The risk assessment the EU CRA requires — documented per product
STRIDE threat modeling, risk matrix, and results that flow directly into the technical documentation
Art. 13(2) of the EU Cyber Resilience Act requires manufacturers to carry out, document, and keep up to date a cybersecurity risk assessment for every product — it forms part of the technical documentation. Kunnus turns this into a guided process: STRIDE threat modeling in four steps, inherited threats from components, and a risk matrix whose results flow directly into assessment and documentation.
Threat Model — SmartSensor XR
STRIDEKey Benefits
STRIDE Wizard in Four Steps
Select a template, define assets, identify threats, conduct the review. The template library covers common scenarios.
Inherited Threats from Components
Threats from built-in components are automatically carried over into the product model — you assess once, not per variant.
Risk Matrix & Residual Risk
Likelihood and impact per threat, controls documented, and residual risk status tracked — at a glance.
Results Flow into the Documentation
The documented risk assessment forms part of the technical documentation under Art. 13(3) — no duplicate upkeep in separate documents.
Capabilities
Per-Product Cybersecurity Risk Assessment
Art. 13Structured risk assessment for every product in the platform — documented, versioned, and kept up to date across the lifecycle.
STRIDE Threat Modeling
4-step wizard: select template, define assets, identify threats, conduct review. Inherited threats from components are automatically carried over.
Template Library
Pre-built threat model templates for common product scenarios — from connected sensor to gateway. Ready to use and adaptable.
Controls & Residual Risk Status
Annex I Part IControls are documented for every threat and residual risk status is tracked — the rationale for security by design under Annex I Part I No. 1.
Updates on Change
With new versions or substantial modifications, the risk assessment is carried forward — with a traceable history.
Use Cases
New Product before Market Placement
For a new IoT gateway, the STRIDE model is built from a template and threats from built-in components are carried over automatically. The documented assessment accompanies the technical documentation.
Catching Up an Existing Portfolio
A manufacturer assesses their existing portfolio product by product. Templates and inherited threats speed up the work — every assessment is individually documented.
Substantial Modification of a Product
A firmware update changes the attack surface. The risk assessment is carried forward on the new version, as Art. 13(3) requires — with a traceable history.
Related Features
Structure your risk analysis
See how Kunnus guides risk assessment and threat modeling. We'll walk you through the workflow in a personalized demo.