EU Cyber Resilience Act scope check
Answer four questions to determine whether your product with digital elements falls under the CRA, its classification, and the conformity assessment route — each step cited to the article or annex behind it.
- 01
Does the product have digital elements?
Hardware or software placed on the EU market whose intended use includes a direct or indirect data connection to a device or network.
CRA Art. 3(1) — definition of ‘product with digital elements’
- 02
Is it made available on the EU market in the course of a commercial activity?
Free and open-source software developed or supplied outside a commercial activity is out of scope.
CRA Art. 2 & Recital 18 — scope and FOSS exclusion
- 03
Is it a Class II important product (e.g. OS, firewalls, or industrial IAM)?
Annex III lists important products. Class II covers higher-risk categories such as operating systems and firewalls.
CRA Annex III — important products, Class II
- 04
Is it a critical product (e.g. hardware security modules, smart meter gateways)?
Annex IV lists critical products that may require European cybersecurity certification.
CRA Annex IV — critical products
Awaiting input. Answer each question to build a cited determination.
Guidance only — not legal advice. Final classification depends on the full product context and the applicable Annex I essential requirements.
Need a defensible determination?
We turn this preliminary result into documented classification evidence prepared for Notified Body review.