fossick.

Fossick › CRA scope check

Is your product in scope of the EU Cyber Resilience Act?

The Cyber Resilience Act, Regulation (EU) 2024/2847, covers products with digital elements made available on the EU market. Reporting duties for actively exploited vulnerabilities apply from 11 September 2026. The remaining obligations, including the technical documentation, the Declaration of Conformity and CE marking, apply from 11 December 2027.

Check your product in five questions

No account and no email needed to see your result.

The three categories

Everything in scope falls into one of three tiers. The tier is fixed by what the product is, not by company size or turnover.

Default products

Anything in scope that is not named in Annex III or Annex IV: consumer IoT devices without a security function, connected appliances, hard drives, media players, most business software, smart speakers without assistant functions, sensors and non-critical industrial modules.

Important products, class I

Annex III, class I: identity and password managers, standalone and embedded browsers, VPNs, network management systems, SIEM, boot managers, public key infrastructure and certificate issuance software, operating systems, routers, modems and switches, microprocessors and microcontrollers with security-related functions, ASICs and FPGAs with such functions, smart home assistants, connected toys with tracking or social features, and personal wearables with health monitoring.

Important products, class II

Annex III, class II: hypervisors and container runtimes, firewalls, intrusion detection and prevention systems, and tamper-resistant microprocessors and microcontrollers. Above these sit the critical products of Annex IV — hardware devices with security boxes, smart meter gateways, smartcards and secure elements — which may additionally be pushed towards a European cybersecurity certification scheme.

What the category changes in practice

The essential requirements in Annex I are the same for every tier. What changes is who is allowed to attest that they are met.

In every tier the technical documentation, the SBOM and the vulnerability handling process must exist and be kept current for the support period. The tier decides who audits them.

The reporting timeline

The reporting duty is the one that bites first, and it runs on three clocks that all start when the manufacturer becomes aware of an actively exploited vulnerability or a severe incident affecting the security of the product.

The 14 day clock runs from the availability of the fix, not from the initial awareness, so a long remediation does not remove the earlier two deadlines.

Products already on the market are reached too

The reporting duty is not limited to new launches. From 11 September 2026 it applies to products with digital elements that are already placed on the EU market, for the whole time the manufacturer supports them. A product shipped in 2024 and still supported in 2027 is inside the regime, even though it was designed before it existed. The full set of obligations, including the technical documentation and CE marking, applies to products placed on the market from 11 December 2027, and to substantially modified versions of existing products after that date.

What is out of scope

The CRA steps back where other Union legislation already imposes cybersecurity requirements of at least equivalent effect. Excluded, in the main:

Result pages

This is guidance, not a legal determination. Classification under the Cyber Resilience Act depends on the full technical description of your product and, in borderline cases, on the assessment of a notified body or your national market surveillance authority.