Appoint us
Products with digital elements assessed for Cyber Resilience Act scope

REP27 · CRA · Scope

Annex I · Annex III · Annex IV · exclusions

What the Cyber Resilience Act actually covers.

The scope sentence is broad on purpose: products with digital elements made available on the Union market, whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. That takes in hardware with firmware, standalone software sold commercially, and remote data processing solutions integral to the product. Then the annexes narrow it into classes, the exclusions remove whole sectors, and the open-source carve-out changes the answer for a large part of the industry. This page works through all of it.

DefaultImportant IImportant IICriticalExcluded

Request this service   Ask a question

The four classes

The four classes of products with digital elements under the Cyber Resilience Act
The four classes of products with digital elements under the Cyber Resilience Act

Most products are default, and default means self-assessment under module A: you apply the essential requirements, you draw up the documentation, you sign the declaration and you affix the CE mark. No notified body, no external certificate, and no shortcut either.

What the regulation asks of a manufacturer

The four groups of manufacturer duties under the Cyber Resilience Act
The four groups of manufacturer duties under the Cyber Resilience Act
The support period is the item that changes product economics. At least five years unless the expected lifetime is shorter, communicated to the user, and security updates available for that whole time. Hardware sold once and abandoned in eighteen months stops being a viable model.

In scope, out of scope

ProductIn scope?Why
Smart home device with an appYesHardware with digital elements and a data connection
Industrial sensor with firmwareYesSame test; business use does not exclude it
Desktop or mobile application sold commerciallyYesSoftware is a product with digital elements
Cloud service behind the productOnly if it is a remote data processing solution integral to the productOtherwise it is NIS2 territory, not CRA
Medical deviceNoCovered by the MDR and IVDR
Motor vehicle systemsNoCovered by automotive type-approval rules
Civil aviation and marine equipmentNoCovered by their own regimes
Free and open-source software outside commercial activityLargely noWith a lighter regime for open-source stewards

The open-source question

This produced more anxiety than any other part of the regulation and the final text is narrower than the early drafts. Three positions are worth distinguishing.

  1. The individual contributor

    Someone publishing a library for free, outside a commercial activity, is not a manufacturer under the regulation and carries no CE obligations.

  2. The open-source software steward

    A legal person systematically providing sustained support for open-source software intended for commercial activities has a lighter set of duties, focused on a security policy and cooperation.

  3. The company shipping open source in a product

    If you integrate a library into a product you sell, you are the manufacturer of that product. The component's licence does not transfer your responsibility, and your SBOM is where this becomes visible.

  4. The practical consequence

    Dependency hygiene stops being a matter of taste. Vulnerability handling under Annex I part II applies to what you ship, including what you did not write.

Essential requirements, in plain language

Secure by design

Delivered without known exploitable vulnerabilities, with a secure default configuration and the ability to reset to it.

Attack surface

Minimised, with exposed interfaces limited to what the product needs.

Protection of data

Confidentiality and integrity of stored, transmitted and processed data, with encryption where appropriate.

Access control

Authentication and authorisation appropriate to the product, with no universal default credentials.

Updates

Security updates available for the support period, delivered securely, automatically where appropriate with the ability to opt out.

Vulnerability handling

An SBOM in a commonly used machine-readable format, a coordinated disclosure policy, and a contact address for reports.

How to classify your own catalogue in an afternoon

StepOutput
List every product you place on the Union marketA row per product, with firmware and software listed separately where they are sold separately
Check the exclusions firstMedical, automotive, aviation, marine drop out immediately
Check Annex III and IVImportant class I, class II or critical, if the product appears there
Everything else is defaultModule A self-assessment, which is most catalogues
Note the conformity route per rowSelf-assessment, harmonised standard, or notified body
Note the support period per rowAt least five years unless the lifetime is shorter, and it has to be published

Doing this early matters because the notified body capacity for important class II and critical products is finite, and the queue at the end of 2027 will not be short.

The short version

If it connects and you sell it in Europe, assume it is in scope until an exclusion says otherwise. Most products are default class and self-assessed; important and critical products need a notified body and planning. Open source outside a commercial activity is largely outside, but what you ship inside your own product is yours regardless of who wrote it. And if you have no establishment in the Union, the optional Article 18 mandate is what fixes your reporting route.

What changes for the product roadmap

Read as engineering rather than law, the CRA rewrites three assumptions that most hardware companies have been running on for a decade.

Old assumptionWhat the regulation requires instead
Ship it and move onSecurity updates for at least five years, resourced as a product line
Default passwords are fine if documentedNo universal default credentials, and secure configuration out of the box
Dependencies are somebody else's problemAn SBOM and vulnerability handling for what you ship, whoever wrote it
Security disclosure is a mailbox nobody readsA coordinated disclosure policy and a published contact point
Updates are optional for usersAutomatic security updates where appropriate, with the ability to opt out
Documentation is written at launchTechnical documentation kept for ten years or the support period, whichever is longer

None of that is exotic in 2026, and most serious manufacturers already do half of it. What changes is that it becomes a market access condition with a CE mark attached rather than a maturity goal, and that it applies to the cheap end of the catalogue exactly as much as to the flagship.

Timing, class by class

Default products

Self-assessment, so the constraint is internal capacity. Start with the essential requirements and the SBOM; the paperwork follows.

Important class I

Applying harmonised standards in full avoids a notified body. Watch the standards as they are published; that decision saves months.

Important class II

Notified body always. Capacity is finite and the queue will lengthen through 2027, so engage early.

Critical

Notified body and possibly a European certification scheme. The longest lead time of all, for a short list of products.

Everyone, by September 2026

The reporting route and the runbook, because that date arrives more than a year before full application.

Everyone, by December 2027

Essential requirements, documentation, declaration of conformity, CE marking.

The short version

If it connects and you place it on the Union market, assume the Cyber Resilience Act applies until an exclusion says otherwise. Most catalogues are default class and self-assessed; important and critical products need a notified body and a plan that starts now rather than in 2027. Security updates for at least five years, an SBOM, no default credentials and a disclosure policy are the requirements that change engineering rather than paperwork. Open source outside a commercial activity is largely outside, but anything you ship inside your own product is yours regardless of who wrote it. And if no entity of yours is established in the Union, the optional Article 18 mandate fixes the one thing you cannot research during an incident.

Two questions that decide your timeline

"Are any of our products important or critical?"

Check Annexes III and IV first, before anything else. A default-class catalogue is a self-assessment exercise you can schedule; a single important class II product changes the plan entirely, because a notified body has to be engaged, capacity is finite and the queue lengthens as December 2027 approaches. Companies that answer this question in 2026 have options; companies that answer it in late 2027 have whatever slot remains.

"How long will we support each product?"

At least five years unless the expected lifetime is shorter, and the period has to be communicated to users. That single sentence reaches into pricing, roadmap and end-of-life planning, and it applies to the cheapest item in the catalogue as much as to the flagship. Deciding it deliberately per product line, and writing it down, is the part most teams postpone and then regret.

How the CRA reads against the GPSR

A connected consumer device sits under both, and teams regularly assume one covers the other. It does not, and the two obligations even attach to different parts of the same box.

PointCyber Resilience ActGPSR
Protects againstCybersecurity riskPhysical safety risk
RepresentativeOptional, Article 18Mandatory, Article 16
Where it appearsTechnical documentation and CE markingPrinted on the product or its packaging
Enforced byMarket surveillance, with CSIRTs for reportingMarket surveillance and the marketplaces
First sign of a problemAn authority request or an exploited vulnerabilityYour listings disappearing from the European sites
Classifying products with digital elements under Annexes III and IV
Classifying products with digital elements under Annexes III and IV
Engineering team reviewing CRA essential requirements for a product

Questions we are actually asked

What is a product with digital elements?

A software or hardware product and its remote data processing solutions, including components placed on the market separately, whose intended or reasonably foreseeable use includes a data connection.

Is standalone software covered?

Yes, where it is placed on the market in the course of a commercial activity. Software is explicitly a product with digital elements.

Are cloud services covered?

Only where they are remote data processing solutions integral to the product. Cloud services as such fall under NIS2 rather than the CRA.

Which products are excluded?

Medical devices, in vitro diagnostics, motor vehicles, civil aviation and marine equipment, each governed by their own legislation.

What are the four classes?

Default, important class I, important class II and critical. Annexes III and IV list the important and critical categories.

What does default class mean in practice?

Self-assessment under module A: apply the essential requirements, draw up the technical documentation, sign the declaration and affix the CE mark.

When is a notified body required?

Always for important class II and critical products; for important class I where harmonised standards are not applied in full.

Is CE marking required?

Yes, from full application on 11 December 2027, based on the applicable conformity assessment route.

What is the support period?

At least five years unless the expected product lifetime is shorter, with security updates available throughout and the period communicated to users.

Is an SBOM mandatory?

Yes, as part of the vulnerability handling requirements, in a commonly used machine-readable format covering at least the top-level dependencies.

How is open source treated?

Software developed or supplied outside a commercial activity is largely outside. Open-source stewards have a lighter regime. What you ship in your own product remains yours.

Do we need an authorised representative?

Optional under Article 18, and it determines the CSIRT that receives your reports if you have no establishment in the Union.

What are the penalties?

Up to €15 million or 2.5% of worldwide annual turnover for the most serious breaches, with lower ceilings for other infringements.

Does the CRA apply to components?

Yes, where they are placed on the market separately. The integrator is the manufacturer of the finished product.

What if we substantially modify someone else's product?

Substantial modification makes you the manufacturer for the modified product, as in the rest of Union product law.

Do we need to keep documentation?

Yes, the technical documentation and the declaration of conformity for ten years or the support period, whichever is longer.

What happens on 11 September 2026?

The reporting obligations apply: actively exploited vulnerabilities and severe incidents, through the ENISA platform.

What does the representative mandate cost?

€490 a year, and it covers holding the documentation and cooperating with market surveillance, not the assessment itself.

Related: the Article 18 mandate · the reporting clock

Scope decided, documentation held

Europe Services, SE in Prague as your Article 18 representative, holding the declaration of conformity and technical documentation for the full retention period.

Request this service