The most common question after a talk on the Cyber Resilience Act is not about the scope of obligations but about whether the regulation applies at all. The five questions below settle it.

1. Does the product have digital elements?

The regulation covers products with digital elements, meaning hardware or software capable of being connected, directly or indirectly, to a device or a network.

An automotive control unit board with test leads clipped to it
An automotive control unit wired to a diagnostic interface. The digital element here is both the chip and the firmware running on it.

The word indirectly carries weight. A sensor with no network interface of its own that works through a gateway is in scope. So is a desktop application, if it communicates with anything at all.

A negative answer ends the analysis. A positive one leads to question two.

2. Do you place it on the EU market commercially?

What counts is the market, not where the company is established. A manufacturer outside the Union selling into Poland is covered on the same terms as a domestic supplier.

Open source software developed non-commercially stays outside the scope. The boundary is less obvious than it looks: paid support, a commercial edition or selling services around your own project can be enough to bring it in.

3. Is the product outside sectoral regulation?

The Cyber Resilience Act gives way to more specific legislation. Outside its scope are, among others:

  • medical devices covered by the MDR and IVDR;
  • vehicles type approved under UN R155 and R156;
  • civil aviation;
  • marine equipment covered by separate rules.

Products at the boundary need attention. An accessory to a medical device that is not itself a medical device remains in scope of the regulation. The same applies to an electric vehicle charger, while the vehicle itself falls under separate rules.

4. What is your role in the supply chain?

RoleWhenPrimary obligation
Manufacturerselling under your own brandfull conformity, documentation, reporting
Importerplacing a product from outside the EUverifying the manufacturer's conformity
Distributormaking available on the marketchecking marking and documents

An important principle applies here: a substantial modification of the product, or selling it under your own brand, makes you the manufacturer, regardless of who physically produced the device. Acting as an integrator does not remove the obligations.

5. Which category does the product fall into?

The category determines whether self assessment suffices or a notified body has to be involved.

CategoryExamplesConformity assessment
Defaultsensors, simple electronics, most consumer productsself assessment
Important, class Ipassword managers, VPN, home routers, IdM systemsself assessment under a harmonised standard
Important, class IIfirewalls, IDS/IPS, hypervisors, tamper-resistant microprocessorsthird party involvement
Criticalsecurity boxes, smart meter gateways, smartcardsEuropean certification

Most IoT devices land in the default category. This simplifies the formal path but does not lower the technical requirements. Self assessment means only that there is no external verification before launch.

Conclusions and next steps

Positive answers to questions one and two, with no sectoral exclusion under question three, mean the product is covered. The order of work then looks as follows:

  1. Establish the category, which determines budget and schedule.
  2. Check the deadlines. The vulnerability reporting duty applies from 11 September 2026, full application of the regulation from 11 December 2027.
  3. Produce an SBOM for one product to gauge the scale of the work.

The full set of requirements is covered in what the CRA requires from manufacturers, and preparing the reporting process in a separate article.

Doubts most often concern products sitting at the edge of sectoral regulation. In that case get in touch and we will work through the case together.


This text is informational and does not replace legal analysis for a specific product.