The Cyber Resilience Act applies to any product with digital elements made available on the EU market whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. That is Article 2(1) of Regulation (EU) 2024/2847 in one sentence, and every other question about scope is a footnote to it. The sector you operate in does not matter. Whether you charge for the product does not matter. What matters is what the product is, whether it can connect, and whether you supply it in the course of a commercial activity.
The Regulation entered into force on 10 December 2024. Under Article 71, the Article 14 reporting duties apply from 11 September 2026 and the rest of the Regulation from 11 December 2027. Scope is therefore not a question for later. A product that passes the Article 2 test today is inside the reporting duties within days, and Article 69(3) makes that true even for products placed on the market years ago.
| Question | Where the answer lives | Short version |
|---|---|---|
| What is in scope | Article 2(1) | Products with digital elements whose intended or reasonably foreseeable use includes a direct or indirect, logical or physical data connection to a device or network. |
| What a product with digital elements is | Article 3(1) and 3(2) | A software or hardware product and its remote data processing solutions, including components placed on the market separately. |
| What is excluded | Article 2(2) to 2(7) | Products under the medical device, in vitro diagnostic, vehicle type-approval, civil aviation and marine equipment regimes, identical spare parts, and national security or defence products. |
| Who carries duties | Articles 13, 14, 18, 19, 20 and 24 | Manufacturers, authorised representatives, importers and distributors, with a lighter regime for open-source software stewards. |
| What classification changes | Articles 7 and 8, Annexes III and IV | The conformity assessment route. Not whether you are in scope. |
| When it applies | Articles 69 and 71 | Reporting from 11 September 2026, everything else from 11 December 2027, with transitional rules for products already on the market. |
What does the Cyber Resilience Act apply to?
Article 2(1) has four moving parts, and a product has to satisfy all of them.
1. A product with digital elements
Article 3(1) defines this as a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately. The last clause is the one that surprises people. A library, a firmware image or a module sold on its own is a product in its own right, with its own manufacturer. The definition does not require a physical object and it does not require a consumer.
2. A data connection, direct or indirect, logical or physical
The connection can be logical, meaning a virtual data connection implemented through a software interface (Article 3(8)), or physical, through electrical, optical or mechanical interfaces, wires or radio waves (Article 3(9)). It can also be indirect. Article 3(10) covers a connection that does not take place directly but as part of a larger system that is itself directly connectable. A sensor that only ever talks to a gateway is connected for the purposes of the Regulation, because the gateway is.
3. Intended purpose or reasonably foreseeable use
Article 3(23) ties intended purpose to what the manufacturer states in its instructions, marketing and technical documentation. Article 3(24) adds reasonably foreseeable use, which is use that is not necessarily the intended purpose. The practical effect is that a line in the manual saying the product should not be connected to a network does not take the product out of scope if connecting it is something users will foreseeably do.
4. Made available on the market
Article 3(22) defines making available as the supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge. Two things follow. Free products supplied as part of a business are in. Software built and used only inside your own organisation, and never supplied to anyone, is not made available on the market at all. Article 3(21) then defines placing on the market as the first making available, which is the moment most manufacturer duties attach.
Is software as a service inside the CRA?
Mostly no, with one exception that catches product companies. The CRA reaches a product's remote data processing solutions, and Article 3(2) defines remote data processing narrowly: data processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the product with digital elements from performing one of its functions.
The recitals spell out the consequence. Cloud functionality supplied by the manufacturer of a smart home device so that users can control it at a distance is inside the Regulation. Websites that do not support the functionality of a product, and cloud services designed and developed outside the responsibility of a product's manufacturer, are outside it. Software as a Service, Platform as a Service and Infrastructure as a Service are dealt with by Directive (EU) 2022/2555, NIS2, which applies to cloud computing service providers that qualify as medium-sized enterprises or larger.
The working rule: if you ship a product and it stops doing one of its jobs when your back end is down, that back end is part of the product for CRA purposes. If you sell a pure service with no product with digital elements attached, your question is the NIS2 scope test, not this one.
What is carved out of scope?
Article 2 removes six groups, and each exclusion attaches to a legal act rather than to an industry.
| Exclusion | Provision | What it covers |
|---|---|---|
| Medical devices | Article 2(2)(a) and (b) | Products to which Regulation (EU) 2017/745 on medical devices or Regulation (EU) 2017/746 on in vitro diagnostic medical devices apply. |
| Motor vehicles | Article 2(2)(c) | Products to which Regulation (EU) 2019/2144 on type-approval requirements for motor vehicles applies. |
| Civil aviation | Article 2(3) | Products certified in accordance with Regulation (EU) 2018/1139. |
| Marine equipment | Article 2(4) | Equipment within the scope of Directive 2014/90/EU. |
| Spare parts | Article 2(6) | Parts made available to replace identical components, manufactured to the same specifications as the components they replace. |
| National security and defence | Article 2(7) | Products developed or modified exclusively for national security or defence purposes, and products specifically designed to process classified information. |
Article 2(5) adds a mechanism rather than a list. Where other Union rules already address some or all of the Annex I risks, the Commission may by delegated act limit or exclude the application of the CRA, provided the sectoral rules achieve the same or a higher level of protection. Until such an act exists for your products, assume the CRA applies in full.
Read the exclusions the way they are written. A product only leaves the CRA if one of those acts actually applies to it. Being a supplier to a hospital, a carmaker or an airline is not the same thing as making a product that Regulation (EU) 2017/745, 2019/2144 or 2018/1139 applies to.
Who carries the obligations?
Article 3(12) lists the economic operators: the manufacturer, the authorised representative, the importer and the distributor. The definitions decide which one you are, and Article 21 can move you between them.
The manufacturer (Article 3(13)) develops or manufactures a product with digital elements, or has it designed, developed or manufactured, and markets it under its own name or trademark. It carries the Article 13 obligations and the Article 14 reporting duties. The importer (Article 3(16)) is established in the Union and places on the market a product bearing the name or trademark of a person established outside the Union; its duties are in Article 19. The distributor (Article 3(17)) makes a product available without affecting its properties, and its duties are in Article 20. An authorised representative (Article 3(15)) acts on a written mandate from a manufacturer, under Article 18.
Article 21 is the trap. An importer or distributor is treated as the manufacturer, and becomes subject to Articles 13 and 14, where it places a product on the market under its own name or trademark, or carries out a substantial modification of a product already placed on the market. White labelling is therefore manufacturing. Our guide to who must comply with the Cyber Resilience Act sets the three main roles side by side.
Free and open-source software
The Regulation only reaches free and open-source software that is made available on the market, which means supplied for distribution or use in the course of a commercial activity. Software that is published but not made available in that sense sits outside the operator duties. For that software the Regulation creates the open-source software steward (Article 3(14)): a legal person, other than a manufacturer, that systematically provides sustained support for the development of specific open-source products intended for commercial activities. Article 24 gives stewards a light regime: a documented cybersecurity policy, cooperation with market surveillance authorities on request, and the Article 14(1) reporting duty to the extent they are involved in development. A commercial product that bundles open-source components is in scope in full, and its manufacturer carries the duties for the whole product.
Does classification change whether you are in scope?
No. Classification decides the conformity assessment route for a product that is already in scope. Article 7 makes a product an important product with digital elements where it has the core functionality of a category listed in Annex III, and sends it to the conformity assessment procedures in Article 32(2) and (3). Annex III lists 19 categories in class I, from identity management systems, browsers and password managers through operating systems, routers and smart home security products, and four in class II: hypervisors and container runtime systems, firewalls and intrusion detection and prevention systems, tamper-resistant microprocessors and tamper-resistant microcontrollers. Annex IV lists three critical categories: hardware devices with security boxes, smart meter gateways, and smartcards and similar devices including secure elements. Article 8 allows the Commission, by delegated act, to require those to hold a European cybersecurity certificate at assurance level at least substantial.
Two details matter for scoping. Article 7(1) says integrating an important component into a product does not in itself make that product important. And Article 7(4) required the Commission to adopt an implementing act with the technical descriptions of the Annex III and Annex IV categories by 11 December 2025, so check the current version of that act before you settle a boundary case. Everything in scope that is not in Annex III or IV is a default product and self assesses. The cost consequences of each route are in our guide to Cyber Resilience Act compliance cost.
When does scope start to matter?
Article 71 sets three dates. Chapter IV, on the notification of conformity assessment bodies (Articles 35 to 51), applies from 11 June 2026. Article 14 applies from 11 September 2026. Everything else applies from 11 December 2027. The Regulation itself entered into force on 10 December 2024, twenty days after publication in the Official Journal on 20 November 2024.
Article 69 handles products already on the market. Products placed on the market before 11 December 2027 are subject to the Regulation only if they undergo a substantial modification from that date (Article 69(2)). Article 69(3) then removes reporting from that relief: the Article 14 obligations apply to all in-scope products placed on the market before 11 December 2027. The scope test you run today therefore has an immediate consequence. Every product that passes it needs a named owner for reporting actively exploited vulnerabilities and severe incidents from 11 September 2026, whatever its conformity status. The full calendar is in Cyber Resilience Act deadlines for 2026 and 2027, and the way fines attach to those dates is in CRA penalties and deadlines.
What the other results get wrong
Four errors recur across the pages ranking for this query.
The first is calling the CRA an internet of things law. Article 3(1) covers software products and components placed on the market separately, with no hardware anywhere. A pure software vendor with a connected product is squarely inside.
The second is reading software as a service out of scope wholesale. The service itself usually is, but Article 3(2) pulls a manufacturer's own back end into the product when the product cannot perform a function without it.
The third is treating free products as exempt. Article 3(22) says making available on the market includes supply free of charge, as long as it happens in the course of a commercial activity. The test is commercial activity, not price.
The fourth is confusing classification with scope. Annex III and Annex IV decide how a product is assessed. Article 2 decides whether the Regulation applies at all, and a product that appears in neither annex is still in scope as a default product.
Run the scope test on one product
Take your highest-volume product and fill this in. Then repeat for the rest of the portfolio, because scope is decided product by product.
| Question | Your answer | Provision |
|---|---|---|
| Is it software, hardware, or a component placed on the market separately? | Article 3(1) | |
| Can it connect to a device or network, directly or indirectly, logically or physically? | Article 2(1), Article 3(8) to (10) | |
| Is that connection within its intended purpose or reasonably foreseeable use? | Article 3(23) and (24) | |
| Do you supply it on the Union market in the course of a commercial activity? | Article 3(22) | |
| Does one of the Article 2(2) to 2(7) exclusions actually apply to it? | Article 2 | |
| Does it depend on a back end you designed, without which it loses a function? | Article 3(2) | |
| Do you market it under your own name or trademark? | Article 3(13), Article 21 | |
| Does it have the core functionality of an Annex III or Annex IV category? | Articles 7 and 8 |
If the first five answers put a product in scope, the remaining three tell you which duties you carry and by which route. A free compliance check will show how far the Annex I requirements are from where the product stands today, and our guide to choosing a CRA compliance tool covers what to look for once the portfolio is larger than a spreadsheet can hold.
Frequently asked questions
Does the CRA apply to manufacturers outside the EU?
Yes. Article 2(1) attaches to products made available on the Union market, not to where the manufacturer sits. The Regulation assumes non-EU manufacturers exist: Article 3(16) defines the importer as the Union entity placing a product that bears a non-Union manufacturer's name, and Article 18 provides for authorised representatives.
Are internal tools we never sell in scope?
The trigger is making available on the market, which Article 3(22) defines as supply for distribution or use on the Union market in the course of a commercial activity. Software you build and use only inside your own organisation is not supplied to anyone, so it does not meet that definition. The moment you license it to a customer, it does.
Is a product with no network interface in scope?
Only if its intended purpose or reasonably foreseeable use includes a data connection, which Article 2(1) allows to be indirect and physical as well as direct and logical. A device with a USB port that will foreseeably be connected to a computer is a harder case than a device with no interface at all. Document the reasoning either way.
Are spare parts in scope?
Not where Article 2(6) applies: parts made available to replace identical components, manufactured to the same specifications as the components they replace. A replacement that changes the specification is a new product.
What happens if we get the scope call wrong?
A product wrongly treated as out of scope has no conformity work, no technical documentation and no reporting owner. Once Article 14 applies, a missed report is a top tier breach under Article 64, with a ceiling of 15 million euros or 2.5% of total worldwide annual turnover, whichever is higher. The tiers are in our guide to Cyber Resilience Act fines and penalties.
Primary sources
Every article reference above is taken from Regulation (EU) 2024/2847 as published in the Official Journal on 20 November 2024: Articles 2, 3, 7, 8, 13, 14, 18 to 21, 24, 64, 69 and 71, and Annexes III and IV. Context on remote data processing and open-source software comes from the Regulation's recitals, and background from the European Commission's Cyber Resilience Act policy pages. Confirm the current text before relying on a specific provision.





