prEN 40000-1-2 §6 · STRIDE · MITRE EMB3D

Product threat modeling for connected devices

Zybercomply guides manufacturers of connected products and embedded devices through a complete, documented cybersecurity risk assessment — from scope and assets to treatment and monitoring — with an AI assistant drafting each step.

Following the prEN 40000-1-2 §6 workflow

The wizard walks through the clauses in order: context and scope, assets and their confidentiality, integrity and availability needs, risk acceptance criteria, threat identification, risk evaluation, treatment and ongoing monitoring. Each step records evidence so the final report shows coverage of every §6.x requirement.

Threats per asset with STRIDE

For every asset the assistant proposes Spoofing, Tampering, Repudiation, Information disclosure, Denial of service and Elevation of privilege threats, drawing on the MITRE EMB3D catalogue of device threats and mitigations. You accept, edit or reject each one.

CRA and RED (EN 18031) risk assessment

The EU Cyber Resilience Act requires manufacturers of products with digital elements to perform and document a cybersecurity risk assessment, and radio equipment must meet the RED delegated act requirements assessed with EN 18031. The resulting risk register, treatment decisions and coverage report form the evidence for that technical documentation.

What you get

  • A risk register with likelihood, impact and residual risk
  • Documented acceptance criteria and treatment decisions
  • A §6.x coverage report and monitoring log
  • Print-ready PDF and Markdown exports