Skip to main content
Oficiálna stránka verejnej správy SR
Cyber Resilience Act · National Security Authority

Does the CRA apply to my product?

Last updated:

Quick answer

The CRA will generally apply to a product with digital elements when all of the following
are true:

  1. it is a software or hardware product, or a
    separately placed component, including its necessary remote data
    processing solution;
  2. its intended purpose or reasonably foreseeable use includes a
    direct or indirect logical or physical data connection
    to a device or network;
  3. it is made available on the EU market—supplied for
    distribution or use in the course of a commercial activity, whether paid
    or free of charge; and
  4. no exclusion under Article 2 of the CRA or a subsequent delegated
    act applies.

If the answer is yes, you must still determine whether the product is
is a product with digital elements, is an important product with digital elements in class I or II, or is
a critical product with digital elements. Classification mainly affects the conformity
assessment route; the CRA’s essential requirements apply to every
product within scope.

What is a product with
digital elements?

Article 3(1) of the CRA defines it as a software or hardware product
and its remote data processing solutions, including software or hardware
components being placed on the market separately.

Typical examples that may be in scope when the other
tests are met include:

Software

Hardware

It does not matter whether software is supplied on physical media,
through an app store or as a download. The relevant question is whether
the product is supplied to the user and operates on, or as part of, the
user’s electronic information system.

What is usually
not a standalone CRA product?

These items may nevertheless be part of a product as remote data
processing, a component, or a source of cybersecurity risk. The result
depends on the specific architecture.

The connection test

A product meets the connection test where its intended purpose or
reasonably foreseeable use includes a data connection to a device or
network. The connection may be:

A manufacturer’s “offline” label may not be decisive if connection or
data exchange is part of reasonably foreseeable use.

Making available and
placing on the market

Making available on the market means supplying a
product for distribution or use on the EU market in the course of a
commercial activity, whether in return for payment or free of charge.
Placing on the market is the first such making
available of an individual product.

A free product is therefore not automatically outside the CRA. The
business context, not only the price, matters. Ask:

Commercial activity requires a case-by-case assessment. A business
can make a product available commercially even when it is free of
charge. Conversely, optional standalone consulting around a freely
available open-source project does not by itself necessarily mean that
the software is placed on the market.

Remote data processing

A cloud or remote function forms part of the product as a
remote data processing solution only when three
elements are present:

  1. data is processed at a distance;
  2. without that processing, the product could not perform one
    of its functions
    ; and
  3. the remote processing software was designed and developed by, or
    under the responsibility of, the manufacturer.

Potential functions include sending commands to a device,
synchronising files, onboarding users, configuration and
personalisation, automated distribution of updates, or identity and
access management.

Example: an authentication portal that issues a
token required for a locally installed app to operate may be remote data
processing. A product information page is not.

If the remote processing is not necessary for any function, it is not
a remote data processing solution under the CRA, although the
manufacturer may need to address the related risk in its risk
assessment. If it is necessary but uses a general third-party service
not designed or developed by or for the manufacturer, the service will
generally not be the manufacturer’s remote data processing solution. Its
integration should nevertheless be assessed similarly to a third-party
component.

Free and open-source
software

The CRA has a specific approach to free and open-source software
(FOSS). For CRA purposes, FOSS is software whose source code is openly
shared and which is made available under a licence that provides rights
to make it freely accessible, usable, modifiable and
redistributable.

Use this sequence:

  1. Is the source code openly shared and does the licence grant
    all of those rights?
    If not, the CRA’s FOSS treatment does not
    apply.
  2. Who publishes the project and exercises primary control over
    development, releases and distribution?
    A contributor without
    such control is not responsible merely because they submitted code.
  3. Does that person monetise the supply of the
    software?
    If yes, they may be a manufacturer subject to the
    ordinary CRA regime even though the software has an open-source
    licence.
  4. If the software is not monetised, is it published by a legal
    person that systematically provides sustained support for its
    development for intended commercial use and ensures its
    viability?
    That person may be an open-source software steward
    with specific obligations under Article 24.
  5. Is it only a natural person publishing non-monetised FOSS
    outside a commercial activity?
    Such publication will generally
    not amount to placing a product on the market under the CRA.

Practical orientation examples:

These examples follow the European Commission’s non-binding guidance
of 27 July 2026. Every project requires its own assessment.

Exclusions and
sector-specific rules

The CRA does not apply in the following situations:

The Commission may exclude further categories by delegated act where
other EU rules achieve the same or a higher level of protection. Verify the exclusion list against the current legislation and after every relevant legislative change.

Components require care: a generic component also
sold outside an excluded sector may not benefit from the exclusion. The
Commission, for example, distinguishes an automotive component designed
and distributed exclusively for the vehicles concerned from a generic
product offered to the public.

Parallel legislation: unless there is an express
exclusion, the CRA may apply alongside other EU legislation, including
rules on radio equipment, machinery, artificial intelligence, general
product safety, data protection and product liability. Compliance with
one instrument does not automatically establish compliance with all
others. Article 69(1) of the CRA contains a transitional rule for
existing EU type-examination certificates and approval decisions
concerning cybersecurity requirements under other Union harmonisation
legislation, but it is not a general exemption from the CRA.

Which product category
applies?

Classify only after confirming that the product with digital elements is in scope.

Product with digital elements 

Products with digital elements that fall within the scope of the CRA and do not have the core functionality of the categories of important or critical products with digital elements set out in Annexes III or IV of the CRA.

Critical product with digital elements

Check whether the core functionality of the whole
product with digital elements
meets a category in Annex IV of the CRA and its
technical description in Implementing Regulation (EU) 2025/2392:

Important product with digital elements — class II

If the product with digital elements is not critical, check Annex III class II of the CRA:

Important product with digital elements — class I

If it is not in the categories above, check Annex III class I of the CRA.
Examples include:

Key rule: integrating one important or critical
component does not automatically make the whole product important or
critical. Classification follows the core functionality of the product with digital elements
as a whole. The manufacturer must still consider the security of the
integrated component when assessing and securing the whole product.

Decision aid: does the
CRA apply to me?

  1. Do I supply software, hardware or a separately supplied
    digital component?

    • No → it is probably not a product with digital elements. Check whether
      you provide necessary remote data processing for another product.
    • Yes → continue.
  2. Does its intended purpose or reasonably foreseeable use
    include a data connection to a device or network?

    • No → the CRA will generally not apply under Article 2(1).
    • Yes → continue.
  3. Do I supply the product for distribution or use on the EU
    market?

    • No; it is used only internally and not supplied to another person → this
      is generally not making available on the market.
    • Yes → continue.
  4. Is the supply part of a commercial activity, even if free
    of charge?

    • No → for FOSS, still check whether you are an open-source software
      steward.
    • Yes or unclear → continue and document the business model.
  5. Does an express sectoral or purpose-based exclusion
    apply?

    • Yes → the CRA does not apply, or applies only to requirements not
      covered; verify the exact scope of the sectoral instrument.
    • No → the product with digital elements is likely within scope.
  6. Does the product’s core functionality meet a technical
    description of a category of important or critical product with digital elements?

    • Yes → specify the category in accordance with Annexes III and IV and Regulation 2025/2392.
    • No → it is a product with digital elements that is neither important nor critical.
  7. What is my role?

    • I market the product with digital elements under my name or trademark → likely
      manufacturer.
    • I place a third-country manufacturer’s product on the EU market → likely
      importer.
    • I supply the product with digital elements in the distribution chain → likely
      distributor.
    • I systematically provide sustained support for non-monetised FOSS
      intended for commercial use → assess the open-source software steward
      role.

The result is not a legal determination. Keep the
answers, product version, intended purpose, architecture, distribution
model, business model, components and legal sources. This record will
support the product’s risk and conformity assessment.

Key definitions

What to do next