Skip to main content
Oficiálna stránka verejnej správy SR
Cyber Resilience Act · National Security Authority

Cybersecurity risk assessment and technical documentation

Last updated:

Cybersecurity risk assessment and technical documentation

Risk assessment is not a one-off attachment to CE marking. It determines which essential requirements are relevant, how the manufacturer will meet them and what evidence must be maintained during the support period.

Law

The manufacturer must assess the cybersecurity risks associated with the product with digital elements. It must consider intended purpose, reasonably foreseeable use, conditions of use and the expected use time. The assessment informs planning, design, development, production, delivery and maintenance.

The assessment must state whether and how each Annex I Part I requirement applies. A requirement considered inapplicable needs a clear justification. An identified risk cannot simply be ignored because a particular technical measure is unsuitable; it should be addressed through another proportionate measure, a restriction of intended purpose or user information.

The assessment must be included in the technical documentation before placement on the market. Relevant cybersecurity aspects, known vulnerabilities and third-party information must be documented systematically and proportionately. Update the assessment where appropriate, at least during the support period.

Required technical-documentation content

Article 31 and Annex VII require at least, where applicable:

Prepare the file before placement and keep it continuously updated where appropriate, at least during support. One combined technical file may cover other applicable EU legislation if all required information is included.

Keep the technical documentation and EU declaration available to market-surveillance authorities for at least ten years after placement or for the support period, whichever is longer. On a reasoned request, supply the necessary information and documentation in paper or electronic form and in an easily understood language.

Guidance — practical workflow

  1. Assign an unambiguous product, model and version identifier and a documentation owner.
  2. Describe assets, trust boundaries, data flows, interfaces, operating environment, users and reasonably foreseeable misuse.
  3. Identify threats, vulnerabilities, impact and likelihood; determine inherent and residual risk.
  4. Map each risk to an Annex I requirement, control, test, evidence and owner.
  5. Record inapplicability decisions and alternative measures.
  6. Connect component risk, the SBOM, supplier commitments and component end-of-support dates to final-product risk.
  7. Define update triggers: new release, component change, vulnerability, incident, standard change, environment change or intended-purpose change.
  8. Have an independent reviewer confirm completeness, version and evidence traceability before release.

Approval check

Page sources: CRA Articles 13(2)–(7), 13(12), 13(22), 31; Annexes I and VII; Commission final implementation guidance, sections on risk assessment. See the shared source register below.