FAQ HubEUCyber Resilience Act

EU Cyber Resilience Act FAQ

Browse focused CRA FAQ modules built around the questions that usually slow market access, product launch, conformity work, and component governance.

Each sub-FAQ is grounded in official sources and designed for legal, compliance, product, engineering, and security teams.

Author
Sorena AI
Published
Mar 10, 2026
Updated
Mar 10, 2026
FAQ modules
40

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Mar 10, 2026
Updated Mar 10, 2026
Overview

Use this FAQ hub when the general CRA page is too broad and you need a tighter answer set. The sub-FAQs below group high-friction questions into practical modules so teams can move faster on interpretation, evidence design, and release decisions without losing source traceability.

Browse sub-FAQs

Choose the CRA question set you need

These focused FAQ modules break the CRA into narrower answer sets so teams can move straight to the right source-backed guidance.

Browse all FAQ items1072
Focused FAQ modules
40
Showing 40 of 40
FAQ module

CRA Blue Guide Concepts FAQ | Placing on the Market, Making Available, Distance Sales

CRA FAQ on Blue Guide concepts used in Cyber Resilience Act interpretation: placing on the market, making available, putting into service, online sales.

28 items
FAQ module

CRA CE Marking FAQ | Meaning, Placement Rules, Software Labeling, Notified Bodies

CRA CE marking FAQ covering what the mark means, when it is mandatory, software and website placement rules, packaging fallback, notified body numbers.

26 items
FAQ module

CRA Component Due Diligence FAQ | Third-Party Components, FOSS, SBOM, Vulnerabilities

CRA component due diligence FAQ covering third-party components, FOSS, CE-marked components, SBOM review, risk-based checks, upstream vulnerability reporting.

21 items
FAQ module

CRA Conformity Assessment Routes FAQ | Module A, Module B+C, Module H, Critical and Important Products

CRA FAQ on conformity assessment routes covering module A, module B+C, module H, important and critical products, harmonised standards, certification schemes.

25 items
FAQ module

CRA Core Functionality FAQ | Important Products, Critical Products, Classification

CRA FAQ on core functionality covering classification of important and critical products, ancillary functions, integrated components.

21 items
FAQ module

CRA Cybersecurity Risk Assessment FAQ | Article 13, Threat Modelling, Variants, Constraints

CRA FAQ on cybersecurity risk assessment covering Article 13, threat modelling, intended purpose, foreseeable misuse, external dependencies, documentation.

26 items
FAQ module

CRA Declaration of Conformity FAQ | Full vs Simplified, Languages, Updates, Duties

CRA FAQ on the EU declaration of conformity covering full and simplified formats, required contents, languages, updates, single declarations across EU laws.

19 items
FAQ module

CRA Economic Operators FAQ | Manufacturers, Importers, Distributors, Authorised Representatives

CRA FAQ on economic operators covering manufacturer, authorised representative, importer, distributor, responsible operator rules, checks, traceability.

26 items
FAQ module

CRA Essential Cybersecurity Requirements FAQ | Annex I Part I and Part II

CRA FAQ on the essential cybersecurity requirements covering Annex I Part I and Part II, applicability, evidence, interoperability constraints.

20 items
FAQ module

CRA Hardware and Software Boundaries FAQ | Product Scope, Combined Products, Source Code

CRA FAQ on hardware and software boundaries covering combined products, standalone software, source code, companion apps, remote data processing.

26 items
FAQ module

CRA Harmonised Standards and Common Specifications FAQ | Presumption of Conformity, OJ Publication

CRA FAQ on harmonised standards, common specifications, and certification schemes covering presumption of conformity, Official Journal publication.

24 items
FAQ module

CRA Important and Critical Products FAQ | Annex III, Annex IV, Core Functionality

CRA FAQ on important and critical products covering Annex III and Annex IV classification, core functionality, conformity routes, FOSS rule limits.

30 items
FAQ module

CRA Integrated Components and Dependencies FAQ | Due Diligence, RDPS, Third-Party Components

CRA FAQ on integrated components and dependencies covering due diligence, third-party components, RDPS, cloud dependencies, upstream fixes, FOSS dependencies.

21 items
FAQ module

CRA Interplay With Other EU Laws FAQ | RED, AI Act, GDPR, Data Act, EHDS, Machinery

CRA FAQ on interplay with other EU laws covering exclusions, overlap with RED, AI Act, GDPR, Data Act, EHDS, Machinery, GPSR, NIS2, aviation, marine.

25 items
FAQ module

CRA Known Exploitable Vulnerabilities at Launch FAQ | Placement on the Market, CVEs, Late Discoveries

CRA FAQ on known exploitable vulnerabilities at launch covering the launch-time rule, exploitability, known vulnerabilities, CVEs, compensating controls.

18 items
FAQ module

CRA Legacy Products FAQ | Pre-2027 Products, Reporting, Grandfathering, Substantial Modification

CRA FAQ on legacy products covering pre-11 December 2027 products, Article 14 reporting, continued sale, substantial modification, spare parts, old designs.

21 items
FAQ module

CRA Manufacturer Obligations FAQ | Article 13 Duties, Support Period, Reporting, Documentation

CRA FAQ on manufacturer obligations covering Article 13 duties, risk assessment, support periods, vulnerability handling, reporting, documentation.

41 items
FAQ module

CRA Market Surveillance and Enforcement FAQ | Authorities, Safeguards, Sweeps, Formal Non-Compliance

CRA FAQ on market surveillance and enforcement covering authorities, investigations, safeguard procedures, formal non-compliance, sweeps, joint activities.

39 items
FAQ module

CRA Module A FAQ | Internal Control, Self-Assessment, Eligibility, Documentation

CRA FAQ on module A covering internal control, eligible products, class I limits, FOSS exception, technical documentation, testing, CE marking.

28 items
FAQ module

CRA Module B+C FAQ | EU-Type Examination, Conformity to Type, Notified Bodies

CRA FAQ on module B+C covering EU-type examination, conformity to type, notified-body role, certificate changes, production control, CE marking.

32 items
FAQ module

CRA Module H FAQ | Full Quality Assurance, Notified Body Surveillance, CE Marking

CRA FAQ on module H covering full quality assurance, quality-system approval, notified-body surveillance, scope changes, CE marking, language rules, records.

31 items
FAQ module

CRA Notified Bodies FAQ | Notification, Scope, NANDO, Independence, Competence

CRA FAQ on notified bodies covering notification, competence, independence, NANDO scope, accreditation, cross-border choice, subcontracting.

35 items
FAQ module

CRA Open-Source Software FAQ | FOSS, Commercial Activity, Stewards, Donations, Paid Editions

CRA FAQ on open-source software covering FOSS qualification, commercial activity, donations, paid support, stewards, contributors, repositories.

39 items
FAQ module

CRA Over-the-Air Updates FAQ | OTA, Automatic Updates, Secure Distribution, Offline Paths

CRA FAQ on over-the-air updates covering OTA versus automatic updates, secure distribution, screenless products, gateways, offline update paths.

25 items
FAQ module

CRA Penalties and Fines FAQ | Fine Tiers, Turnover Caps, SME Carve-Outs, Stewards

CRA FAQ on penalties and fines covering Article 64 fine tiers, turnover caps, SME carve-outs, steward exemptions, cumulative fines, criminal sanctions.

23 items
FAQ module

CRA Product Families FAQ | Variants, Shared Assessments, Family Reuse, Conformity Scope

CRA FAQ on product families covering shared risk assessments, family-wide documentation reuse, cybersecurity-relevant variant differences.

16 items
FAQ module

CRA Remote Data Processing Solutions FAQ | RDPS Scope, Cloud Services, SaaS Boundaries, Documentation

CRA FAQ on remote data processing solutions covering Article 3(2) RDPS tests, cloud-service boundaries, websites and portals, third-party SaaS, backend scope.

21 items
FAQ module

CRA Repairs and Spare Parts FAQ | Repairs, Refurbishment, Spare-Part Exemption, Compatibility

CRA FAQ on repairs and spare parts covering substantial modification, Article 2(6) identical spare parts, non-identical replacements.

18 items
FAQ module

CRA Reporting Obligations FAQ | Article 14 Deadlines, CSIRT Filing, User Notices, Legacy Products

CRA FAQ on reporting obligations covering Article 14 deadlines, actively exploited vulnerabilities, severe incidents, CSIRT routing, user notifications.

35 items
FAQ module

CRA Scope FAQ | Products with Digital Elements, Connections, Software, Exclusions

CRA FAQ on scope and products with digital elements covering software, firmware, components, direct and indirect connections, offline products, exclusions.

30 items
FAQ module

CRA Secure-by-Default FAQ | Default Configuration, Auto Updates, Tailor-Made Limits

CRA FAQ on secure by default covering Annex I default configuration, automatic security updates, opt-outs, components, inapplicability.

18 items
FAQ module

CRA Security Updates vs Functionality Updates FAQ | Separation, Free Updates, Article 13(10)

CRA FAQ on security updates versus functionality updates covering separation where technically feasible, free security updates, automatic updates.

24 items
FAQ module

CRA Substantial Modification FAQ | Post-Market Changes, New Manufacturer, Legacy Products

CRA FAQ on substantial modification covering Article 3(30), software updates, repairs, new manufacturer status, conformity reassessment.

27 items
FAQ module

CRA Support Period FAQ | Placement on the Market, Unit-Level Timing, Update Availability

CRA FAQ on support periods covering Article 13(8), placement on the market timing, unit-level support periods, standalone software, update availability.

71 items
FAQ module

CRA Tailor-Made Products FAQ | Business-User Exception, Paid Updates, Evidence

CRA FAQ on tailor-made products covering the narrow business-user carve-out, secure-by-default and paid-update deviations, required evidence.

17 items
FAQ module

CRA Technical Documentation FAQ | Annex VII, Languages, Authority Access, Updates

CRA FAQ on technical documentation covering Annex VII content, timing, languages, versioning, authority access, reused documentation, simplified formats.

21 items
FAQ module

CRA Transition Period FAQ | Key Dates, Legacy Products, Pre-CRA Stock, RED Interplay

CRA FAQ on the transition period covering entry into force, phased application dates, legacy products, stock and customs timing, standalone software.

23 items
FAQ module

CRA Update Availability and Archives FAQ | Article 13(9), Archives, Historical Versions

CRA FAQ on update availability and software archives covering Article 13(9), Article 13(10), Article 13(11), retention of issued security updates.

24 items
FAQ module

CRA User Information and Transparency FAQ | Annex II, Support Disclosure, User Notices

CRA FAQ on user information and transparency covering Annex II instructions, support-period disclosure, end-of-support notices, vulnerability notices.

28 items
FAQ module

CRA Vulnerability Handling FAQ | Lifecycle Duties, Components, Disclosure, Fix Sharing

CRA FAQ on vulnerability handling covering Annex I Part II duties, component vulnerabilities, upstream reporting and fix sharing.

29 items
Primary sources

References and citations

ec.europa.eu
Referenced sections
  • Core New Legislative Framework concepts used for CRA market-access interpretation and CE marking context.
data.europa.eu
Referenced sections
  • Primary legal text for scope, conformity, CE marking, due diligence, and vulnerability handling.
Related guides

Explore more topics

Applicability Test | EU Cyber Resilience Act, CRA Product Security and CE Marking
Use this CRA applicability test to confirm product scope, exclusions, remote data processing boundaries, operator role, product classification.
Checklist | EU Cyber Resilience Act, CRA Product Security and CE Marking
Use this Cyber Resilience Act checklist to assign owners, deadlines, evidence, and release gates for scope, Annex I controls, support period operations.
Compliance Program | EU Cyber Resilience Act, CRA Product Security and CE Marking
Build a CRA compliance program that covers product scope, governance, engineering controls, support period operations, Article 14 reporting.
Conformity Assessment and CE Marking | EU Cyber Resilience Act, CRA Product Security and CE Marking
Choose the right CRA conformity route, prepare the declaration of conformity, structure the technical file.
CRA vs RED Cybersecurity Delegated Act | EU Cyber Resilience Act, CRA Product Security and CE Marking
Compare the Cyber Resilience Act with the RED cybersecurity delegated act so you can decide which products fall under which rule, what dates apply.
CRA vs UK PSTI Act | EU Cyber Resilience Act, CRA Product Security and CE Marking
Compare the EU Cyber Resilience Act with the UK PSTI product security regime so your team can plan dual market compliance without mixing two different rule.
Deadlines and Compliance Calendar | EU Cyber Resilience Act, CRA Product Security and CE Marking
Track the CRA entry into force date, the notified body date, the reporting start date, and the main application date.
Essential Cybersecurity Requirements | EU Cyber Resilience Act, CRA Product Security and CE Marking
Understand the CRA essential cybersecurity requirements in Annex I.
Penalties and Fines | EU Cyber Resilience Act, CRA Product Security and CE Marking
Understand the CRA administrative fine tiers in Article 64, the conduct that attracts the highest penalties, and the evidence that reduces enforcement exposure.
Products with Digital Elements Scope | EU Cyber Resilience Act, CRA Product Security and CE Marking
Understand what counts as a product with digital elements under the CRA, how remote data processing fits, and where the scope boundary usually causes mistakes.
Reporting Obligations | EU Cyber Resilience Act, CRA Product Security and CE Marking
Prepare for CRA Article 14 reporting, including the twenty four hour early warning, the seventy two hour notification, final reports, CSIRT routing.
Requirements | EU Cyber Resilience Act, CRA Product Security and CE Marking
Review the full CRA requirement set, including manufacturer duties, operator duties, support period rules, user information, corrective action, reporting.
SBOM and Vulnerability Management Template | EU Cyber Resilience Act, CRA Product Security and CE Marking
Use this CRA SBOM and vulnerability management template to structure dependency records, triage, remediation, advisory publication, and support period evidence.
Technical Documentation and Audit File | EU Cyber Resilience Act, CRA Product Security and CE Marking
Build a CRA technical documentation file that covers product definition, risk assessment, support period, Annex I mapping, standards use, test evidence.
Vulnerability Handling and Disclosure | EU Cyber Resilience Act, CRA Product Security and CE Marking
Build a CRA vulnerability handling system that covers SBOM, intake, triage, remediation, coordinated vulnerability disclosure, secure updates.