Why Required
CRA Article 13(2) mandates a documented cybersecurity risk assessment prior to placing a product on the market. The assessment informs the security controls in Annex I, Part I.
The 7-Step Process
- Define product scope
- Identify assets — data, interfaces, keys, services
- Map attack surface — APIs, data flows, entry points
- Identify threats — use STRIDE methodology
- Assess impact — confidentiality, integrity, availability
- Document controls and effectiveness
- Calculate residual risk
Use our Risk Assessment Wizard for guided assistance.
Get the CRA deadline calendar
A one-page PDF showing every CRA date that matters for your product team. Free — no spam, unsubscribe anytime.
Related articles
Ready to Take Action?
Start your CRA compliance journey with our free assessment tool.