Free local worksheet · product cybersecurity
Cyber Resilience Act product risk assessment.
Create a structured product cybersecurity risk assessment draft for a software or connected product. Record intended use, threat scenarios, controls, residual risk, owners and evidence, then download the draft for your team's review.
What is a CRA product cybersecurity risk assessment? The Cyber Resilience Act requires manufacturers to assess cybersecurity risks associated with a product with digital elements and take the assessment into account during planning, design, development, production, delivery and maintenance. The outcome informs how the product's essential cybersecurity requirements apply and is part of technical documentation.
This worksheet helps a team organise that reasoning. It does not prescribe a risk method, invent legal thresholds or determine that a product is compliant. Document your method and product-specific decisions, and have the result reviewed by the people responsible for product security and regulatory interpretation.
1 · Product context
Describe the product and its use.
2 · Risk scenarios
Record the reasoning and evidence.
Draft output
Product risk record
1 scenario recorded · 0 with a team-assessed residual-risk band · review 2026-09-30
- Scenario 1Product asset or function not enteredResidual: Not assessed
4 · Review and retain
What this worksheet does
It organises product use context, risk reasoning, controls, residual risk and evidence for human review. It does not calculate risk, determine CRA applicability, decide conformity or certify compliance. Review the assessment as the product, threat landscape and supporting evidence change.
Method and source
A record, not a legal score
The browser draft uses no formula or automated legal conclusion. It preserves what your team enters in this browser and exports a JSON worksheet only when you choose to download it.
Last verified 29 September 2026 against the Official Journal text of Regulation (EU) 2024/2847.
Read next
- Guide
CRA readiness checklist for software and connected-product manufacturers
A practical CRA checklist across governance, SBOM, vulnerability handling, disclosure, incidents, reporting, support period and documentation, with evidence to keep and current transition milestones.
- Guide
SBOM guide for the CRA: formats, minimum content and operations
CycloneDX versus SPDX, what a CRA-oriented SBOM must contain, which tools generate one per ecosystem, how to keep it current per release, how to share it, and how it feeds vulnerability handling and VEX.
- Guide
CRA product classification: default, important (Class I / II) and critical
How Annex III and Annex IV categories work, the core-functionality test, what changes for conformity assessment under Article 32, edge cases, and how to document a classification decision that will survive scrutiny.
- Docs
Product registry
Products, versions, lifecycle, classification, exposure context.
- Docs
SBOM ingestion
Upload, GitHub, GitLab, CI/CD and the API.
- Docs
VEX
Per-product exploitability statements and signed CycloneDX VEX documents.
- Free tool
SBOM quality checker
Inspect CycloneDX or SPDX structure, identifiers, metadata and dependency graph locally in your browser.