Cyber Resilience Act

Cybersecurity risk

Legal definition Art. 3(37) CRA

“the potential for loss or disruption caused by an incident and is to be expressed as a combination of the magnitude of such loss or disruption and the likelihood of occurrence of the incident”
Regulation (EU) 2024/2847, Art. 3(37) CRA

Cybersecurity risk is not a mood in the Cyber Resilience Act (CRA) but a combination of two factors: the magnitude of a possible loss or disruption, and the likelihood that the incident causing it occurs. Both belong to the definition. A catastrophic but practically unreachable outcome is therefore not a high risk, and neither is a frequent triviality.

The reference point is the Incident, not the vulnerability. The CRA takes that definition from Article 6, point (6), of Directive (EU) 2022/2555 (NIS2): an event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data, or of the services offered by, or accessible via, network and information systems. Without a conceivable event of that kind there is no risk in the sense of the Regulation.

The assessment decides which requirements apply

Article 13(2) obliges the manufacturer to undertake an assessment of the cybersecurity risks associated with a product with digital elements and to take its outcome into account across six phases: planning, design, development, production, delivery and maintenance.

The practical weight sits in Annex I, Part I, point 2. The thirteen product properties listed there under points (a) to (m) run from being made available without known exploitable vulnerabilities through secure-by-default configuration, protection against unauthorised access and data minimisation to the secure deletion of all data and settings. They apply expressly “on the basis of the cybersecurity risk assessment” and “where applicable”. Which of them a given product must meet therefore follows from the assessment. Two blocks are not subject to that qualifier: the appropriate level of cybersecurity based on the risks required by Annex I, Part I, point 1, and the vulnerability handling requirements in Annex I, Part II.

The minimum content

Article 13(3) prescribes what the assessment must comprise at least:

  • an analysis of cybersecurity risks based on the intended purpose and reasonably foreseeable use, including the conditions of use such as the operational environment or the assets to be protected
  • taking into account the length of time the product is expected to be in use
  • a statement of whether and, if so, in what manner the requirements in Annex I, Part I, point 2 apply and how they are implemented
  • a statement of how the manufacturer applies Annex I, Part I, point 1 and the vulnerability handling requirements in Annex I, Part II

The assessment must be documented and updated as appropriate throughout the Support period. Article 13(7) adds a duty to document all relevant cybersecurity aspects systematically and proportionately to the nature of the risks (including vulnerabilities the manufacturer becomes aware of) and to update the assessment where applicable.

Where the assessment lands

On placing the product on the market, Article 13(4) requires the manufacturer to include the assessment in the Technical documentation; Annex VII names it explicitly under point 3. Where certain essential cybersecurity requirements do not apply to the product, a clear justification belongs in the same documentation.

Recital 55 gives an example: the intended purpose of a product may require the manufacturer to follow widely recognised interoperability standards even where their security features are no longer state of the art. Where the manufacturer has identified risks in that connection, they do not disappear with the non-applicability. The manufacturer should then address them by other means, for instance by limiting the intended purpose to trusted environments or by informing users about those risks. The recital explains the Regulation; it does not create an obligation of its own.

For high-risk AI systems under Article 12, the assessment may form part of the risk assessment those other Union legal acts require in any case. Two separate documents are not prescribed.

Significant cybersecurity risk: the second tier

Article 3, point (38) adds an escalation. A significant cybersecurity risk is one which, based on its technical characteristics, can be assumed to have a high likelihood of an incident that could lead to a severe negative impact, including by causing considerable material or non-material loss or disruption.

Obligations beyond the manufacturer attach to it. Importers (Article 19(3) and (5)) and distributors (Article 20(3) and (4)) must inform the manufacturer and the Market surveillance authority as soon as they identify such a risk. Where a market surveillance authority has sufficient reason to consider that a significant cybersecurity risk is present, it evaluates the product against the requirements of the Regulation under Article 54(1). If that evaluation finds the product non-compliant, the authority requires the economic operator to take corrective action, to withdraw the product from the market or to recall it, within a period commensurate with the nature of the cybersecurity risk.

Two points are easily missed. First, under Article 54(2) authorities also weigh non-technical risk factors, notably those from the Union-level coordinated security risk assessments of critical supply chains under Article 22 NIS2, even though the definition itself refers only to technical characteristics. Second, Article 57 bites on products that fully comply with the Regulation: where the authority finds, having performed an evaluation under Article 54, that they present a significant cybersecurity risk together with one of the further risks listed there, such as a risk to the health or safety of persons, it must require the economic operator to take appropriate measures.

What the CRA leaves open

The Regulation prescribes no method. There is no mandated scale, no risk matrix, and no threshold above which a risk counts as controlled. A manufacturer applying neither harmonised standards nor common specifications nor European cybersecurity certification schemes must instead describe, under Annex VII, point 5, the solutions adopted to meet the essential requirements in Annex I, Parts I and II. That shifts the burden of justification onto the manufacturer.

For microenterprises and small enterprises, Article 33(5) provides a simplified format for the technical documentation, to be specified by the Commission in an implementing act and to be accepted by notified bodies. What that eases is the form, not the substance of the assessment.

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.