The EU Cyber Resilience Act, Regulation (EU) 2024/2847, applies to products with digital elements that are made available on the EU market, meaning software and hardware whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. If you manufacture, import or distribute such a product for the EU market, you are very likely in scope. The main obligations apply from 11 December 2027.
The Regulation covers both software and hardware with digital elements, together with their remote data processing solutions where those are necessary for the product to perform its functions. In practice this reaches operating systems, applications, firmware, connected consumer devices, industrial components, and the libraries and modules built into them.
A few tests help you decide:
If the answer to both is yes, treat the product as in scope until you can point to a specific exclusion.
The CRA assigns duties by role, and the same organisation can hold more than one role across its portfolio.
If you substantially modify a product already on the market, you may take on manufacturer obligations for the modified product.
Most products follow the default conformity route, but two elevated categories carry stricter assessment. Annex III lists "important" products and Annex IV lists "critical" products, and these trigger stricter conformity assessment routes because of the risk they present. Commission Implementing Regulation (EU) 2025/2392 of 28 November 2025 sets out the technical descriptions of those categories, so consult it when you suspect your product sits in one of them.
Some products are governed by other, more specific EU regimes and are excluded or partly excluded from the CRA. The CRA excludes products governed by the EU Medical Devices and In-vitro Diagnostic Medical Devices Regulations, products covered by specified motor-vehicle legislation, products certified under the EU civil-aviation regime, and marine equipment covered by Directive 2014/90/EU; Article 2 also excludes specified spare parts and national-security, defence and classified-information products, while allowing the Commission to limit CRA application where equivalent or stronger sectoral cybersecurity rules apply.
The treatment of software as a service is nuanced. The CRA is a product regulation and focuses on products placed on the market rather than on pure services. The CRA does not automatically exclude cloud functionality or SaaS: manufacturer-controlled remote processing forms part of a product with digital elements where its absence would prevent the product performing one of its functions, whereas a stand-alone cloud or SaaS service that does not meet that dependency test remains outside the CRA product definition and may instead fall within NIS2.
CRANIS2 maps your product portfolio against CRA roles and product classes so you can see, per product, whether you are acting as a manufacturer, importer or distributor and which conformity route applies. It flags likely "important" or "critical" candidates for closer review and keeps the reasoning on record. Start by running a scope assessment for your products at our conformity assessment tool.
The Regulation treats non-commercial open source development differently from commercial supply, through the concept of the open source software steward, and stewards cannot be fined for a CRA infringement. Commercial products that incorporate open source components are still in scope for the manufacturer placing them on the market.
The CRA governs products made available on the EU market. If none of your products are placed on or made available on the EU market, the CRA does not apply to them, though you should keep the position under review if you expand.
Under the transitional rule in Article 69, products placed on the market before 11 December 2027 fall under the full requirements only if they are substantially modified after that date. The reporting obligations, however, apply regardless.
Related guides: CRA compliance checklist for manufacturers and CRA timeline of key deadlines.