FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
856of856items
Across 40 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
Mar 10, 2026
Updated
Jul 24, 2026
CRA Important and Critical Products

Can a manufacturer use product naming or documentation to avoid the stricter route?

No. The draft Commission guidance says the manufacturer may not misrepresent core functionality to escape the applicable conformity assessment regime.

Classification evidence should therefore align the product's instructions for use, promotional materials, sales statements, technical documentation, intended purpose, technical capabilities, and chosen conformity route. Inconsistencies between those records are a warning sign, especially for products close to Annex III or Annex IV categories.

Citations
Cyber Resilience Act

Annex VII requires technical documentation to include intended purpose and the conformity assessment procedure followed.

CRA Important and Critical Products

What should an important-or-critical classification record contain?

Record the product boundary, intended purpose, main features and technical capabilities, selected core functionality, and the exact Annex III or Annex IV category considered. Map those facts to the corresponding technical description in Implementing Regulation (EU) 2025/2392 and explain both matches and material non-matches.

Then record the class, the Article 32 conformity route, and the evidence that makes that route available. For class I, identify the exact harmonised standards, common specifications, or qualifying certification coverage relied on for the relevant requirements; partial or missing coverage can require module B plus C or module H. Keep the decision aligned with instructions, marketing, technical documentation, and later product changes.

Citations
Cyber Resilience Act

Articles 7, 8, 27, and 32 and Annexes III, IV, and VII connect core-functionality classification, evidence coverage, conformity route, and technical documentation.

CRA Integrated Components and Dependencies

What is the difference under the Cyber Resilience Act between an integrated component, a remote data processing solution, and an external dependency?

Under the CRA, an integrated component is a software or hardware component that forms part of the product with digital elements. A remote data processing solution can also form part of the product where it meets the Article 3(2) definition. An outside system or service may remain an external dependency rather than part of the product itself.

The consequence is different in each case:

- integrated components are part of the product and trigger due diligence under Article 13(5)

- remote data processing solutions that meet the CRA definition are also part of the product

- outside systems may remain external dependencies, but their risks still have to be considered in the cybersecurity risk assessment and mitigated through product-level measures

Citations
CRA Integrated Components and Dependencies

Under the Cyber Resilience Act, does the manufacturer remain responsible for the cybersecurity of the whole product when it integrates third-party components?

Yes.

The CRA places the compliance obligation on the manufacturer of the finished product. The Commission FAQ is explicit that vulnerability-handling obligations apply to the product in its entirety, including integrated components.

Citations
CRA Integrated Components and Dependencies

Are Cyber Resilience Act cybersecurity risk assessment and component due diligence the same obligation?

No.

The draft guidance treats them as distinct but complementary obligations. The cybersecurity risk assessment covers risks affecting the product, including risks originating outside the product. Due diligence under Article 13(5) is the additional obligation to verify, in a risk-based way, that third-party integrated components do not undermine the product's compliance.

CRA Integrated Components and Dependencies

What does due diligence mean under the Cyber Resilience Act when integrating third-party components?

It means taking appropriate, risk-based steps so that the integrated components do not compromise the cybersecurity of the product.

Recital 34 and the Commission FAQ give examples such as checking whether the component already bears the CE marking, checking whether it receives regular security updates, checking relevant vulnerability databases, and carrying out additional security tests where appropriate.

The Commission FAQ also lists practical due-diligence evidence that is useful for third-party software: software composition analysis, reviewing the component's SBOM when available, checking the component support period, verifying that the component's intended purpose fits the integrating manufacturer's use, and assessing the component manufacturer's security posture.

Citations
CRA Integrated Components and Dependencies

Does the Cyber Resilience Act require SBOM-style evidence for integrated components and dependencies?

Yes, as part of vulnerability handling and technical documentation, but the CRA does not turn every SBOM into a public artifact.

Annex I Part II requires manufacturers to identify and document vulnerabilities and components contained in products with digital elements, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at least the top-level dependencies. Annex VII also lists the SBOM as part of the vulnerability-handling information in technical documentation, and Annex II only requires user-facing access information if the manufacturer decides to make the SBOM available to users.

For integrated components, maintain a component inventory tied to vulnerability handling, support-period checks, update evidence, third-party documentation, and the risk assessment. The CRA does not require the full SBOM to be published in every case.

Citations
Cyber Resilience Act

Annex I Part II point 1 requires component and vulnerability documentation, Annex VII includes SBOM in technical documentation, and Annex II addresses user access only where the manufacturer makes the SBOM available.

CRA Integrated Components and Dependencies

Under the Cyber Resilience Act, does a CE-marked component automatically make the finished product compliant?

No.

The Blue Guide explains that CE-marked components do not automatically guarantee that the finished product also complies. In the CRA context, a CE-marked component can support the integrating manufacturer's assessment, but the integrating manufacturer still has to ensure that the finished product complies as a whole.

Citations
CRA Integrated Components and Dependencies

Can a manufacturer integrate components that are not CE-marked under the Cyber Resilience Act?

Yes.

The CRA does not require manufacturers to integrate only CE-marked components. Manufacturers can integrate components that are outside the CRA, that were placed on the market before the CRA applies, or that were never placed on the market as CRA products. But they still have to exercise due diligence and ensure that the finished product complies.

Citations
CRA Integrated Components and Dependencies

Can the integrating manufacturer rely on the component manufacturer's own Cyber Resilience Act work?

Partly, but not completely.

The Commission FAQ says that where the component is itself subject to the CRA, the integrating manufacturer can rely in part on the component manufacturer's lifecycle work, such as its vulnerability handling and conformity documentation. But that does not transfer the finished-product manufacturer's own obligations.

Citations
CRA Integrated Components and Dependencies

Under the Cyber Resilience Act, do vulnerability-handling obligations extend to integrated components?

Yes.

Recital 34 and the Commission FAQ say that the CRA vulnerability-handling obligations apply to the product in its entirety, including all integrated components.

Citations
CRA Integrated Components and Dependencies

Under the Cyber Resilience Act, what must a manufacturer do if it finds a vulnerability in an integrated component?

The CRA expects more than just recording the issue.

Article 13(6) and recital 34 require the manufacturer to inform the person or entity manufacturing or maintaining the component, address and remediate the vulnerability, and, where applicable, provide that person or entity with the applied security fix.

Citations
CRA Integrated Components and Dependencies

What happens under the Cyber Resilience Act if an integrated component stops receiving support before the finished product's support period ends?

That does not end the finished-product manufacturer's duties.

The Commission FAQ says the manufacturer must comply with the vulnerability-handling obligations for the duration of the product's own support period, for the product in its entirety, including integrated components. If the upstream component is no longer supported, the manufacturer may still need to patch it, replace it, disable affected functions, or mitigate the risk through other means.

Citations
CRA Integrated Components and Dependencies

Must the Cyber Resilience Act risk assessment also consider risks from outside systems that are not themselves part of the product?

Yes.

The draft guidance says the cybersecurity risk assessment must cover relevant risks that originate outside the product itself, such as external networks, environmental factors, infrastructure, or other systems on which the product relies. The CRA then requires those risks to be mitigated through product-level measures rather than by imposing obligations on the outside environment.

CRA Integrated Components and Dependencies

How should a manufacturer treat third-party SaaS or cloud services that a Cyber Resilience Act product relies on?

It depends on whether the service qualifies as a remote data processing solution.

If the relevant software is designed and developed by the manufacturer or under its responsibility, and its absence would prevent the product from performing one of its functions, it can be part of the product as RDPS. If that second condition is met but the software is a third-party solution not designed and developed by the manufacturer or under its responsibility, the draft guidance says it should be treated similarly to a third-party component: the manufacturer must assess the integration risk and exercise due diligence.

Citations
Page 15 of 58