CRA Desk

Is your product in scope of the Cyber Resilience Act (CRA)?

Four questions. The verdict is computed in your browser - nothing is sent anywhere - and every line cites the provision it rests on.

These are the Annex III and Annex IV categories, as described by Implementing Regulation (EU) 2025/2392. Core functionality decides - not a feature you happen to have.

How is it supplied?
Where does the software run?

The last option is the one that pulls a hosted component into scope: if the product cannot do its job without it, it is part of the product.

All 26 categories Annex III and Annex IV list

The form above answers for one product. This is the whole map: every category the CRA singles out as important or critical, what the Implementing Regulation says falls in it and the conformity route that follows from 11 December 2027. Core functionality decides which one you are in - the primary purpose the product is on the market for, not a feature it happens to include.

Each summary condenses that category's technical description in Implementing Regulation (EU) 2025/2392, adopted 28 November 2025. It is a summary, not a verbatim quote - the annex point linked beside it is the text that governs.

Annex III - class I - Important, class I

19 categories of important products. Applying harmonised standards in full is what keeps a manufacturer here out of a notified body's hands - and no harmonised standard for the CRA has been published in the Official Journal yet.

Conformity route from 11 December 2027: Notified body, unless harmonised standards are applied in full

Annex III - class II - Important, class II

4 categories of important products, one step stricter than class I: applying harmonised standards does not remove the notified body from the route.

Conformity route from 11 December 2027: Notified body required

Annex IV - critical - Critical

3 categories, the narrowest list in the regulation. Conformity here runs through a European cybersecurity certification scheme rather than a notified body alone.

Conformity route from 11 December 2027: European cybersecurity certification scheme

  • Hardware devices with security boxes

    Multi-component devices with tamper evidence or resistance that store sensitive data or perform cryptographic operations - payment terminals, HSMs, tachographs.

    Source: Annex IV, point 1; Annex II, point 1

  • Smart meter gateways

    Products controlling communication within smart metering systems: meter data collection, encryption and firewalling.

    Source: Annex IV, point 2; Annex II, point 2

  • Smartcards or similar devices, including secure elements

    Secure microcontrollers or microprocessors at AVA_VAN.4 handling cryptographic operations and identity or payment credentials.

    Source: Annex IV, point 3; Annex II, point 3

Not on either list? That is a verdict, not a gap.

Most software is in none of these categories and that is the cheapest outcome the regulation offers: a default-class product self-assesses under Article 32(1) - no notified body, no certification scheme. Being absent from Annex III and Annex IV does not put you outside the CRA. It puts you in the lightest conformity route inside it.

None of this moves the September date. Article 14's 24-hour early warning applies to every product in scope, in every class, default class included - and to products you shipped years ago.