Cyber Resilience Act

Significant cybersecurity risk

Legal definition Art. 3(38) CRA

“a cybersecurity risk which, based on its technical characteristics, can be assumed to have a high likelihood of an incident that could lead to a severe negative impact, including by causing considerable material or non-material loss or disruption”
Regulation (EU) 2024/2847, Art. 3(38) CRA

A significant cybersecurity risk is the threshold at which the Cyber Resilience Act (CRA) sets market surveillance in motion. Article 3, point (38) describes no new kind of risk but an escalation of the general one, and specific duties for importers and distributors hang on it, as does a formal enforcement procedure.

The definition requires two elements, and both must be present. First, an Incident must be highly likely. Second, that incident must be capable of a severe negative impact, including by causing considerable material or non-material loss or disruption. Miss either element and the term does not bite. A likely incident with slight consequences qualifies no more than a devastating one that is far-fetched.

The base concept is the Cybersecurity risk of Article 3, point (37), which combines magnitude and likelihood of occurrence. Significance puts a threshold across both, without naming a number for either.

Technical characteristics, and yet not only those

The wording turns expressly on the technical characteristics of the risk. Article 54(2) widens the lens again. When determining significance, market surveillance authorities must also consider non-technical risk factors, in particular those established through the Union-level coordinated security risk assessments of critical supply chains under Article 22 of the NIS-2 Directive.

Recital 58 shows what the legislator has in mind. It treats dependencies on high-risk suppliers as a strategic risk and names, as possible points of attachment, the jurisdiction applicable to the manufacturer, the characteristics of its corporate ownership, and the links of control to the government of the third country where the manufacturer is established. Read the term as purely technical and you will underestimate what an authority may weigh.

Who has to make the call

The term does not appear in the manufacturer duties of Articles 13 and 14; manufacturer reporting under Article 14 attaches to the actively exploited vulnerability and to the severe incident having an impact on the security of the product. The significant cybersecurity risk is judged further down the supply chain.

The Importer carries the duty in three places:

  • Considering a product or the manufacturer’s processes non-compliant, the importer must not place it on the market until conformity has been brought about. Where it additionally presents a significant cybersecurity risk, Article 19(3) requires the manufacturer and the market surveillance authorities to be informed as well.
  • The same paragraph carries a second, free-standing duty: where the importer has reason to believe a product may present such a risk in light of non-technical risk factors, the authorities must be informed and then proceed under Article 54(2). No technical finding is needed.
  • On becoming aware of a vulnerability, Article 19(5) requires the importer to inform the manufacturer without undue delay. Where the product presents a significant cybersecurity risk, the importer must in addition immediately inform the authorities of every Member State where it made the product available, giving details, in particular, of the non-compliance and of any corrective measures taken.

Article 20(3) and (4) put the same pattern on the Distributor, but narrower in two respects. The judgement is expressly measured against the information in the distributor’s possession, and the non-technical risk factor clause is absent. The Regulation gives no reason for the difference.

Manufacturers meet the term only as a documentation duty. Annex II, point 5 requires the information and instructions to the user to name any known or foreseeable circumstance, related to the use of the product in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to significant cybersecurity risks.

What the Article 54 procedure means

Where a Market surveillance authority has sufficient reason to consider that a product, including its vulnerability handling, presents a significant cybersecurity risk, it evaluates the product without undue delay, with the relevant CSIRT where appropriate. Two points get underestimated. The trigger expressly covers vulnerability handling, and the evaluation does not stop at the trigger: compliance with all the requirements of the Regulation is examined. The economic operators concerned must cooperate with the authority as necessary.

Where necessary to assess conformity with the essential cybersecurity requirements of Annex I, Article 53 gives the authority access, on reasoned request, to the data needed to assess design, development, production and vulnerability handling, including the related internal documentation of the economic operator.

Where the authority finds non-compliance, it requires the economic operator to take corrective action, to withdraw the product or to recall it, within a period commensurate with the nature of the cybersecurity risk. The CRA names no fixed number of days. Article 18 of Regulation (EU) 2019/1020 governs those corrective actions.

Where the economic operator takes no adequate corrective action within that period, Article 54(5) brings provisional measures prohibiting or restricting availability on the national market, withdrawal or recall, and the Commission and the other Member States are notified without delay. If neither a Member State nor the Commission objects within three months of receipt of that notification, the measure is deemed justified. If somebody does object, the Commission decides under the Union safeguard procedure of Article 55, within nine months of receipt of that same notification, whether the national measure is justified.

A compliant product can be caught too

Article 57 is the provision most easily overlooked. It applies where the authority, having performed an evaluation under Article 54, finds that the product and the manufacturer’s processes do comply, yet present a significant cybersecurity risk together with a risk to one of the following:

  • the health or safety of persons
  • compliance with obligations under Union or national law intended to protect fundamental rights
  • the availability, authenticity, integrity or confidentiality of services offered by essential entities under Article 3(1) of the NIS-2 Directive using an electronic information system
  • other aspects of public interest protection

Both elements have to coincide; a significant cybersecurity risk on its own does not carry Article 57. Where they do, the authority requires appropriate measures, which can extend to withdrawal from the market or recall and must be proportionate to the nature of those risks. The Commission then evaluates the national measure and decides whether it is justified.

What the CRA leaves open

The CRA sets no threshold at which a likelihood becomes “high” and an impact “severe”. It provides for neither an implementing act nor a harmonised standard to fill that gap. When it matters, the authority makes the classification.

The only counterweight is built long beforehand: a risk assessment stating which incidents the manufacturer considers likely, what consequences it attributes to them, and why. Supply that only once a procedure is running and you argue about your documentation instead of your product.

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.