Check if the Cyber Resilience Act applies to your product
Answer a few questions to determine CRA applicability and classification
The Cyber Resilience Act (Regulation (EU) 2024/2847) reaches almost anything with software in it that is sold in Europe. What it asks of you depends entirely on which class your product falls into, and that single decision changes whether you can self assess or whether a notified body has to be involved.
By submitting this form, you accept our Terms and acknowledge that Regulus will process your data to provide CRA Scope Wizard. For more details, see our Privacy Policy.
What the wizard checks
- Whether the product is placed on the EU market. The regulation attaches to the act of selling, licensing or distributing in the EU, not to where you are based.
- What kind of product it is. Hardware with firmware, installable software, a component sold to other manufacturers, or a pure cloud service.
- Whether a sector exclusion applies. Medical devices, type-approved vehicles, civil aviation, marine equipment and defence sit outside the CRA.
- Whether it is radio equipment. WiFi, Bluetooth, cellular or any other RF brings a second set of cybersecurity obligations that is already in force.
- Whether it can exchange data, directly or indirectly, with another device or network.
- Which Annex III or Annex IV category it matches, if any.
- How long you intend to provide security updates.
The four CRA classes, and what each one costs you
Default
Most products land here: connected industrial equipment, appliances, instruments, most firmware. You self assess under internal control. The work is the technical documentation, the cybersecurity risk assessment, the Annex I requirements mapping, the SBOM and the EU declaration of conformity. No notified body.
Important, Class I
Identity and access management, password managers, standalone and embedded browsers, VPNs, network management and traffic monitoring, SIEM, boot managers, PKI and certificate software, operating systems, routers, modems and switches, non-industrial firewalls and intrusion detection, microprocessors and microcontrollers with security functionality, smart home assistants, smart locks, security cameras, baby monitors, alarm systems, connected toys with social or location features, and personal wearables with a health monitoring purpose.
Self assessment is still available, but only if you apply the harmonised standards in full. If you do not, or the standards do not cover your case, a third party has to be involved.
Important, Class II
Hypervisors and container runtimes, firewalls and intrusion detection or prevention systems for industrial use, and tamper-resistant microprocessors and microcontrollers.
Here self assessment on its own is not available. A notified body takes part in the conformity assessment. This is the tier that changes budgets rather than paperwork.
Critical
Hardware devices with security boxes, smart meter gateways, and smartcards or secure elements. The intended route is European cybersecurity certification.
FAQs
Does the Cyber Resilience Act apply to my product?
If it has digital elements, whether software or firmware, and it is sold, licensed or distributed in the EU, it is very likely in scope. The exceptions are products already covered by another regime: medical devices, type-approved vehicles, civil aviation, marine equipment and defence. Pure cloud services with nothing installable fall under NIS2 instead.
What is a product with digital elements?
Any software or hardware product, plus its remote data processing solutions, that can be connected directly or indirectly to another device or network. The remote part matters: a platform your product reports into counts as part of the product, not as a separate service.
What is the difference between default, important and critical?
Default products self assess. Important Class I products can self assess only if harmonised standards are applied in full. Important Class II products need a notified body. Critical products are aimed at European cybersecurity certification. The class is set by what the product does, not by how risky you consider it.
Does the CRA apply to SaaS?
Not on its own. A service with nothing installable is covered by NIS2. But if you ship an agent, an app or any downloadable component, that component and the backend that serves it can be in scope.
Does the CRA apply to open source?
Not to non-commercial open source. It does apply once software is supplied in the course of a commercial activity, and there is a lighter set of duties for open source stewards.
We already have CE marking. Is that enough?
No. The CRA stacks on top of the directives you already comply with rather than replacing any of them. Existing approvals under the radio, machinery, measuring instruments or EMC rules do not satisfy it, and neither does PCI or ISO 27001.
How long do we have to provide security updates?
You have to determine and declare a support period based on how long the product is expected to be in use. Five years is the reference point in the regulation, and shorter periods need to be justified.
What happens to products already on the market?
Products placed on the market before the regulation applies stay under the old rules unless they are substantially modified. The reporting obligations, however, reach products already out there from 11 September 2026.
Early Access for CRA Compliance Tools 🇪🇺
Join Early Access — Save 20%