stored or processed, while risks from surrounding infrastructure and third-party cloud services should be assessed and mitigated at product level.
Article 13(2)-(4), Article 31, and Annex VII ground the risk-assessment and technical-documentation obligations.
Section 4.1.2 states that the cybersecurity risk assessment covers the entire product, including remote data processing when in scope.
Points 187-190 explain RDPS documentation, conformity-scope delineation, and risk treatment for related cloud or infrastructure dependencies.