Skip to main content

Clause 6.4 — Product cybersecurity risk assessment

Subclause 6.4 details requirements for identifying assets, threats, analyzing risks, and evaluating residual risk against acceptance criteria under FprEN 40000-1-2:2026.

Portal UI Path: CRA Portal → Products → [Select Product] → Assess → Risk assessment (Clause 6.4)

Related Procedures:

What Clause 6.4 requires

Clause 6.4 covers four distinct sub-activities:

1. Asset Identification (6.4.2)

  • [RMA-03-RQ-01]: Identify product cybersecurity assets and their properties (confidentiality, integrity, availability). Covers stored data, cryptographic keys, functions, hardware/software components, updates, and user health/safety.

2. Threat Identification (6.4.3)

  • [RMA-04-RQ-01]: Identify threats affecting assets, including targeted properties and threat causes. Incorporates threat modeling (STRIDE, PASTA, attack trees) and known vulnerabilities.

3. Risk Analysis (6.4.4)

  • [RMA-05-RQ-01]: Estimate likelihood of occurrence for each threat.
  • [RMA-05-RQ-02]: Estimate impact severity for each threat from the user perspective.
  • [RMA-05-RQ-03]: Document specific risk scenarios.

4. Risk Evaluation and Acceptance (6.4.5)

  • [RMA-06-RQ-01]: Compare each risk against pre-established acceptance criteria.
  • [RMA-06-RQ-02]: Accept risks only when they meet acceptance criteria.
  • [RMA-06-RQ-03]: Ensure user-mitigated risks are within expected user knowledge/ability.
  • [RMA-06-RQ-04]: Document justification for all accepted residual risks.

How CVD Portal supports compliance

CVD Portal streamlines the complete risk assessment workflow:

STRIDE Threat Model in CVD Portal

Risk Assessment Form

  • Integrated asset and SBOM registry: Software assets map directly to uploaded SBOM components, while supporting assets (cryptographic keys, updates) are tracked in the workspace.
  • CVSS v3.1 / v4.0 calculator: Built-in CVSS scoring standardizes impact and likelihood estimations for reported vulnerabilities.
  • Threat intelligence correlation: Automated feeds cross-reference components against EUVD, GCVE, and CISA KEV to identify active threats automatically.
  • Residual risk justification workflow: When accepting a risk, the dashboard prompts you to record formal justifications and verify user capability before marking the item compliant.