Definition

Cybersecurity risk assessment

The documented assessment of a product's cybersecurity risks that drives which essential requirements apply and how.

Manufacturers must undertake an assessment of the cybersecurity risks associated with a product with digital elements and take its outcome into account during planning, design, development, production, delivery and maintenance. It must consider the intended purpose and reasonably foreseeable use, and it determines how each Annex I Part I requirement applies (or is documented as not applicable). The assessment is part of the technical documentation and is updated during the support period.

Reference: Art. 13(2)–(3); Annex VII(3) · Regulation (EU) 2024/2847 on EUR-Lex

Updated 2026-09-12 · Paraphrase for orientation, not legal advice.

Related terms

See the term as a workflow.

Vellaci turns each of these definitions into a record with an owner, a timestamp and evidence.