There is a real argument against handing anyone a pre-filled risk assessment. Article 13(2) puts the assessment on the manufacturer, and Article 13(3) makes it the manufacturer's own determination, documented and kept current across the support period. It decides which Annex I Part I(2) requirements apply and which get justified away. Pre-fill it and you have supplied a way to skip the only step that carries legal weight.
That argument identifies a real risk. It then treats the empty document as neutral, and this is where the reasoning breaks. Both starting points carry a bias. One of them shows it to you.
What the blank page selects for
Ask a team that has never done this to list the threats to its product. The list arrives fast, and it holds the threats that team already discusses, drawn from incidents they lived through, components they personally own, and attack classes that were recently in the press. It is recall presented as analysis.
The gaps in that list are predictable, because the omissions are structural.
| Reliably omitted | Why it goes missing | Where the CRA still asks |
|---|---|---|
| The interface between device and vendor cloud | It belongs to two teams, so it is assessed by neither | Annex I Part I(2) |
| Credentials and data at decommissioning | Nobody is measured on the resale or scrapping stage | Annex I Part I(2) |
| Availability failure at population scale | A team that thinks per-device misses the fleet reconnect | Annex I Part I(2) |
| The supplier component with a known unpatchable weakness | Writing it down looks like inviting work, so it gets silently reassigned | Annex I Part II |
These gaps trace back to an assessment whose scope was set by who happened to be in the room. The blank page ratifies that scope, and it yields a document that reads as complete because every line in it is one somebody thought of.
Archetypes share more attack surface than teams expect
A starting draft can help because the attack surface of a product follows from what kind of product it is. Ownership matters far less than shape.
Two industrial controllers from unrelated vendors carry close to the same asset inventory. Firmware with a boot chain. An engineering path that can download logic. A fieldbus carrying commands to drives. A control program whose integrity determines physical behaviour. A safe state that has to hold when the network drops. Implementations differ enormously. The list of things worth attacking stays almost constant.
The same holds elsewhere. On a smart home hub the governing question is always whether an unlock command authenticates to a person or to a position on the network. On a smart meter gateway it is key material in the security module and the aggregate effect of a fleet-wide command. On a mobile robot it is the teleoperation link and the behaviour on link loss. Archetype content enumerates the questions a product of that shape has to answer, including the handful a first-time team reliably skips.
A starter holds claims to dispose of
Take tampering with data in transit on a local pairing radio, applied to a smart home hub. Nobody outside your team knows your radio, your pairing flow or your replay protection, so the row settles nothing on its own. Its value is that it now has to be disposed of, and there are only three defensible endings.
It applies outcome 1
Name the control that addresses it. That produces the implementation reference the technical documentation needs anyway.
It does not apply outcome 2
Record why. That produces precisely the justification Annex I Part I(2) requires for a requirement you are treating as inapplicable.
Nobody knows outcome 3
The most valuable of the three. An unknown surfaced during assessment costs a conversation. The same unknown surfaced after placing on the market costs an Article 14 notification.
Every ending advances the file. A blank page supplies a fourth, where the question goes unasked, never appears, and leaves nothing behind to mark its absence.
The same holds for shipping default likelihood and impact values in a starter. The defaults will be wrong for your deployment, and that is the point. A wrong number invites an argument while an empty cell invites agreement. A team that sees an interface it knows is unreachable rated medium will correct the rating. The same team scrolls past an unscored row.
The property that makes it safe
All of it collapses if seeded content can be inherited without a decision. A starter that quietly counts toward your compliance posture does real damage, because it converts an unexamined assumption into apparent evidence. So the rule is that nothing a template supplies may count until a person has confirmed it.
Seeded assets arrive unconfirmed and sit outside the coverage measurement until someone ticks them. A proposed classification is stored as a suggestion carrying no decision timestamp, so the gate governing placing on the market still requires a human to read Annex III and Annex IV and commit. Risk criteria are visibly defaults, present so scoring has documented scales from day one, with the scales fixed before the scores.
Classification earns the most caution, because it is the one field where an inherited wrong answer becomes expensive. Article 32 ties the route to the class. Default class may self-assess. Annex III Class II needs a notified body. Annex IV critical needs a certification scheme or an equivalent route. Inherit a class without checking it and a team can spend months on the wrong conformity path, discovering the error exactly when correcting it costs most.
There is a fair objection. Unconfirmed content still anchors, and a team starting from ten threats may stop at ten. That is true. It is why a starter has to announce itself as an archetype, and why the prompts asking what is missing carry more weight than the rows already filled. The claim worth defending is modest: a draft trades an invisible bias for a visible one, and a visible one can be argued with.
What actually changes
The assessment stays yours. Article 13(3) does not move, and the determination of which Annex I Part I(2) requirements apply remains yours to make and defend.
What changes is the first hour. The team spends it disagreeing with a list that already contains the decommissioning path, the interface nobody owns, and the failure that only appears at fleet scale. The output is a shorter list of open questions and a longer list of decisions with reasons attached, and the second list is what the technical documentation under Annex VII has to carry.
Regulation references are to Regulation (EU) 2024/2847. A longer treatment aimed at compliance teams, together with archetype starters for ten common product types, is on the CVD Portal blog as What an empty risk assessment leaves out. This article is informational and does not constitute legal advice.