productcybersecurity
CRAScope & Classification Tool

EU Cyber Resilience Act scope check

Answer four questions to determine whether your product with digital elements falls under the CRA, its classification, and the conformity assessment route — each step cited to the article or annex behind it.

Scope & Classification00/04
  1. 01

    Does the product have digital elements?

    Hardware or software placed on the EU market whose intended use includes a direct or indirect data connection to a device or network.

    CRA Art. 3(1) — definition of ‘product with digital elements’

  2. 02

    Is it made available on the EU market in the course of a commercial activity?

    Free and open-source software developed or supplied outside a commercial activity is out of scope.

    CRA Art. 2 & Recital 18 — scope and FOSS exclusion

  3. 03

    Is it a Class II important product (e.g. OS, firewalls, or industrial IAM)?

    Annex III lists important products. Class II covers higher-risk categories such as operating systems and firewalls.

    CRA Annex III — important products, Class II

  4. 04

    Is it a critical product (e.g. hardware security modules, smart meter gateways)?

    Annex IV lists critical products that may require European cybersecurity certification.

    CRA Annex IV — critical products

Decision Trail

Awaiting input. Answer each question to build a cited determination.

Guidance only — not legal advice. Final classification depends on the full product context and the applicable Annex I essential requirements.

Need a defensible determination?

We turn this preliminary result into documented classification evidence prepared for Notified Body review.

Schedule Consultation