Does every CRA product need a cybersecurity risk assessment, or only important and critical products?
Every in-scope product with digital elements needs one. Classification as an important or critical product affects conformity assessment routes and assurance expectations, but it does not supersede the Article 13 risk assessment.
The Commission FAQ is explicit that default-category, important, and critical products all require a comprehensive cybersecurity risk assessment. The depth of treatment should reflect the product's actual risk profile, intended use, deployment context, and expected exposure.
Article 13(2) applies the assessment duty to products with digital elements in scope.
Section 3.3 states that the obligation applies irrespective of default, important, or critical classification.