CRA · 18 Jul 2026

Am I in scope for the CRA? The five questions that decide it.

Nearly every conversation we have with a manufacturer starts in the same place: does this law actually apply to us? Fair question. The Cyber Resilience Act is a long regulation, but the scope logic inside it is short. Five questions decide it, and you can answer most of them from memory.

1. Does your product contain software or firmware?

The CRA covers what it calls products with digital elements. That is any hardware product with software inside it, and any software sold as a product in its own right. A temperature sensor with firmware, an industrial controller, a smart lock, a desktop application: all of it qualifies. The definition also pulls in the remote data processing a product depends on. If your device only works with its companion cloud service, that service is treated as part of the product, not as a separate thing you can leave out of scope.

2. Can it connect to anything?

The definition asks whether the product has, or can reasonably be expected to have, a direct or indirect data connection to a device or a network. Indirect is the word doing the work. A machine that never touches the internet but takes a USB stick for firmware updates has a data connection. A sensor that talks only to a local gateway has one too. Products with software but no conceivable data connection exist, but they are rare, and if you are reading this about your product, yours probably is not one of them.

3. Do you sell it in the EU?

The CRA applies to products placed on the EU market in the course of a commercial activity. Where your company sits does not matter. If customers in the EU can buy the product, it is on the EU market, and a manufacturer outside the EU is caught the moment an importer carries the product in.

4. What is your role in the chain?

The manufacturer carries the main obligations: build the product to the essential requirements, run vulnerability handling, keep the documentation. Importers and distributors are not spectators. They must verify the manufacturer did its work, and they share liability if it did not. Two details catch people out. If you sell someone else's device under your own brand, the law treats you as the manufacturer. And if you substantially modify a product you resell, the same happens.

5. Is it already covered by sector law?

Some product families are carved out because their own regimes handle cybersecurity: medical devices, in vitro diagnostics, motor vehicles, civil aviation, marine equipment, and products built for defence or national security. If that is you, your obligations flow through those laws instead. Mixed portfolios need care, because the carve-out follows the product, not the company. The industrial arm of a medical device maker can be fully in scope while the clinical arm is not.

One boundary worth naming: open-source software made available outside a commercial activity sits outside the CRA. Monetising it, or shipping it inside a commercial product, changes that, and the law created a lighter regime for open-source stewards. If your product leans on open-source components, and nearly every product does, the components you ship become your responsibility. That is why the software bill of materials exists.

In scope. What now?

Being in scope means the product must meet the essential requirements: secure by design and by default, shipped without known exploitable vulnerabilities, supplied with security updates across a support period that will normally be at least five years, documented, and carrying a software bill of materials. You need a working process for handling and reporting vulnerabilities, and reporting is already live: since 11 September 2026, actively exploited vulnerabilities and severe incidents must be reported, with an early warning inside 24 hours and follow-ups on a fixed clock.

Compliance is confirmed through a conformity assessment. Most ordinary products can self-assess against the requirements; the categories the law lists as important or critical face stricter routes with third parties involved. Pass, and the product carries its CE mark. The full regime applies from 11 December 2027, and after that date a non-compliant product cannot legally be sold in the EU. Penalties reach 15 million euro or 2.5 percent of worldwide turnover, whichever is higher.

Five questions, five minutes. We built an interactive version of exactly this logic, so you can get an instant read. And if the answer comes back in scope, the next question is the size of the gap between your product and December 2027. That is what a readiness assessment measures, and what the scoping call is for.

Get an instant read on your product, nothing stored or sent. Take the in-scope check →
Already know you are in scope? A readiness assessment sizes the gap. Book a scoping call →

← Back to Insights