CRA Applicability Check
Answer a few questions about your product. Get a four-line verdict — scope, Annex III/IV classification, conformity route, and penalty exposure — each citation-anchored to the regulation.
SCOPE // awaiting inputsCLASS // requires SCOPEROUTE // requires CLASSPENALTY // requires ROUTE
How to read this verdict
- SCOPE — whether the CRA applies to your product at all.
- CLASS — your Annex III/IV class: default, important I/II, or critical.
- ROUTE — the conformity-assessment path: self-assessment or notified body.
- PENALTY — the maximum fine exposure under Art. 64.
Answer the questions above and each line resolves with its article citation.
What the CRA requires — at a glance
The EU Cyber Resilience Act (Reg (EU) 2024/2847) applies in full from 11 December 2027, with manufacturer vulnerability- and incident-reporting obligations (Art. 14) starting 11 September 2026. It covers products with digital elements placed on the EU market. The essential cybersecurity requirements sit in Annex I; 'important' products are enumerated in Annex III (class I and class II) and 'critical' products in Annex IV — classification is by enumerated category, not by abstract risk factors. Maximum penalties reach €15M or 2.5% of worldwide annual turnover (Art. 64).
- Scope
- Products with digital elements on the EU market — Art. 2 + Art. 3
- Classes
- Default · Important class I · Important class II · Critical — Annex III/IV
- Reporting from
- 11 Sep 2026 — manufacturer reporting (Art. 14)
- Full application
- 11 Dec 2027 — placing on the market (Art. 71)
- Max penalty
- ≤ €15M or 2.5% of worldwide turnover — Art. 64
Official sources: European Commission — CRA summary · EUR-Lex — Reg (EU) 2024/2847 · European Commission — conformity assessment
Citations and the Annex III/IV classification list verified against EUR-Lex on 2026-06-13. Dataset version 2.0.0.
Frequently asked questions
- When does the EU Cyber Resilience Act apply?
- The CRA entered into force on 10 December 2024. Manufacturer reporting obligations (Art. 14) apply from 11 September 2026, the rules on conformity assessment bodies (Chapter IV) from 11 June 2026, and the regulation applies in full — including placing-on-the-market obligations — from 11 December 2027.
- Where are the CRA essential cybersecurity requirements written?
- Annex I. Part I lists product properties (secure by design, no known exploitable vulnerabilities, secure default configuration, confidentiality/integrity/availability protection, security updates) and Part II lists vulnerability-handling requirements. Annex II is a different annex — it covers the information and instructions supplied to the user.
- How does the CRA classify important and critical products?
- By an enumerated product-category list, not by audience or connection type. Annex III lists 'important' products (class I, e.g. password managers, VPNs, routers, operating systems, smart-home security devices; class II, e.g. firewalls, IDS/IPS, tamper-resistant microcontrollers). Annex IV lists 'critical' products (security boxes, smart meter gateways, smartcards with secure elements). Anything in scope but not enumerated is the default category.
- Do I need a Notified Body for my CRA conformity assessment?
- Default-category products use self-assessment (Module A). Important class I products can self-assess only when harmonised standards, common specifications or a cybersecurity certification scheme are fully applied — otherwise a Notified Body is required. Important class II products require a Notified Body (or an EU cybersecurity certification scheme). Critical products require a Notified Body in every case.
- Is pure SaaS covered by the CRA?
- Generally no — a standalone hosted service with no product component is treated as a service (covered by NIS2 / sectoral law). But a 'remote data processing solution' that is essential to a product's function and developed by or for the manufacturer is captured by the CRA (Art. 3(2)). This tool flags that case as AMBIGUOUS rather than out of scope.
- What are the maximum CRA penalties?
- Up to €15M or 2.5% of total worldwide annual turnover (whichever is higher) for breach of the Annex I essential requirements and the Art. 13/14 obligations; up to €10M or 2% for other obligations; and up to €5M or 1% for supplying incorrect or misleading information to a Notified Body or market surveillance authority (Art. 64).