Is your connected product ready for the CRA?
In 20 minutes, jargon-free, place your product against the CRA obligations: classification, role, priority gaps and deadlines (Sept. 2026 / Dec. 2027).
No sign-up required for the assessment.
The Cyber Resilience Act, in three sentences
The Cyber Resilience Act — Regulation (EU) 2024/2847 — sets cybersecurity requirements for products with digital elements placed on the European Union market. It does not target one industry: as soon as a hardware or software product has a digital part and is commercialised in the Union, it falls within scope by default.
Obligations do not depend on company size but on two variables: the product category, which determines how demanding the verification procedure is, and your economic role — manufacturer, importer, distributor — which determines what you must demonstrate.
Two dates shape the timeline: 11 September 2026 for the obligation to report actively exploited vulnerabilities, and 11 December 2027 for general application, CE marking included.
Are you in scope?
The default rule is broad. A product with digital elements, made available on the Union market in the course of a commercial activity, is within scope. A few cases fall outside it.
Typically in scope
- Industrial equipment driven by firmware, even when it is only connected to a local network.
- A sensor, a PLC or a gateway that sends data back to a server.
- Software sold on its own or embedded in a hardware product.
- A product manufactured outside the Union that you import and make available on the European market.
Outside the scope
- Products covered by sector-specific rules: medical devices (Regulations 2017/745 and 2017/746), motor vehicles (2019/2144), aviation (2018/1139), marine equipment (Directive 2014/90/EU).
- Products with no digital element.
- Free and open-source software developed or supplied outside a commercial activity — the Regulation also provides a lighter regime for open-source software stewards (Art. 24).
When in doubt, the assessment settles it in a few questions and tells you which article the conclusion rests on.
Two dates to remember
A third date, 11 June 2026, concerns the designation of notified bodies. It creates no direct obligation for manufacturers, but it governs how available those bodies are for the products that need them. See the full timeline
How the assessment works
You describe the product
Category, connectivity, any sector-specific regime, economic role, then your current practices across eight areas. Around fifteen questions, in plain language.
The engine applies the rules
Deterministic logic — not a language model — matches your answers against the rules of the Regulation. Identical answers, identical verdict.
You leave with a plan
A reasoned classification, the obligations attached to your role, a gap register sorted by deadline and severity, with an effort estimate for each.
A traceable verdict
Every conclusion is tied to an article or annex of the regulation. No black box: you know why you are classified as you are.
A prioritised action plan
Your gaps, ranked by deadline and criticality, with estimated effort — enough to present a plan to your leadership or your customer.
Understanding the CRA, topic by topic
In-depth guides built on the same reference material as the assessment engine: every statement points back to the article or annex behind it.
11 September 2026 for an SME
The first CRA deadline, what it actually requires of a twenty-person manufacturer, and the reporting checklist to put in place beforehand.
CRA product classes
Class I, class II, critical products: what decides which regime applies to your product — and whether a notified body is involved.
Manufacturer, importer, distributor
The CRA allocates obligations by economic role. Here are yours, article by article.
CRA deadlines
11 June 2026, 11 September 2026, 11 December 2027: what applies when, and how to plan backwards from it.
SBOM and the CRA
What Annex I actually requires of a software bill of materials — and what it does not.
Technical documentation and conformity
Annex VII, the Article 32 procedures, and when self-assessment remains possible.
AI Act and connected products
What applies to a connected product with AI features, and from when.
Frequently asked questions
What is the Cyber Resilience Act?
The Cyber Resilience Act is Regulation (EU) 2024/2847. It sets cybersecurity requirements for products with digital elements placed on the Union market: security by design, vulnerability handling, technical documentation, conformity assessment and CE marking.
Is my industrial product in scope?
By default yes, as soon as it contains digital elements and is made available on the Union market in the course of a commercial activity. The main exceptions are products covered by sector-specific rules — medical devices, vehicles, aviation, marine equipment — and open-source software supplied outside a commercial activity.
What are the CRA application dates?
The obligation to report actively exploited vulnerabilities and severe incidents applies from 11 September 2026. The other obligations — essential requirements, technical documentation, conformity assessment, CE marking — apply from 11 December 2027.
What is an important product of class I or class II?
Annex III of the Regulation lists product categories considered more sensitive, split into class I (password managers, VPNs, operating systems, routers, microcontrollers with security functions, and so on) and class II (hypervisors, firewalls, IDS/IPS, tamper-resistant microcontrollers and microprocessors). Annex IV lists critical products. This classification determines which conformity assessment procedure applies.
Do I need a notified body?
Not necessarily. For a product in the default category, self-assessment is possible. For class I it is also possible where the applicable harmonised standards are applied in full; otherwise a notified body must be involved. For class II and the critical products of Annex IV, a notified body is required.
Does the CRA apply to open-source software?
Open-source software developed or supplied outside a commercial activity is not subject to the manufacturer's obligations. The Regulation creates a separate, lighter regime for open-source software stewards (Art. 24). An open-source component embedded in a commercial product, however, falls under the responsibility of whoever places that product on the market.
Let's do it together
The diagnostic takes twenty minutes on your own. If the regulation's vocabulary slows you down, we run it with you in one session, and you leave with a prioritised action plan.
Place your product in 20 minutes
The assessment is free and requires no sign-up. You get your product's classification, the obligations attached to your role, and a prioritised gap register.
Start my free assessment