Fossick › CRA scope check
Is your product in scope of the EU Cyber Resilience Act?
The Cyber Resilience Act, Regulation (EU) 2024/2847, covers products with digital elements made available on the EU market. Reporting duties for actively exploited vulnerabilities apply from 11 September 2026. The remaining obligations, including the technical documentation, the Declaration of Conformity and CE marking, apply from 11 December 2027.
Check your product in five questions
No account and no email needed to see your result.
The three categories
Everything in scope falls into one of three tiers. The tier is fixed by what the product is, not by company size or turnover.
Default products
Anything in scope that is not named in Annex III or Annex IV: consumer IoT devices without a security function, connected appliances, hard drives, media players, most business software, smart speakers without assistant functions, sensors and non-critical industrial modules.
Important products, class I
Annex III, class I: identity and password managers, standalone and embedded browsers, VPNs, network management systems, SIEM, boot managers, public key infrastructure and certificate issuance software, operating systems, routers, modems and switches, microprocessors and microcontrollers with security-related functions, ASICs and FPGAs with such functions, smart home assistants, connected toys with tracking or social features, and personal wearables with health monitoring.
Important products, class II
Annex III, class II: hypervisors and container runtimes, firewalls, intrusion detection and prevention systems, and tamper-resistant microprocessors and microcontrollers. Above these sit the critical products of Annex IV — hardware devices with security boxes, smart meter gateways, smartcards and secure elements — which may additionally be pushed towards a European cybersecurity certification scheme.
What the category changes in practice
The essential requirements in Annex I are the same for every tier. What changes is who is allowed to attest that they are met.
- Default — self-assessment. The manufacturer runs the conformity assessment internally under module A and signs the Declaration of Conformity itself.
- Important class I — self-assessment remains available only where the product is built in full accordance with the applicable harmonised standards or a European cybersecurity certification scheme; otherwise a notified body is required.
- Important class II — a notified body is required in all cases: EU type-examination plus conformity to type, or full quality assurance.
In every tier the technical documentation, the SBOM and the vulnerability handling process must exist and be kept current for the support period. The tier decides who audits them.
The reporting timeline
The reporting duty is the one that bites first, and it runs on three clocks that all start when the manufacturer becomes aware of an actively exploited vulnerability or a severe incident affecting the security of the product.
- 24 hours — early warning to ENISA and the CSIRT designated as coordinator in the Member State of main establishment.
- 72 hours — full notification, with an assessment of the vulnerability or incident and any corrective or mitigating measures taken.
- 14 days — final report once a corrective or mitigating measure is available: a description of the vulnerability, its severity and impact, and where available the exploitation vector.
The 14 day clock runs from the availability of the fix, not from the initial awareness, so a long remediation does not remove the earlier two deadlines.
Products already on the market are reached too
The reporting duty is not limited to new launches. From 11 September 2026 it applies to products with digital elements that are already placed on the EU market, for the whole time the manufacturer supports them. A product shipped in 2024 and still supported in 2027 is inside the regime, even though it was designed before it existed. The full set of obligations, including the technical documentation and CE marking, applies to products placed on the market from 11 December 2027, and to substantially modified versions of existing products after that date.
What is out of scope
The CRA steps back where other Union legislation already imposes cybersecurity requirements of at least equivalent effect. Excluded, in the main:
- Medical devices and in vitro diagnostic medical devices under Regulations (EU) 2017/745 and 2017/746.
- Motor vehicles and their systems covered by Regulation (EU) 2019/2144, together with UN Regulations 155 and 156.
- Civil aviation products covered by Regulation (EU) 2018/1139.
- Marine equipment covered by Directive 2014/90/EU.
- Products developed exclusively for national security, defence, or the processing of classified information.
- Spare parts that restore an existing product to its original function, and non-commercial free and open source software supplied outside a commercial activity.
- Pure services, including SaaS, unless the remote data processing solution is necessary for the product to perform its function.
Result pages
- Out of scope — Out of scope of the Cyber Resilience Act: what it means
- Default product — Default category under the Cyber Resilience Act: what it means
- Important product, class I — Important product class I under the Cyber Resilience Act
- Important product, class II — Important product class II under the Cyber Resilience Act
This is guidance, not a legal determination. Classification under the Cyber Resilience Act depends on the full technical description of your product and, in borderline cases, on the assessment of a notified body or your national market surveillance authority.