Zealience logo
Cyber Resilience Act compliance
Z-CMS Feature

CRA Risk Assessment, Automated.
Every Asset, Threat and Treatment Covered.

Risk assessment required by 11 December 2027

The risk assessment is the first step of Cyber Resilience Act compliance — it decides which essential requirements apply to your product. Z-CMS walks you through it with a guided Q&A: declare your assets, get the relevant threats, score them against your own criteria and record your treatments, in line with prEN 40000-1-2 and EN IEC 62443-4-1.

prEN 40000-1-2 EN IEC 62443-4-1 MITRE EMB3D
Watch the workflow

Where CRA compliance starts

What a CRA risk assessment has to cover

The Cyber Resilience Act is risk-based: how far the essential requirements in Annex I apply to your product depends on what your risk assessment says. EN 40000-1-2, the horizontal standard currently published as the draft prEN 40000-1-2, sets out the framework: what a risk assessment must cover. EN IEC 62443-4-1 follows the same framework, with slightly different terminology. Neither tells you step by step how to carry it out — that part is left to you. Here is what both ask for.

Product context

Describe the product, its intended use, its operating environment and its interfaces — the scope everything else is assessed against.

Risk acceptance criteria

Define how you rate risk and where your acceptance threshold sits, before you start scoring anything.

Asset identification

Identify everything in the product worth protecting. Threats are identified per asset, so an incomplete asset list means an incomplete assessment.

Threat identification

For each asset, identify the threats that apply to it. EN 40000-1-2 points to MITRE EMB3D as a source catalogue.

Risk scoring and treatment

Rate each threat on likelihood and impact and compare it against your threshold. Every risk above it needs a treatment and a justification; accepted risks need a justification too.

Applicable requirements

Based on the risks you identified, determine which CRA essential requirements — and which requirements of standards such as prEN 40000-1-4 — you need to implement to address them.

Z-CMS covers all six.

Its methodology is tailored to prEN 40000-1-2 and EN IEC 62443-4-1, and it guides you through every requirement to collect the information the standard asks for — mostly through intelligent Q&A, so you answer questions about your product instead of filling in templates.

The workflow

From assets to treated risks

Six steps, in the order the standards ask for them. The guided Q&A does the heavy lifting on the two steps manufacturers find hardest: working out what the assets are, and working out which threats apply to each one.

  1. Start from the configurable 5×5 matrix and calibrate the ratings to your product. This is the step EN 40000-1-2 and EN IEC 62443-4-1 require before any risk is scored.

Threat modelling, built in

Threat modelling, without the whiteboard

Threat modelling means working out what an attacker could target, how, and which threats matter most — before anyone exploits them. It is usually treated as a specialist exercise. In Z-CMS it is part of the risk assessment: your engineers answer questions about the product they built, and Z-CMS does the modelling.

The traditional way

Workshops and whiteboards

  • A security specialist, in-house or external, has to lead the exercise
  • Architecture, attack paths and threats are drawn by hand
  • Coverage depends on who happens to be in the room
  • Hard to repeat for every product and every release

Built into Z-CMS

Just fill in questionnaires

  • Your engineers do it — nobody knows the product better
  • They fill in questionnaires: no diagrams, no security background needed
  • Every asset is checked against 120+ built-in threats
  • Threats land straight in the risk register, ready to rate

Comprehensive, repeatable, reproducible

Comprehensive

Every asset and every threat is properly documented, and each asset is checked against the full catalogue of 120+ threats — nothing depends on what someone happens to remember.

Repeatable

The same guided process for every product and every release, so the next assessment is as thorough as the first.

Reproducible

Same answers, same threats — whoever runs the assessment. Results you can explain to an auditor.

Every threat modelling activity, done systematically

  1. 1

    Identify what to protect

    Assets picked from the same curated list, every time

  2. 2

    Identify threats

    Every asset checked systematically against 120+ threats

  3. 3

    Analyse

    Likelihood and impact rated against your defined criteria

  4. 4

    Prioritise

    Your threshold decides what needs treatment — consistently

120+

built-in threats checked against every asset

EMB3D

MITRE EMB3D plus proprietary Zealience threats

0

architecture diagrams to draw

Risk assessment has traditionally been work for cybersecurity experts. That doesn't scale under the CRA, where every product with digital elements needs one, kept up to date for its whole support period. That's why we built Z-CMS: to equip the engineers who build your products to carry out the risk assessment themselves.

Common questions

CRA risk assessment FAQ

Ready to start your
CRA risk assessment?

See the full workflow on your own product — acceptance criteria, asset Q&A, threat identification from MITRE EMB3D, risk register and treatments — in a personalised demo. Or explore our pricing.

View Pricing

Trusted by manufacturers worldwide

prEN 40000-1-2 & EN IEC 62443-4-1
Free Customer Support
On-Premises Security