Implementation

How to Conduct a CRA Product Risk Assessment (Article 13 + Annex I)

A walkthrough of CRA's mandatory product risk assessment using the BSI TR-03183-1 framework.

March 2026 · 11 min read

Why Required

CRA Article 13(2) mandates a documented cybersecurity risk assessment prior to placing a product on the market. The assessment informs the security controls in Annex I, Part I.

The 7-Step Process

  1. Define product scope
  2. Identify assets — data, interfaces, keys, services
  3. Map attack surface — APIs, data flows, entry points
  4. Identify threats — use STRIDE methodology
  5. Assess impact — confidentiality, integrity, availability
  6. Document controls and effectiveness
  7. Calculate residual risk

Use our Risk Assessment Wizard for guided assistance.

Get the CRA deadline calendar

A one-page PDF showing every CRA date that matters for your product team. Free — no spam, unsubscribe anytime.

Related articles

Ready to Take Action?

Start your CRA compliance journey with our free assessment tool.