×
1 Choose EITC/EITCA Certificates
2 Learn and take online exams
3 Get your IT skills certified

Confirm your IT skills and competencies under the European IT Certification framework from anywhere in the world fully online.

EITCA Academy

Digital skills attestation standard by the European IT Certification Institute aiming to support Digital Society development

LOG IN TO YOUR ACCOUNT

CREATE AN ACCOUNT FORGOT YOUR PASSWORD?

FORGOT YOUR PASSWORD?

AAH, WAIT, I REMEMBER NOW!

CREATE AN ACCOUNT

ALREADY HAVE AN ACCOUNT?
EUROPEAN INFORMATION TECHNOLOGIES CERTIFICATION ACADEMY - ATTESTING YOUR PROFESSIONAL DIGITAL SKILLS
  • SIGN UP
  • LOGIN
  • INFO

EITCA Academy

EITCA Academy

The European Information Technologies Certification Institute - EITCI ASBL

Certification Provider

EITCI Institute ASBL

Brussels, European Union

Governing European IT Certification (EITC) framework in support of the IT professionalism and Digital Society

  • CERTIFICATES
    • EITCA ACADEMIES
      • EITCA ACADEMIES CATALOGUE<
      • EITCA/CG COMPUTER GRAPHICS
      • EITCA/IS INFORMATION SECURITY
      • EITCA/BI BUSINESS INFORMATION
      • EITCA/KC KEY COMPETENCIES
      • EITCA/EG E-GOVERNMENT
      • EITCA/WD WEB DEVELOPMENT
      • EITCA/AI ARTIFICIAL INTELLIGENCE
    • EITC CERTIFICATES
      • EITC CERTIFICATES CATALOGUE<
      • COMPUTER GRAPHICS CERTIFICATES
      • WEB DESIGN CERTIFICATES
      • 3D DESIGN CERTIFICATES
      • OFFICE IT CERTIFICATES
      • BITCOIN BLOCKCHAIN CERTIFICATE
      • WORDPRESS CERTIFICATE
      • CLOUD PLATFORM CERTIFICATENEW
    • EITC CERTIFICATES
      • INTERNET CERTIFICATES
      • CRYPTOGRAPHY CERTIFICATES
      • BUSINESS IT CERTIFICATES
      • TELEWORK CERTIFICATES
      • PROGRAMMING CERTIFICATES
      • DIGITAL PORTRAIT CERTIFICATE
      • WEB DEVELOPMENT CERTIFICATES
      • DEEP LEARNING CERTIFICATESNEW
    • CERTIFICATES FOR
      • EU PUBLIC ADMINISTRATION
      • TEACHERS AND EDUCATORS
      • IT SECURITY PROFESSIONALS
      • GRAPHICS DESIGNERS & ARTISTS
      • BUSINESSMEN AND MANAGERS
      • BLOCKCHAIN DEVELOPERS
      • WEB DEVELOPERS
      • CLOUD AI EXPERTSNEW
  • FEATURED
  • SUBSIDY
  • HOW IT WORKS
  •   IT ID
  • ABOUT
  • CONTACT
  • MY ORDER
    Your current order is empty.
EITCIINSTITUTE
CERTIFIED

In case my product (TOE Target of Evaluation) is in a default category, is there any specific layout or template for risk assessment, or can I choose the document template of my company?

by Fahad Pathan / Thursday, 10 September 2026 / Published in Cybersecurity, EITC/IS/CRA Cyber Resilience Act, CRA operating model, scope, roles and classification, From legal text to a product-security operating model

When dealing with the European Union’s Cyber Resilience Act (CRA) and considering the obligations regarding risk assessment for products falling within the default category (typically non-critical, standard risk digital products), it is important to understand the regulatory requirements and the degree of flexibility permitted concerning documentation practices.

Regulatory Background and CRA Requirements

The CRA aims to establish a clear set of cybersecurity obligations for manufacturers, importers, and distributors of digital products intended for the European market. A core requirement under the CRA is the implementation and documentation of risk assessments for products within its scope. Article 10 and Article 24 of the CRA draft specifically mandate that manufacturers must conduct and maintain appropriate risk assessments for the cybersecurity of their products to ensure conformity with essential requirements.

The CRA stratifies products into different classes: “default” (standard risk), “important,” and “critical,” with additional obligations for the latter two. For default category products, the risk assessment and documentation process is less prescriptive compared to important or critical categories, for which harmonized standards and more rigorous conformity assessment procedures are often required.

Layout and Template Requirements under the CRA

The legal text of the CRA does not impose a mandatory, unified format or template for risk assessments for products classified in the default category. Instead, it requires that the risk assessment:

– Be appropriate and proportionate to the nature, function, and intended use of the product.
– Be documented and maintained as part of the technical documentation for the product (Annex II, Section 2).
– Demonstrate that all essential cybersecurity requirements have been addressed and that identified risks are mitigated to an acceptable level.

The absence of a mandated template means that manufacturers have the flexibility to use their own document formats, provided that the risk assessment is comprehensive, systematic, and meets the content requirements outlined in the CRA. This approach is in line with the general principles of EU product legislation, which tend to focus on the achievement of objectives (i.e., the “what”) rather than prescribing specific methods or document layouts (i.e., the “how”).

Key Content Elements for CRA-Compliant Risk Assessments

Regardless of the layout or template used, manufacturers must ensure that their risk assessment covers the following aspects:

1. Identification of Assets and Scope: Clearly define the assets (hardware, software, data, interfaces, and connections) covered by the product, its purpose, and operational environment.

2. Threat Identification: List potential cybersecurity threats relevant to the product in its intended context, considering known vulnerabilities, attack vectors, and adversary profiles.

3. Vulnerability Analysis: Document known or potential vulnerabilities in the product or its supply chain that could be exploited.

4. Impact and Likelihood Assessment: Assess the impact and likelihood of potential exploitation of these vulnerabilities, taking into account the severity of consequences for users and other stakeholders.

5. Risk Evaluation: Provide a clear risk evaluation, typically using a risk matrix or similar methodology, to prioritize risks based on their impact and likelihood.

6. Risk Mitigation Measures: Describe the security controls, design features, or operational processes implemented to mitigate identified risks.

7. Residual Risk: Document the residual risk after mitigation and explain why it is considered acceptable in the product’s context.

8. Review and Update Process: Outline procedures for reviewing and updating the risk assessment throughout the product’s lifecycle, especially in response to new threats or vulnerabilities.

Using Company Templates: Practical Considerations

Given the CRA’s flexibility for default category products, organizations may use their own risk assessment templates, provided they address the elements described above. This can facilitate integration with existing processes (for example, those aligned with ISO/IEC 27001, ISO 14971 for medical devices, or IEC 62443 for industrial automation).

Illustrative Example: Using a Company Template Compliant with CRA

Suppose a software vendor produces a desktop productivity application (not classified as critical or important under the CRA). The vendor’s existing risk assessment template, based on ISO/IEC 27005, includes the following sections:

– Product description and scope
– Stakeholder analysis
– Asset inventory
– Threat and vulnerability identification
– Risk analysis and treatment plan
– Residual risk acceptance
– Appendices (supporting evidence, test results)

If this template is used to conduct the CRA-required risk assessment, and all relevant cybersecurity risks and mitigation strategies are documented, it will be considered compliant with the CRA for a default category product. The template should be reviewed to ensure it explicitly covers all CRA-required content, such as a lifecycle approach, regular review triggers, and linkage to technical documentation.

Best Practices for CRA-Aligned Risk Assessment Documentation

1. Clarity and Traceability: Ensure risk assessments are clear, logically structured, and traceable to the essential cybersecurity requirements in the CRA. This makes regulatory inspections and audits more efficient.

2. Lifecycle Considerations: Document how risks are managed throughout the product’s lifecycle, including post-market surveillance and vulnerability handling.

3. Integration with Technical Documentation: The CRA requires that the risk assessment forms part of the technical documentation for the product. Ensure that the risk assessment is referenced and accessible within the technical documentation package.

4. Review Against Harmonized Standards: If European harmonized standards become available for your product type, review your template to ensure gap coverage and alignment.

5. Audit Readiness: Maintain records of risk assessments, updates, and reviews for at least the period of time required by the CRA (typically five to ten years, depending on product type).

Regulatory Precedents and Harmonization

While the CRA allows manufacturers to select their template, it does reference harmonized standards (once published) as a means of presumption of conformity. For example, the upcoming European standard EN ISO/IEC 42001 (for Artificial Intelligence Management Systems) and established standards like ISO/IEC 27001 or IEC 62443 may influence the expected structure and content of risk assessments.

Manufacturers who wish to future-proof their documentation should monitor the development of these standards and anticipate their likely harmonization with CRA requirements.

Potential Pitfalls to Avoid

– Superficial Risk Assessments: Generic or superficial risk assessments that do not address product-specific threats, vulnerabilities, and mitigations will likely be considered non-compliant.
– Omission of Lifecycle Aspects: Failing to document how risks are monitored and managed after market release may be viewed as a deficiency.
– Lack of Traceability: If the link between identified risks, mitigation measures, and the essential requirements of the CRA is unclear, authorities may request additional information or corrective action.

Documentation for Market Surveillance

Competent authorities and market surveillance bodies may request access to the risk assessment as part of technical documentation reviews. Manufacturers should ensure that their chosen template facilitates rapid retrieval of relevant information and supports clear responses to regulatory inquiries.

Interplay with Other EU Legislation

Products subject to other sectoral regulations (e.g., the Medical Device Regulation, Radio Equipment Directive, Machinery Regulation) may already require some form of risk assessment. In such cases, aligning the CRA risk assessment documentation with existing templates can streamline compliance and avoid duplication. However, it is important to check that all CRA-specific cybersecurity aspects are fully addressed, as the CRA may introduce additional requirements beyond sectoral norms.

Conclusion and Practical Guidance

The CRA provides manufacturers of default category products with flexibility in the format and layout of their risk assessments. Companies may leverage their own templates, provided these comprehensively address the content requirements set forth by the CRA. This approach supports integration with existing governance, risk, and compliance processes, and recognizes the diversity of digital products and their contexts. Regular review and adaptation of templates to reflect evolving standards and regulatory expectations are advisable.

More questions and answers:

  • Field: Cybersecurity
  • Programme: EITC/IS/CRA Cyber Resilience Act (go to the certification programme)
  • Lesson: CRA operating model, scope, roles and classification (go to related lesson)
  • Topic: From legal text to a product-security operating model (go to related topic)
Tagged under: CRA, Cybersecurity, EU Regulation, Product Security, Risk Assessment, Technical Documentation
Home » Cybersecurity » EITC/IS/CRA Cyber Resilience Act » CRA operating model, scope, roles and classification » From legal text to a product-security operating model » » In case my product (TOE Target of Evaluation) is in a default category, is there any specific layout or template for risk assessment, or can I choose the document template of my company?

Certification Center

USER MENU

  • My Account

CERTIFICATE CATEGORY

  • EITC Certification (117)
  • EITCA Certification (9)

What are you looking for?

  • Introduction
  • How it works?
  • EITCA Academies
  • EITCI DSJC Subsidy
  • Full EITC catalogue
  • Your order
  • Featured
  •   IT ID
  • EITCA reviews (Medium publ.)
  • About
  • Contact

EITCA Academy is a part of the European IT Certification framework

The European IT Certification framework has been established in 2008 as a Europe based and vendor independent standard in widely accessible online certification of digital skills and competencies in many areas of professional digital specializations. The EITC framework is governed by the European IT Certification Institute (EITCI), a non-profit certification authority supporting information society growth and bridging the digital skills gap in the EU.
Eligibility for EITCA Academy 90% EITCI DSJC Subsidy support
90% of EITCA Academy fees subsidized in enrolment

    EITCA Academy Secretary Office

    European IT Certification Institute ASBL
    Brussels, Belgium, European Union

    EITC / EITCA Certification Framework Operator
    Governing European IT Certification Standard
    Access contact form or call +32 25887351

    Follow EITCI on X
    Visit EITCA Academy on Facebook
    Engage with EITCA Academy on LinkedIn
    Check out EITCI and EITCA videos on YouTube

    Funded by the European Union

    Funded by the European Regional Development Fund (ERDF) and the European Social Fund (ESF) in series of projects since 2007, currently governed by the European IT Certification Institute (EITCI) since 2008

    Information Security Policy | DSRRM and GDPR Policy | Data Protection Policy | Record of Processing Activities | HSE Policy | Anti-Corruption Policy | Modern Slavery Policy
    Select LanguageAfrikaansArabicBelarusianBengaliBosnianBulgarianCatalanChinese (Simplified)Chinese (Traditional)CroatianCzechDanishDutchEnglishEstonianFilipinoFinnishFrenchGeorgianGermanGreekHebrewHindiHungarianIndonesianItalianJapaneseJavaneseKoreanKurdishLatvianLithuanianMalayMongolianMyanmar (Burmese)NepaliNorwegianPashtoPersianPolishPortuguesePunjabiRomanianRussianSerbianSlovakSlovenianSpanishSwedishTamilTeluguThaiTurkishUkrainianUrduVietnamese
    function doGLTTranslate(lang_pair) {if(lang_pair.value)lang_pair=lang_pair.value;if(lang_pair=='')return;var lang=lang_pair.split('|')[1];if(typeof _gaq!='undefined'){_gaq.push(['_trackEvent', 'GTranslate', lang, location.hostname+location.pathname+location.search]);}else {if(typeof ga!='undefined')ga('send', 'event', 'GTranslate', lang, location.hostname+location.pathname+location.search);}var plang=location.hostname.split('.')[0];if(plang.length !=2 && plang.toLowerCase() != 'zh-cn' && plang.toLowerCase() != 'zh-tw' && plang != 'hmn' && plang != 'haw' && plang != 'ceb')plang='en';location.href=location.protocol+'//'+(lang == 'en' ? '' : lang+'.')+location.hostname.replace('www.', '').replace(RegExp('^' + plang + '[.]'), '')+glt_request_uri;}

    Automatically translate to your language

    Terms and Conditions | Privacy Policy
    EITCA Academy
    • EITCA Academy on social media
    EITCA Academy


    © 2008-2026  European IT Certification Institute
    Brussels, Belgium, European Union

    TOP

    We care about your privacy

    EITCI uses cookies and similar technologies to keep this site secure, remember your choices, provide personalized experience, measure the traffic, serve more relevant content and certification programmes. You can accept all cookies or customize your preferences. Cookies are variables used to store website specific information on your device to facilitate processing of data for personalized website visit, such as login to your account, accessing the programmes, placing enrolment orders in chosen programmes and improving your EITC certification journey. You can change or withdraw your consent at any time by clicking the Consent Preferences button at the left-bottom of your screen. We respect your choices and are committed to providing you with a transparent and secure browsing experience, which may be limited when cookies aren't accepted. For more details refer to the Privacy Policy
    Customize Consent Preferences
    We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.
    The cookies categorized as Necessary are stored on your browser as they are essential for enabling the basic functionalities of the site.
    To learn more about how Google processes personal information, visit: Google privacy policy

    Necessary

    Always Active

    Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

    Functional

    Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

    Preferences

    Stores personalization choices such as interface preferences.

    External media and social features

    Allows embedded video, social, chat, and external interactive services that may set their own cookies. Keep off until the user chooses these features.

    Analytics

    Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

    Marketing and conversions

    Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.

    CHAT WITH SUPPORT
    Do you have any questions?
    Attach files with the paperclip or paste screenshots into the message box (Ctrl+V). Max 5 file(s), 10 MB each.
    We will reply here and by email. Your conversation is tracked with a support token.