Cybersecurity risk assessment and technical documentation
Risk assessment is not a one-off attachment to CE marking. It determines which essential requirements are relevant, how the manufacturer will meet them and what evidence must be maintained during the support period.
Law
The manufacturer must assess the cybersecurity risks associated with the product with digital elements. It must consider intended purpose, reasonably foreseeable use, conditions of use and the expected use time. The assessment informs planning, design, development, production, delivery and maintenance.
The assessment must state whether and how each Annex I Part I requirement applies. A requirement considered inapplicable needs a clear justification. An identified risk cannot simply be ignored because a particular technical measure is unsuitable; it should be addressed through another proportionate measure, a restriction of intended purpose or user information.
The assessment must be included in the technical documentation before placement on the market. Relevant cybersecurity aspects, known vulnerabilities and third-party information must be documented systematically and proportionately. Update the assessment where appropriate, at least during the support period.
Required technical-documentation content
Article 31 and Annex VII require at least, where applicable:
- a general product description, intended purpose and software versions affecting conformity;
- for hardware, photographs or illustrations of external features, marking and internal layout;
- information needed to understand design, development, production, operation and vulnerability handling;
- the complete cybersecurity risk assessment and Annex I mapping;
- the information and factors used to determine the support period;
- descriptions of implemented solutions and controls, including security architecture;
- harmonised standards, common specifications, certification schemes and other technical specifications applied fully or partly;
- evidence from design reviews, analyses, tests and conformity assessment;
- vulnerability-handling information, including a machine-readable SBOM covering at least top-level dependencies, the CVD policy, contact point and secure update distribution;
- a copy of the EU declaration of conformity.
Prepare the file before placement and keep it continuously updated where appropriate, at least during support. One combined technical file may cover other applicable EU legislation if all required information is included.
Keep the technical documentation and EU declaration available to market-surveillance authorities for at least ten years after placement or for the support period, whichever is longer. On a reasoned request, supply the necessary information and documentation in paper or electronic form and in an easily understood language.
Guidance — practical workflow
- Assign an unambiguous product, model and version identifier and a documentation owner.
- Describe assets, trust boundaries, data flows, interfaces, operating environment, users and reasonably foreseeable misuse.
- Identify threats, vulnerabilities, impact and likelihood; determine inherent and residual risk.
- Map each risk to an Annex I requirement, control, test, evidence and owner.
- Record inapplicability decisions and alternative measures.
- Connect component risk, the SBOM, supplier commitments and component end-of-support dates to final-product risk.
- Define update triggers: new release, component change, vulnerability, incident, standard change, environment change or intended-purpose change.
- Have an independent reviewer confirm completeness, version and evidence traceability before release.
Approval check
Page sources: CRA Articles 13(2)–(7), 13(12), 13(22), 31; Annexes I and VII; Commission final implementation guidance, sections on risk assessment. See the shared source register below.