The Cyber Resilience Act establishes cybersecurity requirements for products with digital elements supplied on the EU market. Start by identifying the product and your role, then determine its category and the applicable assessment procedure.
Apply this to your product

Answer the questions and see the reasoning.

Open scope & role

Begin with the product boundary

Regulation (EU) 2024/2847 covers hardware and software, including separately supplied components and qualifying remote data processing. Its scope test looks at intended or reasonably foreseeable direct or indirect data connections to another device or network. An internet connection is not necessary.

Describe what is supplied, who receives it and which remote functions belong to it. A commercial desktop application, its mandatory manufacturer-controlled backend and an independently operated web service may require different analyses. Sector-specific exclusions must be checked against the actual legislation covering the product.

Articles 2 and 3; guidance section 2CRA text Commission guidance

Identify who carries which duties

The entity developing or commissioning a product and marketing it under its own name or trademark is generally its manufacturer. An EU-established entity first placing a third-country branded product on the EU market may be an importer. A subsequent reseller may be a distributor.

These roles concern a particular product and supply arrangement. A company may hold different roles for different products. Rebranding or substantially modifying a third-party product can create manufacturer obligations. A software steward is a separate role with targeted duties for certain sustained support of FOSS.

Article 3; Articles 13 and 18–24CRA text

Build evidence throughout the product lifecycle

Manufacturers must assess cybersecurity risks and use that assessment to implement the essential requirements. The work includes secure design, appropriate defaults, handling vulnerabilities, maintaining documentation and giving users the information needed for secure operation.

A support period must reflect expected use and the statutory criteria. The general minimum is five years unless expected use is shorter; a longer expected use can require a longer support period. This is not a universal five-year ceiling.

  • Record product boundaries, intended purpose, foreseeable use and cybersecurity risks.
  • Document component due diligence, security testing and vulnerability handling.
  • Maintain technical documentation and a reasoned support-period decision.
  • Select an assessment route, complete it and prepare the declaration and CE marking where required.
Article 13; Annexes I, II and VII; guidance section 5CRA text Commission guidance

Keep classification separate from compliance

Default, Important Class I, Important Class II and Critical identify product categories that affect conformity assessment. They do not establish whether a particular product is secure or compliant.

The core functionality of the whole product must be compared with the statutory categories and their technical descriptions. Using an important component does not automatically make the whole product important.

Articles 7, 8 and 32; Annexes III and IV; Regulation 2025/2392CRA text Implementing Regulation (EU) 2025/2392

Prepare for two different application dates

Article 14 reporting for manufacturers starts on 11 September 2026. Open-source software steward reporting under Article 24(3) applies from 11 December 2027 under Article 71(2). Most product obligations apply from 11 December 2027. Products already placed on the market have transitional treatment, but manufacturer reporting also covers older in-scope products.

Create an incident runbook before reporting applies. Record awareness accurately, distinguish exploited vulnerabilities from severe incidents and know who will submit notifications. A completed checker is a planning aid, not a conformity assessment or permission to affix CE marking.

Articles 14, 69 and 71; guidance section 9CRA text Commission guidance

Frequently asked questions

Does the CRA apply only to products made in the EU?

No. The scope concerns supply on the EU market. A manufacturer can be established outside the EU; the supply chain may also include an EU importer.

Does passing a CRA checker mean my product is compliant?

No. A checker helps identify likely rules from your answers. Compliance requires the relevant engineering, documentation, assessment and ongoing processes.

Can a free product fall within scope?

Yes. Supply in a commercial activity can be free of charge. For FOSS, examine the particular distribution and monetisation arrangement rather than the download price alone.

This guide supports an initial assessment. Your result depends on the product facts and the applicable measures. Read how to use this guidance.