A product is likely within CRA scope when it is a product with digital elements supplied on the EU market in a commercial activity, has the relevant direct or indirect data connection, and is not covered by an exclusion.
Apply this to your product

Answer the questions and see the reasoning.

Open scope & role

A practical sequence for determining scope

First identify the actual product or separately supplied component. Then establish its intended and foreseeable connections, EU supply and commercial context. Check exclusions only after identifying the product accurately.

The supply of a product and its use inside an organisation are different facts. Mere internal use does not automatically establish that a product was made available on the market. A free download can still be supplied commercially, while publication of community source code may not be commercial supply.

  • Define the product and the relevant version or unit.
  • Identify the entity responsible for that supply.
  • Check EU market availability and the commercial arrangement.
  • Examine product-specific exclusions and any special FOSS role.
Articles 2 and 3; guidance sections 2 and 3CRA text Commission guidance

Connectivity includes more than the internet

The connection can be logical or physical, direct or indirect, to a device or a network. A product operating locally is not automatically excluded simply because it never contacts a cloud server. Software can interact with a host system; hardware can communicate through local interfaces.

Keep the distinction between software supplied for execution by the user and a service merely accessed remotely. The Commission guidance treats locally installed clients, including those built with web technologies, differently from websites accessed exclusively in a browser.

Article 2(1); Article 3(1)–(4); guidance section 2.2CRA text Commission guidance

Read sector exclusions narrowly

Certain products covered by medical-device, in-vitro diagnostic, motor-vehicle and civil-aviation legislation are excluded under the conditions in Article 2. Marine equipment and products exclusively developed or modified for national security or defence also require checking the specific exclusion text.

The exclusion is not an industry-wide exemption for every component or software tool used by a hospital, aircraft manufacturer or defence supplier. Delegated Regulation 2025/1535 also addresses certain products covered by the L-category vehicle framework. If coverage under the sectoral act is uncertain, seek further assessment.

Article 2; check the current delegated exclusionsCRA text

Distinguish FOSS supply from stewardship

Non-commercial FOSS is excluded from the ordinary product obligations, but a legal entity sustaining specific FOSS intended for commercial activities may qualify as a steward under Article 24. Contributors do not automatically become manufacturers.

Optional paid consulting around freely available FOSS does not by itself make its supply commercial. Access to a paid edition or maintenance conditioned on remuneration is a different scenario. Pure recovery of actual costs can be treated differently from profit-seeking supply. Assess the particular edition, supplier and arrangement.

Article 2(3), Article 3(14), Article 24; guidance section 3CRA text Commission guidance

Keep a record of the boundary decision

Retain a short architecture description, distribution terms, a list of remote dependencies and the evidence for any exclusion. Revisit the decision when the product, delivery model, branding or commercial arrangement changes.

Once scope and role are established, classification is the next step. Scope alone does not determine whether internal control or a notified body is available for conformity assessment.

Articles 7, 8, 13 and 32CRA text

Frequently asked questions

Is a software library a product?

A separately supplied software component can be a product with digital elements. Its commercial supply and any FOSS treatment still need to be assessed.

Does a cloud dependency always fall within scope?

No. The definition requires a functional dependency and software designed or developed by or under the responsibility of the manufacturer. It is not enough that a service is useful to the business.

This guide supports an initial assessment. Your result depends on the product facts and the applicable measures. Read how to use this guidance.