Decide whether software, hardware, a separately marketed component, or necessary remote processing is a under the CRA (Regulation (EU) 2024/2847), which regulated role you hold, and what must happen before EU market placement and during the .
The CRA is about products with digital elements, including software, hardware, separately marketed components, and remote processing that the product needs for its functions.
Build the product security file
Keep the risk assessment, Annex I requirement mapping, vulnerability-handling process, SBOM record, support-period rationale, user instructions, tests, and conformity evidence together.
Route CE and reporting work early
reporting applies before the main application date. Conformity assessment and depend on whether the product is outside the important and critical categories, important class I, important class II, or critical, and on the standards, common specifications, or certification route used.
Use the timeline and topic guides to move from product classification to release gates, security-update operations, reporting readiness, and market-surveillance evidence.
Key dates
Annex I
Security
Art. 14
Reporting
Art. 32
Conformity
CE
Marking
What the hub helps you check
Product scope
Check the direct or indirect data connection, EU market activity, separately marketed components, and remote processing needed for product functions. Then test the specific exclusions, including certain regulated medical, vehicle, aviation and marine products, products developed or modified exclusively for national-security or defence purposes, and free and open-source software developed or supplied outside commercial activity.
Role and product class
Identify the manufacturer, authorised representative, importer, distributor, or open-source software steward. One organisation can hold more than one role, while own-branding or a can make an importer or distributor the manufacturer. Then classify the product as default, important class I, important class II, or critical.
Obligations, evidence and dates
Tie the cybersecurity risk assessment, Annex I requirements, component due diligence, SBOM, disclosure and update processes, support-period rationale, technical documentation, conformity assessment, EU declaration and to one product record. reporting starts on 11 September 2026, including for in-scope products placed on the market before 11 December 2027. The remaining requirements generally apply from 11 December 2027, subject to the transition rule for products already placed on the market. Reassess the record when the intended purpose, product functions, remote processing, brand owner, EU market route, listed product category, or post-market modification changes.
Classify product
Map duties
Prepare evidence
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Mar 4, 2026
Updated
Jul 31, 2026
Start with the product boundary and exclusions, then classify the product, assign the economic-operator roles, map Annex I and lifecycle duties, choose the conformity route, and prepare for reporting from 11 September 2026 and general application from 11 December 2027.
Focused CRA guidance
Open the guide for your product decision
Use these focused answers for classification, conformity assessment, open-source scope, and reporting under the EU Cyber Resilience Act (CRA). The complete guide library remains available below.
Decide whether a notified body is needed
Start with the product category and conformity route. A is an independent organization designated by an EU country to assess specified products and procedures. Most ordinary products can use the manufacturer's internal-control route, so a notified body is not always required.
Connect the product category to the permitted route. is the manufacturer's internal control. combines an EU-type examination with production checks. is full quality assurance under notified-body oversight. Record the selected route, EU declaration of conformity, and basis.
is the full-quality-assurance route. A approves and monitors the manufacturer's quality system, while the manufacturer remains responsible for each product's conformity and the supporting technical documentation.
Free and open-source software lets people inspect, use, change, and redistribute its source code. Separate non-commercial publication from commercial market activity, then identify whether the organization acts as a contributor, open-source software steward, or product manufacturer.
requires manufacturers to report an and a severe incident when the relevant test is met. Those reporting duties start on 11 September 2026; most other CRA duties apply from 11 December 2027. Keep the two dates and reporting tests separate.
Track the staged application of Chapter IV notified-body rules from 11 June 2026, reporting from 11 September 2026, the main CRA obligations from 11 December 2027, and the related transition rules for products already placed on the market.
Loading timeline...
Recommended reading path
Choose the next CRA decision
New to the CRA? Start with scope. If the product is already scoped, jump to requirements, evidence and market access, vulnerability operations and deadlines, or a focused comparison or question.
1
Start here: scope and product boundary
Decide whether the CRA applies to the product, market activity and software or service boundary before assigning controls.
Turn CRA product scope into owned security and conformity work
This hub is the shared entry point for CRA product classification, vulnerability-handling design, reporting readiness, technical documentation, conformity assessment, , and importer or distributor checks.
What this unlocks
Start with one product model, software release, component, or remote processing dependency and record the intended purpose, foreseeable use, EU market path, placement date, economic-operator role, classification, and reassessment triggers.
Use Assessment Autopilot to request the cybersecurity risk assessment, Annex I mapping, SBOM record, support-period rationale, coordinated disclosure policy, update-delivery evidence, tests, and EU declaration of conformity.
Use Research Copilot for cited questions about product scope, remote data processing, open-source components, important or critical product classification, reporting, and conformity assessment modules.
Keep legal interpretation, engineering evidence, supplier records, release approvals, user information, vulnerability reports, and reassessment triggers connected to the same product file.