Topic
Cybersecurity risk assessment
The document Annex I keeps pointing back to.
The risk assessment is the load-bearing document of Article 13: it is drawn up around the product's risks, drives which Annex I Part I properties apply and how F-017, and lands in the technical documentation that is prepared before placing on the market and kept for at least ten years F-016.
What it actually does
Annex I's product properties are written as outcomes conditioned on risk — secure by design and default as the frame, the risk assessment as the reasoning that connects the frame to your product F-017. The technical documentation contract in Annex VII then expects that reasoning to be inspectable F-022.
The failure mode
Writing the assessment after the architecture is frozen. Done late it becomes a justification document; done early it is the cheapest security-design tool the Regulation hands you F-017.
Verified facts this page relies on
- F-016 Technical documentation (Annex VII) is drawn up before placing on the market and kept, with the EU declaration of conformity, for at least ten years after placing on the market or the support period, whichever is longer. Art. 13(12)–(13), Art. 31
- F-017 Annex I Part I — product properties (secure by design and default; see checklist items I.1–I.3m). Annex I Part I
- F-022 Technical documentation contents (Annex VII). Annex VII, Art. 31
Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).
Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.
Related in the reference
- Article 13 — Obligations of manufacturers
- Annex I — Essential cybersecurity requirements
- Topic: Technical documentation