A secure development lifecycle is a useful implementation framework. The CRA requires risk assessment to inform decisions throughout planning, design, development, production, delivery and maintenance; it does not prescribe this page’s exact workflow.

Frame the system
Define product functions, trust boundaries, dependencies and foreseeable use. Record assumptions and security risks before choosing controls.
- Product and component inventory
- Threat and risk assumptions
- Security requirements tied to design decisions
Build and verify
Review architectures and components, configure secure defaults, test relevant security properties and track findings to remediation. Keep traceable evidence for product versions.
Maintain in use
Plan security updates, support communications, vulnerability intake and post-release review. Feed newly discovered issues back into the risk assessment.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.