Classic risk treatment offers four options: avoid, mitigate, transfer, accept. In the world of industrial plants, "accept" is a legitimate and frequently used option — documented, justified and owned by the person responsible.
For products that fall under the Cyber Resilience Act, this logic shifts. Not because acceptance is forbidden, but because the question of what you are allowed to decide about shifts.
What the CRA Actually Requires
Two statements are central to risk treatment.
The risk assessment is mandatory — and it is not a document, it is an input. The manufacturer must carry out a cybersecurity risk assessment, and that assessment must feed into the implementation of the essential requirements: across planning, design, development, production, delivery and maintenance.
The requirements must be traceable to the assessment. The essential requirements of Annex I are to be tied to the results of the risk assessment. Security features should be the direct answer to identified risks — not a ticked-off list. Conversely: whoever chooses the approach that, in their view, best mitigates the risks may do so, as long as the choice is justified in the risk assessment.
Annex I itself consists of two parts: Part I describes properties the product must have; Part II describes the vulnerability handling processes the manufacturer must operate.
The Decisive Difference
This leads to a separation that is often overlooked in practice:
What you may decide: how you meet an essential requirement. Which mechanism, what depth, what compensation — that is an engineering question, and the answer follows from your risk assessment. There is latitude here, and that latitude is explicitly intended.
What you may not decide: whether the essential requirements apply. They are a prerequisite for market access, not the outcome of a trade-off. "Accepting" a risk that falls within the scope of an Annex I requirement is not a risk decision — it is an open conformity deficiency.
Transferring the risk does not hold up either. Insurance or a contractual assignment to the customer changes the financial consequence of damage, but not the obligation attached to the product.
What This Means for Documentation
If every decision must be traceable to the risk assessment, the assessment itself becomes the load-bearing document of conformity. In practice this means:
Every requirement needs a trail. For each item in Annex I it should be traceable which identified risk it addresses and which concrete activity fulfils it. A tick mark without an activity behind it is exactly the gap that stands out in an audit.
Justifications belong in the analysis, not in an email. "Back then we decided against it because…" cannot be found two years later. The justification belongs with the risk it relates to.
Residual risk must be named, not concealed. That a residual risk remains after all measures is normal and to be expected. It becomes a problem when it is written down nowhere — in hindsight it then looks not like a decision, but like an omission.
The Timeline
Two dates structure the transition:
- 11 September 2026 — the reporting obligations apply: actively exploited vulnerabilities and severe incidents must be reported to ENISA and the competent national CSIRT. This also applies to products already on the market, with no transition period.
- 11 December 2027 — the remaining obligations apply in full: essential requirements of Annex I, conformity assessment, technical documentation, EU declaration of conformity, CE marking.
For risk treatment, the second date is the relevant one. By then, the chain from assessment through measure to evidence must be in place — not as a declaration of intent, but as a document someone can audit.
The Sober Summary
The CRA does not enforce a new methodology. It enforces that the existing one is carried through all the way to evidence. "Accepted" remains a valid outcome of risk treatment — but only where no essential requirement is affected, and only if the decision is documented with a justification.
This article is a technical assessment and not legal advice. For the binding interpretation in an individual case, please refer to the legal text and seek legal counsel.
Sources
- Cyber Resilience Act — Summary of the legislation (European Commission)
- CRA Annexes I–VIII — Essential Requirements & Product Lists
This article was originally published in German on the Alsensio Cybersecurity Hub.
