> ## Content Index
> Fetch the complete content index at: https://www.smallstepsystems.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# A Pragmatic Approach to CRA Risk Assessment
- URL: https://www.smallstepsystems.com/a-pragmatic-approach-to-cra-risk-assessment/
- Published: 2026-09-28T11:36:34.000Z
- Updated: 2026-09-28T11:57:22.000Z
- Description: In less than 30 minutes, I can explain a pragmatic approach how to model the threats of an embedded system, assess the cybersecurity risks and document the risks in security decision records (SDRs). Here is the video from my talk at the Torizon CRA Summit in Munich.
- Author: Burkhard Stubert
- Tags: Cyber Resilience Act, risk assessment, embedded systems, Torizon, threat modeling

![](https://storage.ghost.io/c/c7/ee/c7ee1cf5-b86f-491b-aab7-20ad081598e1/content/images/2026/09/stubert-goal-of-risk-assessment.png)

Manufacturers must reduce the cybersecurity risk of their products violating any of the 13 essential product properties [from Annex I.I.2a-m](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R2847&ref=smallstepsystems.com#anx%5FI) (the red labels in the diagram above) to an acceptable level or eliminate the risk completely. They must keep the risk assessment up-to-date during the whole product life cycle - also known as *security by design* ([Annex I.I.1](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R2847&ref=smallstepsystems.com#anx%5FI)).

In the risk assessment, manufacturers first describe which product properties are currently violated by security-relevant usage scenarios or threat scenarios. Then, they specify security measures that reduce the violations to an acceptable level. The risk assessment is a gap analysis between the current and target cybersecurity state. It is also a plan which security measures must be implemented to move from the current to the target state.

The risk assessment is not just a documentation exercise. Manufacturers must be able to demonstrate to the market surveillance authorities that they really implemented the security measures in their products. The best evidence are tests, tests and tests. Execution logs, screenshots of short videos are also valid evidence.

In less than 30 minutes, I can explain a systematic and pragmatic approach 

- how to [model the threats](https://shostack.org/resources/threat-modeling?ref=smallstepsystems.com) of an embedded system,
- how to assess the cybersecurity risks for the threat scenarios and
- how to document everything in [security decision records](https://www.smallstepsystems.com/risk-assessment-of-essential-product-da3/).

This is the same approach I teach [in my CRA trainings](https://www.microconsult.de/trainings-beratung/training/der-cyber-resilience-act-cra-praktisch-erklaert-fuer-die-embedded-entwicklung/AAAAHVS/?ref=smallstepsystems.com) and [in my CRA Survival Bootcamps](https://www.smallstepsystems.com/cra-survival-bootcamp-for-your-embedded-system/). After this introduction, the trainees write their first 3-5 security decision records (SDRs) within a day - with less and less guidance from me. The SDRs are by far the largest and most important part of the technical documentation ([Annex VII](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R2847&ref=smallstepsystems.com#anx%5FVII)). Moreover, the SDRs guide the manufacturer through the implementation of the identified security measures.

[Risk Assessment of Product PropertiesPresentation slides in PDF formatstubert-torizon-cra-summit-munich.pdf2 MBdownload-circle](https://www.smallstepsystems.com/content/files/2026/09/stubert-torizon-cra-summit-munich.pdf "Download")