Is your product in scope of the CRA?
Four quick steps to see, indicatively, whether the Cyber Resilience Act applies to your product and in which class — with the minimum obligations and the technical file you will need.
Step 1/4
How the Cyber Resilience Act classifies products
Four tiers, one rule: what the product does decides, not how big the company making it is. The class decides the conformity route, not the reporting duties — those apply to everyone.
Regulation (EU) 2024/2847 splits products with digital elements into four sets. The first is the rule, the other three are listed exceptions: Annex III names the "important" products in two classes, Annex IV the "critical" ones. Outside those lists you are in the default category.
Default category: the rule, not the exception
This is where the large majority of connected products land. The manufacturer self-assesses conformity through an internal control module: no external body, no certification. The obligations stay whole — Annex I essential requirements, vulnerability-handling process, technical documentation, EU declaration of conformity, CE marking. \u201cSelf-assess\u201d does not mean \u201cfewer duties\u201d: it means you produce the evidence yourself.
Important products, class I (Annex III)
Products whose compromise opens the way to others: browsers, password managers, antivirus, VPNs, operating systems, routers, SIEM systems, connected toys with location tracking. You can stay in self-assessment, but by applying the relevant harmonised standards where they exist; otherwise you go through a type examination with a notified body. The difference from the default category is not the number of obligations: it is how demonstrable the way you met them has to be.
Important products, class II (Annex III)
A short list: hypervisors and container runtimes, firewalls and IDS/IPS systems, tamper-resistant microprocessors and microcontrollers. Third-party assessment is typically mandatory here. It is the class that reshapes release plans more than any other, because a notified body's calendar is not yours to set: realising you are here three months before launch is already a scheduling problem.
Critical products (Annex IV)
Hardware devices with security boxes, smart meter gateways, smartcards and secure elements. For these the Commission can make a European cybersecurity certification mandatory at \u201csubstantial\u201d level or above — the EUCC scheme is today's reference. It is the longest route and the most documentation-heavy.
What decides the class
The product's core functionality, not the sector you sell into nor your turnover. A microcontroller becomes \u201cimportant\u201d if it carries security functions; the same part without them stays in the default category. It is a reading made on the real product, component by component, and in borderline cases one to take to an expert: the definitive classification remains the manufacturer's responsibility.
The terms this tool uses — product with digital elements, manufacturer, support period, important product, critical product — are defined in the glossary, each next to its article of the Regulation.
What the class does not change
The Art. 14 reporting obligations do not depend on the class. Twenty-four hours for the early warning, seventy-two for the vulnerability notification, then the final report: they apply to the default category exactly as they apply to critical products, and they apply to products already on the market. The class decides how you demonstrate conformity; Art. 14 decides what you do on the day somebody exploits one of your vulnerabilities.
The chain of deadlines, and the two events that start it, is on the Art. 14 page.
What this tool does not do
It does not produce a classification valid before an authority and it does not replace a conformity assessment. It follows the Regulation's decision tree over the answers you give, and tells you where those answers land: if an answer is imprecise, so is the result. It is there to orient you in five minutes and to show you which questions to bring to the people who do compliance for a living.