- Article 1 excludes products within Regulation (EU) No 168/2013 from the CRA, while preserving CRA coverage for the specified L1e category vehicles designed to pedal.
References and citations
- Draft Commission guidance used only for non-final interpretive examples on remote data processing, open-source commercial activity, support periods, and interaction with other EU legislation.
"remote data processing solutions and free and open-source software"
- Lifecycle security context for IoT manufacturers, developers, integrators, and supply-chain participants.
- Standards-body source for concrete consumer IoT product examples and lifecycle security context; it does not decide CRA scope or classification.
- Commission implementation FAQ used for practical scope examples, including standalone software, firmware, hardware components, direct and indirect connections, websites, SaaS boundaries, own-use tools, and exclusions.
"products with digital elements"
- Commission policy overview confirming that the CRA applies to connectable software and hardware products, introduces manufacturer cybersecurity requirements, and uses CE marking and national market surveillance for enforcement.
"connectable hardware and software"
- Primary source for product scope, remote data processing, components, and important and critical product categories.
- Primary legal source for Article 2 scope and exclusions, Article 3 definitions, manufacturer and economic-operator roles, component due diligence, and open-source steward obligations.
"software or hardware product and its remote data processing solutions"