To calculate the risk we use the following tables, where in the matrix presented in Figure C.1.1-3, we define how the impact (Figure C.1.1-1) and likelihood (Figure C.1.1-2) associated to a risk are combined to calculate the final risk value.
Later on in sections C.1.2 and C.1.3 we further define for the different use cases the impact factors to define these likelihood and impact values.
As a remainder the 4 use cases define in the standard are:
In this section we present the evaluation of the riks factors for each of the 4 use cases.
In the table we evaluate the risks for each use cases related to threats defined in section 4. For each threats the list of associated risk factors values are assessed and for each combinaison of factors a maximum function is applied (the resulting impact or likelihood level is the maximum of all risk factors levels).
The risk are then calculated and their applicability defined using the matrixes presented in Figure C.1.1-3 and Figure C.1.2-1.

**Figure C.2.2-1: Risk evaluation part 1**

**Figure C.2.2-2: Risk evaluation part 2**

**Figure C.2.2-3: Risk evaluation part 3**

**Figure C.2.2-4: Risk evaluation part 4**

**Figure C.2.2-5: Risk evaluation part 5**

# Annex K (normative): Generic requirements and assessment criteria for the use of state of the art cryptography V 0.51 (2025-02-16)
ETSI Drafting rules do not allow footnotes. All footnotes in this Annex will have to be deleted or replaced by relevant references and notes before publication.