The Cyber Resilience Act applies to manufacturers, importers, and distributors of products with digital elements placed on the EU market. The scope is broad - if your product has network connectivity or processes data, it almost certainly qualifies.
The key question is not whether you are in scope, but which product category your products fall into - as this determines what kind of conformity assessment you need and what obligations apply.
The CRA applies to any product that has a direct or indirect logical or physical data connection to a device or network. This is intentionally broad to capture the full range of connected technology.
Primary obligations fall on manufacturers - entities that develop or produce products with digital elements and place them on the EU market under their own name or trademark. Importers and distributors have secondary obligations including verification that manufacturers have met their CRA obligations before placing products on the market.
The CRA classifies products into three categories based on cybersecurity risk. The category determines what type of conformity assessment is required before CE marking. See security-by-design requirements for what each assessment covers.
The vast majority of products with digital elements fall into the default category. These products can self-certify against the Annex I essential requirements without involving a third party.
Class I products present higher cybersecurity risk due to their function or the damage their compromise could cause. These require either a third-party conformity assessment or demonstration of compliance with harmonised European standards.
Class II products are the highest-risk category whose compromise could have severe societal or economic consequences. Conformity assessment by an accredited EU notified body is mandatory - self-certification is not available.
The following categories are explicitly excluded from CRA requirements. Note that these exemptions are narrowly defined - if in doubt, seek legal advice on applicability.
Software supplied in a non-commercial context - where the developer does not derive commercial benefit from the product. Note: companies that commercially distribute or provide support for open source software are likely within scope.
Products developed and used exclusively within an organisation for internal purposes only, not placed on the market. If a product is sold or licensed to external parties, this exemption does not apply.
Products intended exclusively for national security, military, or classified purposes, or designed specifically to process classified information under member state or EU law.
Products already covered by sector-specific EU regulations with equivalent cybersecurity requirements - including certain medical devices, civil aviation systems, and motor vehicles - may be exempt where those regulations provide equivalent protection.
Products made available exclusively for evaluation, testing, or demonstration purposes at trade fairs and similar events, and clearly identified as such, before being placed on the market.
The CRA creates obligations throughout the supply chain, not just at the final product level. Manufacturers who integrate third-party components must account for the security of those components.
If you produce software components (libraries, SDKs, modules) that are incorporated into other manufacturers' products and placed on the EU market, you may have CRA obligations as a component manufacturer. This applies even if your component is not sold directly to end users.
If you build a product using third-party components, you are responsible for the security of the overall product including those components. This requires maintaining an SBOM and actively monitoring for vulnerabilities in your dependencies - not just your own code.
CRA full regulatory text
EU Regulation 2024/2847 - official text via EUR-Lex