Don't miss out on any news and changes relating to CE! Register now for the CE InfoService
Share Article
The Cyber Resilience Act (CRA) sets out binding cybersecurity requirements that manufacturers of products with digital elements must meet. These include, in particular, a cybersecurity risk assessment, appropriate risk-reduction measures, and the documentation of these measures.
However, the CRA provides only limited guidance on a practical question: How can such a risk assessment be carried out in concrete terms, and how can appropriate technical security measures be derived from it?
From the Legal “What” to the Technical “How”
This is precisely where BSI TR-03183-1, Cyber Resilience Requirements for Manufacturers and Products – Part 1: General Requirements, comes in – on two levels that are worth distinguishing.
First, it reproduces the essential cybersecurity requirements from Annex I of the CRA, allowing manufacturers to work with the Technical Guideline without having to refer to the Regulation in parallel. Second – and this is where its real added value lies – it provides an additional methodological interpretation, which is examined in more detail below.
The Technical Guideline is designed as a “living document” and is intended to provide manufacturers with practical guidance on implementing the CRA.
It is important to note that the Technical Guideline is not binding and does not establish a presumption of conformity with the CRA. Its added value therefore lies less in introducing new requirements than in making existing requirements more concrete: the BSI translates the CRA’s abstract requirements into methods, assessment criteria, process steps, and technical tools.
In this technical article, we have summarized the most important questions relating to the document.
What methodology does it provide for cybersecurity risk assessment?
The CRA requires manufacturers to assess cybersecurity risks but does not prescribe a detailed methodology for doing so.
TR-03183-1 describes a process based on ISO 31000, ranging from establishing the risk context and identifying assets and threats to risk analysis, risk treatment, and documentation.
In this context, the BSI distinguishes, among other things, between:
Confidentiality, integrity, and availability are assessed for these assets. The impact of a security incident can be rated on a scale from 1 – negligible – to 5 – very high. The Technical Guideline thus provides a concrete basis for a reproducible risk assessment that the CRA itself does not specify.
What are the criteria for assessing likelihood?
The CRA also does not prescribe a specific method for assessing the likelihood of a cyber incident. For this purpose, the BSI considers factors including:
This approach takes particular account of the intended operating environment. A product operating within a protected industrial network may therefore be assessed differently from a comparable product with a direct connection to external networks.
This is particularly relevant for machinery and plant manufacturers, as the cyber risk may depend heavily on the specific installation environment and intended use.
What are the criteria for acceptable risks?
The Technical Guideline also proposes criteria for determining when a risk can be accepted and when additional measures are required.
Factors considered include the potential severity of damage, the accessibility of the product, and the capabilities of its users.
However, the BSI makes clear that these criteria are only intended as a starting point. Manufacturers must adapt them to the specific product, industry, and application.
Adaptable Risk-based Controls: From Risk to Security Measures
A central element of the Technical Guideline is the concept of Adaptable Risk-based Controls (ARC). The basic idea is that security measures are not prescribed uniformly but selected on the basis of specific risk scenarios.
Factors considered include, for example:
This creates a direct link between risk analysis and technical security measures.
The Technical Guideline illustrates this using automatic updates as an example: depending on the product, network connection, and user group, the same measure may be assessed differently.
Architecture Model for Products with Digital Elements
The Technical Guideline also uses a generic architecture model to structure the scope of the product under assessment. Factors considered include:
For machinery incorporating control systems, HMIs, remote maintenance, cloud services, or apps, this can help manufacturers systematically determine which components and communication relationships must be included in the cybersecurity risk assessment.
Evaluator and Assessment Report
The Technical Guideline also describes a structured assessment procedure. A designated evaluator assesses the implementation of the requirements or controls. The evaluator may be an internal or external person. The BSI recommends appropriate expertise as well as an assessment that is as independent as possible.
Controls can, for example, be assessed as PASS, FAIL, or N/A. However, receiving a PASS for all applicable controls does not automatically demonstrate compliance with the CRA. Likewise, a FAIL does not necessarily constitute a violation of the CRA.
The results can be documented in a structured assessment report. This report may include, among other things, product identification, architecture, assets, threats, risks, security measures, and verification of those measures, and can therefore form part of the technical documentation.
Experimental Risk Scoring
Appendix D additionally contains an experimental scoring method. The so-called Environment Indicator takes particular account of interfaces, access restrictions, and user capabilities and is intended to make the assessment of likelihood more objective.
The BSI explicitly describes this approach as experimental. It is intended to be further developed on the basis of practical experience.
Practical Example: SNC X5 Network Camera
A complete example provided in the appendix is particularly illustrative. Using a fictional SNC X5 network camera, the Technical Guideline walks through the key steps of a cybersecurity risk assessment: from intended use and operating environment to assets and threats and, finally, the selection of specific security measures.
The example covers topics such as the protection of video and audio data, Wi-Fi access data, and user credentials, as well as measures such as HTTPS, encryption, and authentication. Naturally, this kind of practical walkthrough is not included in the CRA itself.
Security Measures in OSCAL Format
In addition, the BSI provides technical controls in OSCAL (Open Security Controls Assessment Language) format. This is intended to enable security measures to be systematically filtered, reused, and documented.
Looking ahead, this creates opportunities for more tool-supported CRA processes.
What does “state of the art” mean in the context of the CRA?
The CRA requires the “state of the art” to be taken into account in various contexts without prescribing specific technologies.
The Technical Guideline provides guidance on how to interpret this requirement: what matters is not necessarily the latest available technology, but rather the use of established methods and technologies that are appropriate for the specific use case.
For cryptography, for example, the BSI refers to relevant cryptographic recommendations such as BSI TR-02102.
Seminar tip
Designing safe machines - risk assessment in practice
In just one day, our seminar "Designing safe machines - risk assessment in practice" teaches technical designers and technical planners how risk assessments should be integrated as efficiently as possible into the development processes of machines or systems.
Register now
BSI TR-03183-1 is useful – but its practical value should not be overestimated.
For manufacturers establishing a systematic cybersecurity process for the first time, it provides a useful framework. In particular, its asset categories, assessment methods, risk criteria, and the link between risks and technical controls can make it easier to get started.
For experienced manufacturers, however, much of this is not fundamentally new. A large part of the Technical Guideline describes established risk management principles in a form tailored to the CRA: identifying assets, assessing threats, treating risks, documenting measures, and verifying their effectiveness.
Furthermore, the Technical Guideline does not relieve machinery and equipment manufacturers in particular of the need to make essential product-specific decisions. Industrial networks, remote maintenance, long product life cycles, control systems, HMIs, supplier components, and the interaction between functional safety and cybersecurity must still be assessed on a case-by-case basis.
The real added value therefore lies less in introducing new requirements than in operationalizing the CRA: the Technical Guideline demonstrates how abstract regulatory requirements can be translated into a structured and traceable assessment and documentation process.
For manufacturers new to systematic cybersecurity risk assessment, it can therefore serve as a valuable guide. Companies with established cybersecurity processes may instead use it primarily as a reference and checklist.
The Technical Guideline is therefore a guide, not a recipe – and certainly not a shortcut to CRA compliance.
Posted on: 2026-08-27
Trained technical editor (tekom-certified) and certified CE coordinator. Previously 11 years of experience in technical communication and as a CE coordinator in the field of mechanical and plant engineering, specialising in ‘Engineered to Order (ETO)’ products.
E-Mail: hendrik.stupin@ibf-solutions.com
We will inform you free of charge by e-mail about new technical articles, important standard publications or other news from the field of mechanical and electrical equipment safety or product compliance.
Register
CE software for systematic and professional safety engineering
Practical seminars on aspects of risk assessment and ce marking
With the CE InfoService you stay informed about important developments in the field of product safety.