Definition
Cybersecurity risk assessment
The documented assessment of a product's cybersecurity risks that drives which essential requirements apply and how.
Manufacturers must undertake an assessment of the cybersecurity risks associated with a product with digital elements and take its outcome into account during planning, design, development, production, delivery and maintenance. It must consider the intended purpose and reasonably foreseeable use, and it determines how each Annex I Part I requirement applies (or is documented as not applicable). The assessment is part of the technical documentation and is updated during the support period.
Reference: Art. 13(2)–(3); Annex VII(3) · Regulation (EU) 2024/2847 on EUR-Lex
Updated 2026-09-12 · Paraphrase for orientation, not legal advice.