FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
856of856items
Across 40 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
Mar 10, 2026
Updated
Jul 24, 2026
CRA Cybersecurity Risk Assessment

Does every CRA product need a cybersecurity risk assessment, or only important and critical products?

Every in-scope product with digital elements needs one. Classification as an important or critical product affects conformity assessment routes and assurance expectations, but it does not supersede the Article 13 risk assessment.

The Commission FAQ is explicit that default-category, important, and critical products all require a comprehensive cybersecurity risk assessment. The depth of treatment should reflect the product's actual risk profile, intended use, deployment context, and expected exposure.

Citations
CRA Cybersecurity Risk Assessment

What inputs must the CRA risk assessment analyse?

At minimum, Article 13(3) requires an analysis of cybersecurity risks based on the product's intended purpose, reasonably foreseeable use, conditions of use, and the length of time the product is expected to be in use.

The conditions of use can include the operational environment, the assets to be protected, user skill assumptions, connected systems, and deployment constraints. Those inputs should be specific enough to explain why particular Annex I requirements apply, why others do not, and how selected controls are proportionate to the risks.

Citations
Cyber Resilience Act

Article 13(3) lists intended purpose, reasonably foreseeable use, conditions of use, and expected use time.

CRA Cybersecurity Risk Assessment

How do intended purpose and reasonably foreseeable use change the assessment?

They define the threat model and the level of risk treatment expected for the product. The same type of product may require different controls if one version is intended for a residential setting and another is intended for critical infrastructure or another high-exposure environment.

Reasonably foreseeable use is broader than the manufacturer's preferred use case. It covers uses likely to result from foreseeable human behaviour, technical operations, or interactions. The assessment should therefore record excluded assumptions, supported environments, user groups, and foreseeable integrations that materially affect cybersecurity.

Citations
Cyber Resilience Act

Article 3(24) defines reasonably foreseeable use, and Article 13(3) makes it part of the risk assessment.

CRA Cybersecurity Risk Assessment

Does the CRA risk assessment need to cover reasonably foreseeable misuse?

Yes. The CRA user-information rules require disclosure of known or foreseeable circumstances linked to intended use or reasonably foreseeable misuse that may lead to significant cybersecurity risks.

For the assessment, that means manufacturers should not rely only on ideal secure deployment. If misuse, misconfiguration, insecure integration, unsupported environments, or predictable user behaviour could create significant cybersecurity risk, the record should show whether the risk is mitigated in the product, constrained by instructions, or treated as a residual risk communicated to users.

Citations
Cyber Resilience Act

Annex II point 5 requires user information about foreseeable circumstances and reasonably foreseeable misuse leading to significant cybersecurity risks.

CRA Cybersecurity Risk Assessment

How should the assessment map to the CRA essential cybersecurity requirements?

Use the assessment to decide which Annex I requirements apply and what evidence shows that each applicable requirement is met. The mapping should cover both product properties in Annex I Part I and the manufacturer's vulnerability-handling processes in Part II.

If an essential cybersecurity requirement is not applicable, the technical documentation must contain a clear justification. Non-applicability does not end the analysis: where the manufacturer identifies a related cybersecurity risk, it must address that risk by other means, such as restricting the intended environment or giving users specific risk information.

Citations
Cyber Resilience Act

Article 13(2)-(4), recital 55, Annex I, and Annex VII require the risk assessment to inform essential-requirement implementation and require clear reasons for non-applicability.

CRA Cybersecurity Risk Assessment

What component and dependency risks belong in the assessment?

Assess risks created by integrated hardware and software components, remote data processing solutions, interfaces, connected systems, and relevant outside dependencies. Component due diligence under Article 13(5) is a separate obligation, but its results should feed the product risk assessment.

Record the component version and function, privilege and exposure, known vulnerabilities, support status, update path, supplier or maintainer evidence, mitigations, and what happens if upstream support ends before the product's support period. The finished-product manufacturer remains responsible for the product as a whole.

Citations
Cyber Resilience Act

Article 13(2), Article 13(5)-(8), recital 34, Annex I Part II, and Annex VII connect whole-product risk assessment, component due diligence, vulnerability handling, and technical documentation.

CRA Cybersecurity Risk Assessment

What evidence should the technical documentation retain from the risk assessment?

Retain the assessment itself and enough linked evidence for a reviewer to follow the decision from product facts to controls. This normally includes the intended purpose and conditions of use, architecture and data flows, assets and trust boundaries, threat scenarios, component and dependency records, applicable and non-applicable Annex I requirements, mitigations, verification results, residual-risk decisions, and the support-period rationale.

Annex VII requires the technical documentation to be continuously updated where appropriate during the support period. Keep version history and decision records so a market surveillance authority or conformity assessment body can tell which product version, risks, requirements, and tests each assessment covered.

Citations
Cyber Resilience Act

Article 13(4), Article 13(7), Article 31, and Annex VII specify the risk-assessment and technical-documentation content and continuing-update duty.

CRA Cybersecurity Risk Assessment

When must a CRA cybersecurity risk assessment be reviewed or updated?

Review it when new information can change the product's risks or the evidence supporting conformity. Triggers include a new vulnerability, changed threat or exposure, a component or supplier change, an unsupported dependency, a new interface or remote service, changed intended purpose or conditions of use, a functionality update, a security incident, or test results that invalidate an assumption.

Article 13(7) requires manufacturers to document relevant cybersecurity aspects and, where applicable, update the assessment. A change that affects Annex I Part I compliance or changes the intended purpose can also be a substantial modification, requiring the person making the change to reassess conformity before the modified product is made available.

Citations
Cyber Resilience Act

Article 3(30), Article 13(7), Article 22, and recital 39 establish documentation, update, and substantial-modification consequences.

CRA Cybersecurity Risk Assessment

Is there one mandatory CRA risk-assessment template or method?

No single template or named threat-modelling method is prescribed by Article 13. The manufacturer may use a method suited to the product, provided the result covers the legally required inputs, supports the Annex I decisions, is proportionate to the risks, and can demonstrate conformity.

A checklist without product-specific threat, exposure, control, and residual-risk reasoning is not enough. Whatever method is used, keep the reasoning traceable across product versions and connect it to design evidence, tests, vulnerability handling, user information, and the conformity assessment.

Citations
Cyber Resilience Act

Article 13 and Annex VII prescribe the required assessment content and evidence outcome without mandating one named assessment methodology.

CRA Declaration of Conformity

What is the CRA EU Declaration of Conformity?

It is the document in which the manufacturer declares that the product with digital elements complies with the Cyber Resilience Act and takes responsibility for that compliance.

For CRA purposes, the declaration states that fulfilment of the applicable essential cybersecurity requirements in Annex I has been demonstrated. It should therefore be consistent with the conformity assessment route, the technical documentation, the cybersecurity risk assessment, and any harmonised standards, common specifications, cybersecurity certifications, or notified-body certificates relied on.

Before signature, match the declaration to the exact product name, type, compliance-relevant software version or other traceable identifier, applicable Union legislation, standards or specifications actually applied, and notified-body evidence where required. A declaration copied from a related model is not enough unless the stated object and supporting technical documentation cover the supplied product.

Citations
CRA Declaration of Conformity

Can a CRA product be placed on the market without a Declaration of Conformity?

No. Before placing a product with digital elements on the market, the manufacturer must draw up technical documentation, complete or have completed the chosen conformity assessment procedure, and, where conformity has been demonstrated, draw up the EU Declaration of Conformity and affix the CE marking.

The product must also be accompanied by either a copy of the full EU Declaration of Conformity or a simplified EU Declaration of Conformity that points to the full text.

Citations
Cyber Resilience Act

Article 13(12) links technical documentation, conformity assessment, the declaration, and CE marking before placement on the market.

CRA Declaration of Conformity

What CRA declaration formats are allowed?

The CRA allows two customer-facing formats. The first is the full EU Declaration of Conformity, using the Annex V model structure. The second is the simplified EU Declaration of Conformity, using the Annex VI wording and giving the exact internet address where the full declaration can be accessed.

The simplified version reduces what accompanies the product, but it does not remove the obligation to create and maintain the full EU Declaration of Conformity.

Citations
Cyber Resilience Act

Article 13(20), Article 28(2), Annex V, and Annex VI establish the full and simplified formats.

CRA Declaration of Conformity

What must the full Annex V Declaration of Conformity contain?

Annex V requires enough information to identify the product and the compliance basis. The full declaration must include the product name, type, and identifying information; the manufacturer or authorised representative name and address; a sole-responsibility statement; the object of the declaration; and a statement that the product conforms with the relevant Union harmonisation legislation.

It must also list the relevant harmonised standards, common specifications, or cybersecurity certification used, and, where applicable, the notified body's name and number, the conformity assessment procedure performed, and the certificate issued. The signature block should identify the place and date of issue, name, function, and signature.

Citations
CRA Declaration of Conformity

What must the simplified Annex VI declaration contain?

The simplified declaration must follow the Annex VI model. It names the manufacturer, identifies the product type, states that the product is in compliance with Regulation (EU) 2024/2847, and gives the internet address where the full EU Declaration of Conformity is available.

Teams using the simplified version should control that URL like a release artifact: it should resolve to the current full declaration for the product version being supplied, remain stable for authority checks, and be updated when the underlying declaration changes.

Citations
Cyber Resilience Act

Article 13(20) and Annex VI require the simplified declaration to include the exact internet address for the full text.

CRA Declaration of Conformity

How does the Declaration of Conformity relate to CE marking?

The CE marking and the declaration are linked outputs of the same market-access sequence. The manufacturer affixes the CE marking only after the relevant conformity assessment procedure has demonstrated conformity and the EU Declaration of Conformity has been drawn up.

For physical products, the CE marking must generally be placed visibly, legibly, and indelibly on the product. Where that is not possible or not warranted, it goes on the packaging and on the accompanying EU Declaration of Conformity. For software products, the CE marking may be placed either on the EU Declaration of Conformity or on the website accompanying the software product, with the relevant website section easily and directly accessible to consumers.

Citations
Cyber Resilience Act

Article 13(12) and Article 30 connect conformity assessment, the declaration, and CRA CE-marking placement rules.

European Commission CRA FAQs

Section 6.7 explains CE marking as a manufacturer self-declaration addressed to consumers and market surveillance authorities.

Page 7 of 58