cra

Art. 13(2)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (3)

Techniques referencing this article

  • EX-0005.01Design FlawsST0004
    addresses
    moderate
    derived

    Manufacturer cybersecurity-risk assessment obligations cover identification of design-flaw classes and their exploitation potential; the assessment is the upstream input to design-flaw remediation prioritisation.

  • EXF-0008Compromised Developer SiteST0008
    addresses
    high
    direct

    Compromise during planning/design/development/production is exactly the lifecycle phase (13)(2)'s risk-assessment obligation requires the manufacturer to consider — including the development environment as part of the cybersecurity risk surface.

  • LM-0006.01Rideshare PayloadST0007
    addresses
    moderate
    direct

    Rideshare deployment is part of the 'reasonably foreseeable use' and 'conditions of use' the manufacturer must consider in the cybersecurity risk assessment under 13(2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.