What does CRA RDPS status change for risk assessment and conformity?
It means the manufacturer has to assess the product as a whole, including RDPS when it is in scope.
The Commission FAQ says the cybersecurity risk assessment needs to cover the entire product with digital elements, including remote data processing where relevant and any supporting functions that may form part of the product. The draft guidance adds that the conformity assessment should focus on the parts of the system where the relevant product data is stored or processed, not the whole surrounding environment.
section 4.1.2
points 162, 187 to 190
Article 13(2), Article 31, Annex VII