Cyber Resilience Act · Regulation (EU) 2024/2847

Is your connected product ready for the CRA?

In 20 minutes, jargon-free, place your product against the CRA obligations: classification, role, priority gaps and deadlines (Sept. 2026 / Dec. 2027).

No sign-up required for the assessment.

The Cyber Resilience Act, in three sentences

The Cyber Resilience Act — Regulation (EU) 2024/2847 — sets cybersecurity requirements for products with digital elements placed on the European Union market. It does not target one industry: as soon as a hardware or software product has a digital part and is commercialised in the Union, it falls within scope by default.

Obligations do not depend on company size but on two variables: the product category, which determines how demanding the verification procedure is, and your economic role — manufacturer, importer, distributor — which determines what you must demonstrate.

Two dates shape the timeline: 11 September 2026 for the obligation to report actively exploited vulnerabilities, and 11 December 2027 for general application, CE marking included.

Are you in scope?

The default rule is broad. A product with digital elements, made available on the Union market in the course of a commercial activity, is within scope. A few cases fall outside it.

Typically in scope

  • Industrial equipment driven by firmware, even when it is only connected to a local network.
  • A sensor, a PLC or a gateway that sends data back to a server.
  • Software sold on its own or embedded in a hardware product.
  • A product manufactured outside the Union that you import and make available on the European market.

Outside the scope

  • Products covered by sector-specific rules: medical devices (Regulations 2017/745 and 2017/746), motor vehicles (2019/2144), aviation (2018/1139), marine equipment (Directive 2014/90/EU).
  • Products with no digital element.
  • Free and open-source software developed or supplied outside a commercial activity — the Regulation also provides a lighter regime for open-source software stewards (Art. 24).

When in doubt, the assessment settles it in a few questions and tells you which article the conclusion rests on.

Two dates to remember

11 September 2026Reporting obligations: any actively exploited vulnerability and any severe incident must be notified to the designated CSIRT and to ENISA (Art. 14).
11 December 2027General application: essential requirements, technical documentation, conformity assessment, EU declaration of conformity and CE marking.

A third date, 11 June 2026, concerns the designation of notified bodies. It creates no direct obligation for manufacturers, but it governs how available those bodies are for the products that need them. See the full timeline

How the assessment works

You describe the product

Category, connectivity, any sector-specific regime, economic role, then your current practices across eight areas. Around fifteen questions, in plain language.

The engine applies the rules

Deterministic logic — not a language model — matches your answers against the rules of the Regulation. Identical answers, identical verdict.

You leave with a plan

A reasoned classification, the obligations attached to your role, a gap register sorted by deadline and severity, with an effort estimate for each.

A traceable verdict

Every conclusion is tied to an article or annex of the regulation. No black box: you know why you are classified as you are.

A prioritised action plan

Your gaps, ranked by deadline and criticality, with estimated effort — enough to present a plan to your leadership or your customer.

Understanding the CRA, topic by topic

In-depth guides built on the same reference material as the assessment engine: every statement points back to the article or annex behind it.

Frequently asked questions

What is the Cyber Resilience Act?

The Cyber Resilience Act is Regulation (EU) 2024/2847. It sets cybersecurity requirements for products with digital elements placed on the Union market: security by design, vulnerability handling, technical documentation, conformity assessment and CE marking.

Is my industrial product in scope?

By default yes, as soon as it contains digital elements and is made available on the Union market in the course of a commercial activity. The main exceptions are products covered by sector-specific rules — medical devices, vehicles, aviation, marine equipment — and open-source software supplied outside a commercial activity.

What are the CRA application dates?

The obligation to report actively exploited vulnerabilities and severe incidents applies from 11 September 2026. The other obligations — essential requirements, technical documentation, conformity assessment, CE marking — apply from 11 December 2027.

What is an important product of class I or class II?

Annex III of the Regulation lists product categories considered more sensitive, split into class I (password managers, VPNs, operating systems, routers, microcontrollers with security functions, and so on) and class II (hypervisors, firewalls, IDS/IPS, tamper-resistant microcontrollers and microprocessors). Annex IV lists critical products. This classification determines which conformity assessment procedure applies.

Do I need a notified body?

Not necessarily. For a product in the default category, self-assessment is possible. For class I it is also possible where the applicable harmonised standards are applied in full; otherwise a notified body must be involved. For class II and the critical products of Annex IV, a notified body is required.

Does the CRA apply to open-source software?

Open-source software developed or supplied outside a commercial activity is not subject to the manufacturer's obligations. The Regulation creates a separate, lighter regime for open-source software stewards (Art. 24). An open-source component embedded in a commercial product, however, falls under the responsibility of whoever places that product on the market.

Let's do it together

The diagnostic takes twenty minutes on your own. If the regulation's vocabulary slows you down, we run it with you in one session, and you leave with a prioritised action plan.

Place your product in 20 minutes

The assessment is free and requires no sign-up. You get your product's classification, the obligations attached to your role, and a prioritised gap register.

Start my free assessment
FirmVox is a compliance assistance tool. It is not legal advice and does not replace consulting the official text or qualified counsel.
FirmVox — Diagnostic de conformité CRA