EU Regulation 2024/2847 - Scope

    Who Does CRA
    Apply To?

    The Cyber Resilience Act applies to manufacturers, importers, and distributors of products with digital elements placed on the EU market. The scope is broad - if your product has network connectivity or processes data, it almost certainly qualifies.

    The key question is not whether you are in scope, but which product category your products fall into - as this determines what kind of conformity assessment you need and what obligations apply.

    "Products with Digital Elements" - The Core Definition

    The CRA applies to any product that has a direct or indirect logical or physical data connection to a device or network. This is intentionally broad to capture the full range of connected technology.

    Hardware products in scope

    • - Routers, switches, and network equipment
    • - Smart home devices (thermostats, cameras, locks)
    • - Wearables with data connectivity
    • - Industrial IoT sensors and controllers
    • - Connected medical devices
    • - Laptops, tablets, smartphones

    Software products in scope

    • - Desktop and server software
    • - Mobile applications
    • - Cloud-connected software (SaaS)
    • - Operating systems and firmware
    • - Software components and libraries with network functionality
    • - APIs and SDKs distributed to third parties

    Who must comply

    Primary obligations fall on manufacturers - entities that develop or produce products with digital elements and place them on the EU market under their own name or trademark. Importers and distributors have secondary obligations including verification that manufacturers have met their CRA obligations before placing products on the market.

    Product Categories and Conformity Assessment

    The CRA classifies products into three categories based on cybersecurity risk. The category determines what type of conformity assessment is required before CE marking. See security-by-design requirements for what each assessment covers.

    Default Category

    Standard riskManufacturer self-assessment

    The vast majority of products with digital elements fall into the default category. These products can self-certify against the Annex I essential requirements without involving a third party.

    Examples

    • Standard consumer software applications
    • Business productivity software
    • Non-critical IoT devices (smart home appliances)
    • Basic web applications
    • General-purpose operating systems (below Class I threshold)

    Class I Products

    Higher riskThird-party assessment OR harmonised standards

    Class I products present higher cybersecurity risk due to their function or the damage their compromise could cause. These require either a third-party conformity assessment or demonstration of compliance with harmonised European standards.

    Examples

    • Web browsers and browser extensions
    • Password managers
    • Software with privileged system access (antivirus, endpoint detection)
    • Network monitoring and management software
    • Firewalls and intrusion detection/prevention systems
    • VPNs and secure communication software
    • Physical access management systems
    • Home automation hubs

    Class II Products

    Highest riskEU Notified Body assessment required

    Class II products are the highest-risk category whose compromise could have severe societal or economic consequences. Conformity assessment by an accredited EU notified body is mandatory - self-certification is not available.

    Examples

    • Hypervisors and container runtime environments
    • Industrial automation and control systems
    • Medical device software
    • Critical infrastructure management systems
    • Automotive software with safety-critical functions
    • Tamper-resistant microprocessors and secure elements
    • Hardware security modules (HSMs)
    • Smart meter gateways

    Exemptions from CRA Scope

    The following categories are explicitly excluded from CRA requirements. Note that these exemptions are narrowly defined - if in doubt, seek legal advice on applicability.

    Open Source Software (Non-Commercial)

    Software supplied in a non-commercial context - where the developer does not derive commercial benefit from the product. Note: companies that commercially distribute or provide support for open source software are likely within scope.

    Bespoke and Custom-Developed Products

    Products developed and used exclusively within an organisation for internal purposes only, not placed on the market. If a product is sold or licensed to external parties, this exemption does not apply.

    Defence and National Security

    Products intended exclusively for national security, military, or classified purposes, or designed specifically to process classified information under member state or EU law.

    Sector-Regulated Products

    Products already covered by sector-specific EU regulations with equivalent cybersecurity requirements - including certain medical devices, civil aviation systems, and motor vehicles - may be exempt where those regulations provide equivalent protection.

    Research and Development Prototypes

    Products made available exclusively for evaluation, testing, or demonstration purposes at trade fairs and similar events, and clearly identified as such, before being placed on the market.

    B2B Supply Chain Obligations

    The CRA creates obligations throughout the supply chain, not just at the final product level. Manufacturers who integrate third-party components must account for the security of those components.

    Component manufacturers

    If you produce software components (libraries, SDKs, modules) that are incorporated into other manufacturers' products and placed on the EU market, you may have CRA obligations as a component manufacturer. This applies even if your component is not sold directly to end users.

    Integrating third-party components

    If you build a product using third-party components, you are responsible for the security of the overall product including those components. This requires maintaining an SBOM and actively monitoring for vulnerabilities in your dependencies - not just your own code.

    CRA full regulatory text

    EU Regulation 2024/2847 - official text via EUR-Lex

    Read the regulation