Cyber Resilience Act
Cyber threat
Legal definition Art. 3(46) CRA
“a cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881”
A cyber threat under the Cyber Resilience Act (CRA) is any potential circumstance, event or action that could damage, disrupt or otherwise adversely impact network and information systems, the users of such systems and other persons. Article 3, point (46), does not spell that out itself; it refers to Article 2, point (8), of Regulation (EU) 2019/881, the Cybersecurity Act.
That definition is deliberately wide. It requires no damage, no attack and not even a malicious actor. The mere possibility of an adverse effect suffices, and circumstances, events and actions all qualify.
A possibility, not an occurrence
What separates the term from its neighbours in the CRA is whether anything happened at all. A cyber threat need never have materialised, because it describes what could occur. An Incident, by contrast, is an event that actually compromises availability, authenticity, integrity or confidentiality. A near miss sits between the two. It is an event that could have caused such a compromise but was prevented from materialising, or never materialised at all.
The reference point differs as well. Incidents and near misses are measured against an affected system, whereas the cyber threat is framed without any product at all. It is directed at network and information systems, their users and other persons. A product with digital elements does not appear in the definition.
The term carries the definition of a vulnerability
The practical weight of the term sits elsewhere in the Regulation. Under Article 3, point (40), a Vulnerability is a weakness, susceptibility or flaw of a product with digital elements that can be exploited by a cyber threat. The cyber threat is therefore the filter separating security-relevant defects from ordinary ones.
Because that filter is coarse, little is held back by it. A conceivable circumstance under which the weakness could have an adverse effect is enough. No published exploit, no named adversary and no entry in a vulnerability database is required. A pure rendering glitch stays outside; an insecure default does not.
Threats do not stop at product boundaries
Recital 9 draws a conclusion from this about how far manufacturer obligations reach. Because cyber threats can propagate through various products with digital elements before a given target is reached, for example by chaining together multiple vulnerability exploits, manufacturers are expected to ensure the cybersecurity of products that are only indirectly connected to other devices or networks.
For the risk assessment this means a product does not drop out of scope merely because it holds nothing worth protecting itself. It can serve as a staging post, and that role belongs in the analysis of the operational environment required by Article 13(3).
Reporting is voluntary
Article 15(1) leaves manufacturers and every other natural or legal person free to report cyber threats that could affect the risk profile of a product with digital elements to a CSIRT designated as coordinator or to ENISA. The CRA imposes no duty to do so.
That is precisely what sets cyber threats apart from the subject matter of Article 14. Only actively exploited vulnerabilities and severe incidents must be reported, and only there does the 24-hour early warning clock run. For cyber threats there is no deadline, because there is no obligation.
A separate channel is nonetheless unnecessary. Article 16(1) expressly brings voluntary reports into the Single reporting platform. Article 15(5) adds protection for whoever reports. The information must be treated confidentially, and a voluntary report may not give rise to obligations that would not have applied without it.
Article 52(11) covers the consumer side. Market surveillance authorities must tell consumers where and how to access mechanisms that facilitate the reporting of vulnerabilities, incidents and cyber threats affecting products with digital elements.
Threat and risk are not the same thing
Under Article 3, point (37), Cybersecurity risk is the potential for loss or disruption caused by an incident, expressed as a combination of magnitude and likelihood of occurrence. The threat is an input to that assessment, the risk its result.
CRA obligations hang on the risk rather than on the threat. Article 13(2) requires a cybersecurity risk assessment, and Article 13(3) requires it to be documented and, where appropriate, updated across the support period, based on intended purpose and reasonably foreseeable use. Which threats to assume, and which sources to draw them from, the Regulation does not say.
Nor is there any grading by severity. The NIS2 Directive knows the significant cyber threat in Article 6, point (11), whereas the CRA escalates only on the risk side, to the significant cybersecurity risk in Article 3, point (38).
Practical questions
-
No. Article 15(5) states expressly that voluntary reporting must not impose obligations that would not have applied without the report, and it binds the receiving body to confidentiality. Two points are still worth factoring in. A CSIRT designated as coordinator may prioritise mandatory notifications, so a swift response is not assured. And where someone other than the manufacturer reports an Actively exploited vulnerability, the CSIRT informs the manufacturer without undue delay.
-
The CRA prescribes no method. What it requires is a cybersecurity risk assessment under Article 13(2) covering, per Article 13(3), at least an analysis of cybersecurity risks based on the intended purpose and reasonably foreseeable use of the product, such as its operational environment or the assets to be protected. Threat modelling is the usual way to make that analysis traceable, but it remains an implementation choice. Anyone applying a harmonised standard normally inherits its methodology.
-
It can. The vulnerability definition in Article 3, point (40), is relative to the threat picture, so a weakness nobody could take advantage of before may become a vulnerability once attack techniques move on. The Annex I, Part II requirements then apply, and they run for the whole support period. Article 13(7) additionally requires the cybersecurity risk assessment to be updated where needed. The product does not become retroactively non-compliant, but the duty to handle the vulnerability applies at once.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.