First obligations from September 2026
Risk Analysis & Threat Modeling

The risk assessment the EU CRA requires — documented per product

STRIDE threat modeling, risk matrix, and results that flow directly into the technical documentation

Art. 13(2) of the EU Cyber Resilience Act requires manufacturers to carry out, document, and keep up to date a cybersecurity risk assessment for every product — it forms part of the technical documentation. Kunnus turns this into a guided process: STRIDE threat modeling in four steps, inherited threats from components, and a risk matrix whose results flow directly into assessment and documentation.

Art. 13(2)Legal basis
STRIDEMethodology
4 stepsGuided wizard
InheritedThreats from components
app.kunnus.tech/products/smartsensor-xr/threats

Threat Model — SmartSensor XR

STRIDE
Risk Matrix
HighMedLow
LowMediumHigh
Likelihood
Identified Threats
HighFirmware Update Channel
Control: Signed OTA updates
MediumLocal API Endpoint
Control: Authentication & TLS
LowConfiguration Storage
Control: Encrypted at rest

Key Benefits

STRIDE Wizard in Four Steps

Select a template, define assets, identify threats, conduct the review. The template library covers common scenarios.

Inherited Threats from Components

Threats from built-in components are automatically carried over into the product model — you assess once, not per variant.

Risk Matrix & Residual Risk

Likelihood and impact per threat, controls documented, and residual risk status tracked — at a glance.

Results Flow into the Documentation

The documented risk assessment forms part of the technical documentation under Art. 13(3) — no duplicate upkeep in separate documents.

Capabilities

Per-Product Cybersecurity Risk Assessment

Art. 13

Structured risk assessment for every product in the platform — documented, versioned, and kept up to date across the lifecycle.

STRIDE Threat Modeling

4-step wizard: select template, define assets, identify threats, conduct review. Inherited threats from components are automatically carried over.

Template Library

Pre-built threat model templates for common product scenarios — from connected sensor to gateway. Ready to use and adaptable.

Controls & Residual Risk Status

Annex I Part I

Controls are documented for every threat and residual risk status is tracked — the rationale for security by design under Annex I Part I No. 1.

Updates on Change

With new versions or substantial modifications, the risk assessment is carried forward — with a traceable history.

Use Cases

01

New Product before Market Placement

For a new IoT gateway, the STRIDE model is built from a template and threats from built-in components are carried over automatically. The documented assessment accompanies the technical documentation.

02

Catching Up an Existing Portfolio

A manufacturer assesses their existing portfolio product by product. Templates and inherited threats speed up the work — every assessment is individually documented.

03

Substantial Modification of a Product

A firmware update changes the attack surface. The risk assessment is carried forward on the new version, as Art. 13(3) requires — with a traceable history.

Structure your risk analysis

See how Kunnus guides risk assessment and threat modeling. We'll walk you through the workflow in a personalized demo.