fossick.

FossickCRA scope check › Out of scope

Out of scope of the Cyber Resilience Act: what it means

On the answers given, the product is not a product with digital elements made available on the EU market, or it is covered by other Union legislation that displaces the CRA.

What the manufacturer must do

Which deadlines apply

No CRA deadline applies. If the product changes and comes into scope, the reporting duties from 11 September 2026 and the full obligations from 11 December 2027 apply immediately, with no transition for that product.

What the conformity route looks like

No CRA conformity route and no CRA CE marking. Any CE marking on the product comes from the other legislation that covers it.

The reporting timeline

The reporting duty is the one that bites first, and it runs on three clocks that all start when the manufacturer becomes aware of an actively exploited vulnerability or a severe incident affecting the security of the product.

The 14 day clock runs from the availability of the fix, not from the initial awareness, so a long remediation does not remove the earlier two deadlines.

Products already on the market are reached too

The reporting duty is not limited to new launches. From 11 September 2026 it applies to products with digital elements that are already placed on the EU market, for the whole time the manufacturer supports them. A product shipped in 2024 and still supported in 2027 is inside the regime, even though it was designed before it existed. The full set of obligations, including the technical documentation and CE marking, applies to products placed on the market from 11 December 2027, and to substantially modified versions of existing products after that date.

Check another product

This is guidance, not a legal determination. Classification under the Cyber Resilience Act depends on the full technical description of your product and, in borderline cases, on the assessment of a notified body or your national market surveillance authority.