Cyber Resilience ActFree Resource

Cyber Resilience Act Scope, duties and CE marking

Decide whether software, hardware, a separately marketed component, or necessary remote processing is a under the CRA (Regulation (EU) 2024/2847), which regulated role you hold, and what must happen before EU market placement and during the .

By Sorena AIUpdated 2026Based on official sources
Quick scan
CRA
Start with the product boundary
The CRA is about products with digital elements, including software, hardware, separately marketed components, and remote processing that the product needs for its functions.
Build the product security file
Keep the risk assessment, Annex I requirement mapping, vulnerability-handling process, SBOM record, support-period rationale, user instructions, tests, and conformity evidence together.
Route CE and reporting work early
reporting applies before the main application date. Conformity assessment and depend on whether the product is outside the important and critical categories, important class I, important class II, or critical, and on the standards, common specifications, or certification route used.

Use the timeline and topic guides to move from product classification to release gates, security-update operations, reporting readiness, and market-surveillance evidence.

Key dates
Annex I
Security
Art. 14
Reporting
Art. 32
Conformity
CE
Marking
What the hub helps you check
Product scope
Check the direct or indirect data connection, EU market activity, separately marketed components, and remote processing needed for product functions. Then test the specific exclusions, including certain regulated medical, vehicle, aviation and marine products, products developed or modified exclusively for national-security or defence purposes, and free and open-source software developed or supplied outside commercial activity.
Role and product class
Identify the manufacturer, authorised representative, importer, distributor, or open-source software steward. One organisation can hold more than one role, while own-branding or a can make an importer or distributor the manufacturer. Then classify the product as default, important class I, important class II, or critical.
Obligations, evidence and dates
Tie the cybersecurity risk assessment, Annex I requirements, component due diligence, SBOM, disclosure and update processes, support-period rationale, technical documentation, conformity assessment, EU declaration and to one product record. reporting starts on 11 September 2026, including for in-scope products placed on the market before 11 December 2027. The remaining requirements generally apply from 11 December 2027, subject to the transition rule for products already placed on the market. Reassess the record when the intended purpose, product functions, remote processing, brand owner, EU market route, listed product category, or post-market modification changes.
Classify product
Map duties
Prepare evidence
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Mar 4, 2026
Updated
Jul 31, 2026

Start with the product boundary and exclusions, then classify the product, assign the economic-operator roles, map Annex I and lifecycle duties, choose the conformity route, and prepare for reporting from 11 September 2026 and general application from 11 December 2027.

Focused CRA guidance

Open the guide for your product decision

Use these focused answers for classification, conformity assessment, open-source scope, and reporting under the EU Cyber Resilience Act (CRA). The complete guide library remains available below.

Decide whether a notified body is needed

Start with the product category and conformity route. A is an independent organization designated by an EU country to assess specified products and procedures. Most ordinary products can use the manufacturer's internal-control route, so a notified body is not always required.

Read the notified-body answer

Choose the conformity route

Connect the product category to the permitted route. is the manufacturer's internal control. combines an EU-type examination with production checks. is full quality assurance under notified-body oversight. Record the selected route, EU declaration of conformity, and basis.

Review conformity assessment

Understand Module H

is the full-quality-assurance route. A approves and monitors the manufacturer's quality system, while the manufacturer remains responsible for each product's conformity and the supporting technical documentation.

Read the Module H answer

Check open-source software scope

Free and open-source software lets people inspect, use, change, and redistribute its source code. Separate non-commercial publication from commercial market activity, then identify whether the organization acts as a contributor, open-source software steward, or product manufacturer.

Review open-source scope

Prepare for Article 14 reporting

requires manufacturers to report an and a severe incident when the relevant test is met. Those reporting duties start on 11 September 2026; most other CRA duties apply from 11 December 2027. Keep the two dates and reporting tests separate.

Review Article 14 reporting
CRA Timeline

Key dates for Cyber Resilience Act implementation

Track the staged application of Chapter IV notified-body rules from 11 June 2026, reporting from 11 September 2026, the main CRA obligations from 11 December 2027, and the related transition rules for products already placed on the market.

Loading timeline...
Recommended reading path

Choose the next CRA decision

New to the CRA? Start with scope. If the product is already scoped, jump to requirements, evidence and market access, vulnerability operations and deadlines, or a focused comparison or question.

2

Requirements and operating model

Translate Annex I and economic-operator duties into a product-level compliance program.

3

Evidence and EU market access

Build the release file, select the conformity route, and connect technical evidence to the declaration and CE marking.

4

Vulnerability operations, reporting and deadlines

Run support-period vulnerability handling, triage Article 14 events, track staged application dates, and understand enforcement exposure.

Next step

Turn CRA product scope into owned security and conformity work

This hub is the shared entry point for CRA product classification, vulnerability-handling design, reporting readiness, technical documentation, conformity assessment, , and importer or distributor checks.

What this unlocks
  • Start with one product model, software release, component, or remote processing dependency and record the intended purpose, foreseeable use, EU market path, placement date, economic-operator role, classification, and reassessment triggers.
  • Use Assessment Autopilot to request the cybersecurity risk assessment, Annex I mapping, SBOM record, support-period rationale, coordinated disclosure policy, update-delivery evidence, tests, and EU declaration of conformity.
  • Use Research Copilot for cited questions about product scope, remote data processing, open-source components, important or critical product classification, reporting, and conformity assessment modules.
  • Keep legal interpretation, engineering evidence, supplier records, release approvals, user information, vulnerability reports, and reassessment triggers connected to the same product file.
Cyber Resilience Act artifact preview
Share it internally
Download the timeline export to align legal, product, engineering, and commercial teams on milestones and deadlines.