If a product is intended to be integrated into another system, must the manufacturer explain its security assumptions and conditions of use in the CRA cybersecurity risk assessment and user information?
Yes.
The Commission FAQ says manufacturers should inform users and integrators about assumptions and requirements relevant to secure installation, operation and use. That follows from the CRA's focus on intended purpose, reasonably foreseeable use, conditions of use and the user information required by Annex II.
Article 13(3), Annex II
section 4.1.4