{"id":"94edcc20-a746-40e8-aeb0-ca19a68272ae","arxiv_id":"2508.21386","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"The EU's five core cyber security acts converge on a probabilistic, asset- and system-centric risk concept, but leave acceptable, residual, and non-probabilistic risks unaddressed.","lead":"The paper maps how five EU cyber security laws frame the concept of risk, finding broad convergence on a probabilistic, risk-based approach. It identifies gaps in how the laws treat acceptable, residual, and non-probabilistic risks.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Selective sample cannot support the gap claims: absence of acceptable/residual/non-probabilistic risk in all five acts needs a full-text check","rationale":"The reader's weakest_assumption identifies the same load-bearing concern: the negative claims about unacceptable/residual/non-probabilistic risks are not supported by a selective reading. The paper explicitly discloses the selection (Section 3, first paragraph) and excludes contextual interpretation (Section 2.2), yet the abstract and conclusion state the gaps as established results. A full-text keyword search is a concrete and feasible check: if the terms appear in unanalyzed provisions, the gaps are artifacts of sampling; if not, the negative claims are strengthened. Since this concern matches the reader's, and the positive contributions remain valuable, the CONDITIONAL verdict is appropriate; no adjustment is needed.","tokens_in":19649,"tokens_out":5986,"duration_ms":53760,"concrete_test":"Run a full-text keyword search over the official EUR-Lex texts of the five acts (Reg (EU) 2019/881; Reg (EU) 2016/679; Reg (EU) 2024/2847; Dir (EU) 2022/2557; Dir (EU) 2022/2555) for the stems/terms: 'residual risk', 'risk acceptance', 'acceptable risk', 'acceptable level of risk', 'tolerab* risk', 'risk appetite', 'remaining risk', 'unacceptable risk', 'non-probabilistic', 'imprecise probabilit*', 'likelihood', 'probability'. For each hit, compare against the provisions analyzed in Section 3; any hit in an unanalyzed article/recital that acknowledges acceptable or residual risk, or a non-probabilistic concept, falsifies the gap claim. If no such hit exists, the negative findings survive this test.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The paper's headline claim is convergence on a probabilistic, asset/system-centric risk concept with notable gaps (acceptable, residual, non-probabilistic risks). The positive mappings are grounded in quoted provisions, but the gap claims in Table 2 (P=0 for Dimension 3b and 4a) and in Section 4.1 ('none of the laws mention or otherwise discuss explicitly') rest on a deliberately selective sample. Section 3 states: 'only considering notable risk-based aspects... not everything about the laws is covered'; Section 2.2 excludes contextual interpretation and case law. Thus, the absence is not established. For example, the CRA analysis covers Articles 3, 13–20, 54, 56 but not the Annexes or all delegated powers; the GDPR analysis covers Articles 25, 32–36, not all risk-relevant provisions. A provision in an unanalyzed article or recital could mention 'acceptable level of risk', 'residual risk', or 'remaining risk', which would directly contradict the gap claim. The paper's own footnote 3 lists further excluded risk-based details. The negative claims are load-bearing because they appear in the abstract and conclusion as the paper's main novel finding.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper interprets the risk concepts in five EU cyber security legislative acts (CSA, GDPR, CRA, CER, NIS2) using a six-dimensional taxonomy derived from risk-management literature. It reports that the acts converge on a probabilistic, asset/system-centric framing of risk, cover technical, organizational, human, and national security to varying degrees, and contain two notable gaps: acceptable/residual risks and non-probabilistic risks. It also analyzes qualifying words that tighten or relax legal obligations and concludes with practical compliance recommendations. The main evidence is a qualitative reading of selected articles, summarized in Table 2.","tokens_in":19907,"tokens_out":8846,"duration_ms":96403,"significance":"If the results are correct, the paper provides a useful mapping for requirements and compliance engineering and contributes to the literature on risk-based regulation in the EU. Its positive classifications are often grounded in quoted provisions, and the authors are transparent about the qualitative, selective nature of the analysis. However, the paper's most novel negative findings — the absence of acceptable/residual risks and of non-probabilistic risks — are not supported by the corpus actually analyzed. This is a correctable but currently load-bearing weakness.","major_comments":[{"comment":"The negative claims in Table 2 (Dimensions 3b and 4a) and Section 4.1 ('none of the laws mention or otherwise discuss explicitly'; 'All laws rely on the conventional probabilistic understanding') assert absence across entire legal instruments. However, the analysis is explicitly selective: Section 3 states that only 'notable risk-based aspects' are considered and 'not everything about the laws is covered'; Section 2.2 excludes contextual interpretation and case law; footnote 3 lists further excluded risk-based details. Because no full-text search for 'acceptable risk', 'residual risk', 'remaining risk', or 'non-probabilistic risk' equivalents is reported, the P=0 entries may be artifacts of the selection. This is load-bearing because the abstract and conclusion present these gaps as the main novel finding. The authors should either perform a systematic corpus check (at least for English","section":"Section 3 / Table 2 / Section 4.1"},{"comment":"The convergence result is partly an artifact of the coding design. The six taxonomy dimensions are imported from the risk-management literature, the categories are coarse, and each law is allowed to map to multiple categories in dimensions (1), (5), and (6). The check-mark table therefore summarizes the authors' classifications, but the table alone does not let a reader verify each cell. I recommend a supplementary table with representative quotations per cell, or an explicit caveat that the convergence claim is descriptive of the authors' interpretive mapping rather than an independent property of the legal texts. This would align the strength of the claim with the evidence.","section":"Section 2.2.3 / Table 2"}],"minor_comments":[{"comment":"Typo: 'ENISA will nothing other national authoritative CSIRTs' should read 'ENISA will notify other national authoritative CSIRTs'.","section":"Section 3.3.3"},{"comment":"Reference [71] gives the year as '201'; this should be '2021'.","section":"References"},{"comment":"The figure contains the misspelling 'inreases'; it should be 'increases'.","section":"Figure 1"},{"comment":"Article 13(1) CER explicitly requires 'technical, security and organisational measures', yet Table 2 does not mark CER under 'Technical security' (5a). If the coding criterion is the presence of concrete technical requirements rather than the mere mention of technical measures, this should be stated in Section 2.2.1 and applied consistently; otherwise the table conflicts with the text.","section":"Section 3.4.2 / Table 2"},{"comment":"Minor grammar issue: 'the NIS2 directive have already involved' should be 'the NIS2 directive has already involved'.","section":"Section 3.5.1"}],"recommendation":"major_revision","confidential_remarks":"I recommend major revision rather than rejection because the positive mapping is useful and the central weakness is fixable. The authors should either verify the negative gap claims with a systematic full-text search or clearly restrict the claims to the analyzed provisions. The abstract and conclusion currently overstate the certainty of the absence findings."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Colleague,\n\nThe paper earns its keep with Table 2. Nobody has put the CSA, GDPR, CRA, CER, and NIS2 on the same six risk dimensions before, and the mappings are grounded in quoted articles rather than vibes. The authors are also upfront about method: they follow an existing taxonomy-building guideline, exclude contextual interpretation and case law, and tell you they only selected \"notable risk-based aspects.\" For a requirements engineer trying to figure out where the laws overlap, this is genuinely useful. The positive claims—probabilistic, asset- and system-centric framing in most acts, with CER as the outlier on non-man-made risks—are plausible and supported by the provisions they cite.\n\nThe soft spot is exactly the one the stress test names. The negative claims (acceptable risks, residual risks, non-probabilistic risks absent from all five acts) sit in the abstract and conclusion, but they rest on a selective sample. Section 3 says plainly that not everything in the laws is covered, and Section 2.2 excludes contextual interpretation and case law. Absence claims of that strength need either a full-text sweep of the articles and recitals or a narrower formulation like \"in the notable risk-based provisions we examined.\" The paper's own footnote 3 lists risk-based details left out, so the reader cannot verify that an unanalyzed recital doesn't mention \"remaining risk\" or an acceptable threshold. This is a load-bearing flaw in presentation, not in the whole enterprise; the taxonomy would survive a more careful wording.\n\nOne more minor wobble: the operational definition of non-probabilistic as \"antonym\" of finding the probability formula is thin. It makes the non-probabilistic gap claim look more crisp than the underlying legal semantics.\n\nWho's it for: people doing compliance engineering, requirement elicitation, or mapping EU cyber law. It's a qualitative legal interpretation, so don't expect formal verification or data. The citation pattern is fine, including self-citations to the earlier CRA/GDPR mapping.\n\nMy call: send it to peer review. The taxonomy deserves referee time. Ask the authors to either demonstrate coverage or soften the gap claims. Either way the paper is worth engaging with.","headline":"Useful map of how five EU cyber laws frame risk; trust the positive taxonomy, treat the absence claims as hypotheses until a full-text check.","tokens_in":20380,"tokens_out":2274,"would_cite":true,"duration_ms":25074,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"Across the CSA, GDPR, CRA, CER, and NIS2, the EU's core cyber security laws all frame risk as probability times impact and cover technical, organizational, human, and national security — but none acknowledges acceptable, residual, or non-pr","keywords":["EU cyber security legislation","risk-based regulation","cyber risk framing","legal taxonomy","compliance","NIS2","Cyber Resilience Act","GDPR"],"falsifier":"Search the full text of the five acts and their recitals for 'residual risk', 'acceptable risk', 'risk tolerance', 'risk appetite', or equivalent formulations in EU languages; a single provision instructing that a risk analysis document what risk remains after mitigation, or setting a tolerable risk threshold, falsifies the claimed gap. Separately, the all-probabilistic claim falls if any act defines or uses risk without reference to likelihood — for instance, a threshold- or impact-only definition such as the CER's 'significant disruptive effect' criteria applied without probability, or a saf","tokens_in":19537,"feed_emoji":"⚖️","tokens_out":10606,"duration_ms":92659,"temperature":0.7,"pith_summary":"Five EU cyber security laws are supposed to be risk-based, but how exactly do they define risk? The paper claims that the CSA, GDPR, CRA, CER, and NIS2 all frame risk through the same conventional formula — probability of occurrence times impact — and that together they cover technical, organizational, human, and national security concerns thoroughly. The paper's central finding is a shared blind spot: none of the five acts acknowledges acceptable risks, residual risks (what remains after countermeasures), or non-probabilistic risk concepts. If correct, this means compliance officers can rely on probability/impact risk matrices as a common substrate across all five laws, but they will find no legal guidance on when residual risk is tolerable, and the regime's risk concept has no way to express safety-style threshold risks. The paper supports these claims with a six-dimension taxonomy built by qualitative legal interpretation of selected provisions.","feed_headline":"Five EU cyber laws share one risk model — and three blind spots","feed_subtitle":"All five regulate risk as probability times impact, but none says what to do with risk that remains after controls.","key_machinery":"The paper's carrying object is a six-dimension taxonomy of risk framings, built from the conventional risk-analysis vocabulary: the formula 'risk = probability of occurrence of a threat × impact of a threat', and the paired definitions of acceptable risk (a risk understood and tolerated by a system's user, operator, owner, or accreditor) and residual risk (the portion of an original risk that remains after countermeasures have been applied). The taxonomy's six dimensions — viewpoint, man-made versus other origins, probabilistic versus non-probabilistic, acceptable/residual recognition, security concept, and development versus operations — do the analytical work: each act is mapped onto the c","core_discovery":"On the paper's own terms, the central claim is that the EU's five core cyber security acts form a convergent, risk-based regulatory regime with specific missing pieces. Interpreting each act against six taxonomy dimensions — risk viewpoint (threat-, asset-, or system-centric), man-made versus other risks, probabilistic versus non-probabilistic framing, recognition of acceptable/residual risks, security concept (technical, organizational, human, national), and development versus operations — the paper finds that all five laws share the conventional probabilistic understanding of risk, that their coverage spans all four security concepts, and that three risk notions are absent everywhere: acce","pith_inferences":["A full-text, corpus-level search of the five acts and their recitals for residual-risk and acceptable-risk vocabulary (including equivalents in other EU languages) would test whether the paper's qualitative absence findings hold at scale; its method deliberately reads only 'notable' provisions, so a systematic scan could either confirm the gaps or reveal mentions the selection missed.","If the gaps are real, a small regulatory fix suggests itself: an implementing or delegated act under the CRA or NIS2 could require documenting residual risk after applying the essential security requirements, filling the gap without new primary legislation.","The paper's reading of the CSA's attacker-skill tiers as an implicit residual-risk scale suggests a bridge between certification assurance levels and the CRA's essential requirements that the paper does not itself build: an assurance level could serve as a rough measure of how much residual risk remains for a certified product.","Applying the same six-dimension taxonomy to neighbouring acts (DORA, the Digital Services Act, the AI Act), which the paper names only as overlaps, would show whether the convergent probabilistic risk concept extends beyond the five core acts into sectoral and technology-specific legislation."],"forward_implications":["Probability/impact risk matrices are a defensible common method across all five acts, since each law operates with the same probabilistic risk formula.","Organizations covered by several acts (e.g., a networked product processing personal data for a critical-sector customer) can legally consolidate overlapping obligations into a single risk analysis spanning the GDPR, CRA, CER, and NIS2.","Because no act recognizes acceptable or residual risk, nothing in the legislation itself says how much risk may remain after countermeasures; this will be settled by enforcement, standards, and future delegated acts.","The paper's taxonomy is explicitly provisional: new implementing and delegated acts may shift where each law maps, so the convergence-and-gap picture should be revisited as the regime develops.","The shared gaps count as a form of convergence: the five acts collectively decline to legislate non-probabilistic, acceptable, and residual risks, which is itself a structural feature of the regime."],"supporting_citations":[{"why":"Internet Security Glossary (RFC 4949); supplies the definitions of acceptable risk and residual risk, plus the probability-times-impact formula, that drive the paper's main gap criteria.","marker":"[64]"},{"why":"The taxonomy development-method guideline whose research activities structure the paper's procedure from goal-setting to validation.","marker":"[70]"},{"why":"The EU's interoperable risk-management toolbox; with [1] it fixes the basic risk/asset/impact vocabulary drawn in Fig. 1.","marker":"[13]"},{"why":"The security engineering framework used to define the conventional risk concepts and security-requirement relations behind the taxonomy.","marker":"[1]"},{"why":"A systematic mapping study showing risk-based approaches are under-studied in requirements-compliance research; establishes the research gap this paper fills.","marker":"[40]"},{"why":"An alignment analysis of the CRA's essential requirements; supports the claim that residual and acceptable risks are unacknowledged in the CRA.","marker":"[58]"},{"why":"An analysis of threat-based versus risk-based cybersecurity governance in the EU; underlies the threat-/asset-/system-centric viewpoint dimension.","marker":"[4]"},{"why":"A CRA-GDPR requirements mapping; underpins the overlaps and compliance-burden discussion and the holistic-compliance advice.","marker":"[56]"},{"why":"A review of risk-based regulatory governance in the EU; frames why the five acts' shared risk concept matters.","marker":"[71]"}],"fun_headline_variants":["EU cyber laws align on risk, but skip acceptable and residual risk","Five EU cyber acts: one risk model, three missing pieces","EU's five cyber laws treat risk the same, omit three key kinds","Risk-based EU cyber rules converge, but leave out residual risk","EU cyber legislation: unified risk framing, three blind spots"],"cache_read_input_tokens":2688,"weakest_assumption_plain":"The gap findings (no acceptable, residual, or non-probabilistic risks anywhere) rest on the authors' selective reading of only 'notable risk-based aspects' of each act; if a provision they did not single out, or an interpretation via recitals, case law, or contextual reading (all excluded), acknowledges these concepts, the claimed gaps would be artifacts of the selection.","fun_headline_variants_meta":{"raw":{"variants":["EU cyber laws align on risk, but skip acceptable and residual risk","Five EU cyber acts: one risk model, three missing pieces","EU's five cyber laws treat risk the same, omit three key kinds","Risk-based EU cyber rules converge, but leave out residual risk","EU cyber legislation: unified risk framing, three blind spots"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000589,"raw_usage":{"total_tokens":2601,"prompt_tokens":746,"completion_tokens":1855,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":490,"completion_tokens_details":{"reasoning_tokens":1767}},"tokens_in":490,"tokens_out":1855,"duration_ms":12305,"temperature":1.0,"reasoning_tokens":1767,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-05T14:18:21.707261+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Search the full text of the five acts and their recitals for 'residual risk', 'acceptable risk', 'risk tolerance', 'risk appetite', or equivalent formulations in EU languages; a single provision instructing that a risk analysis document what risk remains after mitigation, or setting a tolerable risk threshold, falsifies the claimed gap. Separately, the all-probabilistic claim falls if any act defines or uses risk without reference to likelihood — for instance, a threshold- or impact-only definition such as the CER's 'significant disruptive effect' criteria applied without probability, or a saf","supporting_citations":[{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Internet Security Glossary (RFC 4949); supplies the definitions of acceptable risk and residual risk, plus the probability-times-impact formula, that drive the paper's main gap criteria."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"The taxonomy development-method guideline whose research activities structure the paper's procedure from goal-setting to validation."},{"cited_title":"Interoperable EU Risk Management Toolbox","cited_arxiv_id":null,"evidence_quote":"The EU's interoperable risk-management toolbox; with [1] it fixes the basic risk/asset/impact vocabulary drawn in Fig. 1."},{"cited_title":"M., Woody, C., Bandor, M., and Merendino, T","cited_arxiv_id":null,"evidence_quote":"The security engineering framework used to define the conventional risk concepts and security-requirement relations behind the taxonomy."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"A systematic mapping study showing risk-based approaches are under-studied in requirements-compliance research; establishes the research gap this paper fills."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"An alignment analysis of the CRA's essential requirements; supports the claim that residual and acceptable risks are unacknowledged in the CRA."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"An analysis of threat-based versus risk-based cybersecurity governance in the EU; underlies the threat-/asset-/system-centric viewpoint dimension."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"A CRA-GDPR requirements mapping; underpins the overlaps and compliance-burden discussion and the holistic-compliance advice."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"A review of risk-based regulatory governance in the EU; frames why the five acts' shared risk concept matters."}],"review_version":1}