Cyber Resilience Act

Cyber threat

Legal definition Art. 3(46) CRA

“a cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881”
Regulation (EU) 2024/2847, Art. 3(46) CRA

A cyber threat under the Cyber Resilience Act (CRA) is any potential circumstance, event or action that could damage, disrupt or otherwise adversely impact network and information systems, the users of such systems and other persons. Article 3, point (46), does not spell that out itself; it refers to Article 2, point (8), of Regulation (EU) 2019/881, the Cybersecurity Act.

That definition is deliberately wide. It requires no damage, no attack and not even a malicious actor. The mere possibility of an adverse effect suffices, and circumstances, events and actions all qualify.

A possibility, not an occurrence

What separates the term from its neighbours in the CRA is whether anything happened at all. A cyber threat need never have materialised, because it describes what could occur. An Incident, by contrast, is an event that actually compromises availability, authenticity, integrity or confidentiality. A near miss sits between the two. It is an event that could have caused such a compromise but was prevented from materialising, or never materialised at all.

The reference point differs as well. Incidents and near misses are measured against an affected system, whereas the cyber threat is framed without any product at all. It is directed at network and information systems, their users and other persons. A product with digital elements does not appear in the definition.

The term carries the definition of a vulnerability

The practical weight of the term sits elsewhere in the Regulation. Under Article 3, point (40), a Vulnerability is a weakness, susceptibility or flaw of a product with digital elements that can be exploited by a cyber threat. The cyber threat is therefore the filter separating security-relevant defects from ordinary ones.

Because that filter is coarse, little is held back by it. A conceivable circumstance under which the weakness could have an adverse effect is enough. No published exploit, no named adversary and no entry in a vulnerability database is required. A pure rendering glitch stays outside; an insecure default does not.

Threats do not stop at product boundaries

Recital 9 draws a conclusion from this about how far manufacturer obligations reach. Because cyber threats can propagate through various products with digital elements before a given target is reached, for example by chaining together multiple vulnerability exploits, manufacturers are expected to ensure the cybersecurity of products that are only indirectly connected to other devices or networks.

For the risk assessment this means a product does not drop out of scope merely because it holds nothing worth protecting itself. It can serve as a staging post, and that role belongs in the analysis of the operational environment required by Article 13(3).

Reporting is voluntary

Article 15(1) leaves manufacturers and every other natural or legal person free to report cyber threats that could affect the risk profile of a product with digital elements to a CSIRT designated as coordinator or to ENISA. The CRA imposes no duty to do so.

That is precisely what sets cyber threats apart from the subject matter of Article 14. Only actively exploited vulnerabilities and severe incidents must be reported, and only there does the 24-hour early warning clock run. For cyber threats there is no deadline, because there is no obligation.

A separate channel is nonetheless unnecessary. Article 16(1) expressly brings voluntary reports into the Single reporting platform. Article 15(5) adds protection for whoever reports. The information must be treated confidentially, and a voluntary report may not give rise to obligations that would not have applied without it.

Article 52(11) covers the consumer side. Market surveillance authorities must tell consumers where and how to access mechanisms that facilitate the reporting of vulnerabilities, incidents and cyber threats affecting products with digital elements.

Threat and risk are not the same thing

Under Article 3, point (37), Cybersecurity risk is the potential for loss or disruption caused by an incident, expressed as a combination of magnitude and likelihood of occurrence. The threat is an input to that assessment, the risk its result.

CRA obligations hang on the risk rather than on the threat. Article 13(2) requires a cybersecurity risk assessment, and Article 13(3) requires it to be documented and, where appropriate, updated across the support period, based on intended purpose and reasonably foreseeable use. Which threats to assume, and which sources to draw them from, the Regulation does not say.

Nor is there any grading by severity. The NIS2 Directive knows the significant cyber threat in Article 6, point (11), whereas the CRA escalates only on the risk side, to the significant cybersecurity risk in Article 3, point (38).

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.