Back to Knowledge Base
Knowledge Base · implementation

Running a product cybersecurity risk assessment

20 May 2026 6 min read Security

A repeatable method to assess and document product risk — the analytical core of CRA technical documentation.

Steps

  • Define the product, its assets and trust boundaries.
  • Identify threats and likely attackers.
  • Assess likelihood and impact.
  • Decide treatments and accept residual risk explicitly.

Keep it living

Re-run the assessment on significant change. A stale assessment is a common audit finding.

Document it

The assessment and its conclusions are required technical-documentation content.

This is an educational explainer. For the canonical regulation reference, see the dedicated Security page — or run an assessment to see how it applies to your product.