Quick answer
The CRA will generally apply to a product with digital elements when all of the following
are true:
- it is a software or hardware product, or a
separately placed component, including its necessary remote data
processing solution; - its intended purpose or reasonably foreseeable use includes a
direct or indirect logical or physical data connection
to a device or network; - it is made available on the EU market—supplied for
distribution or use in the course of a commercial activity, whether paid
or free of charge; and - no exclusion under Article 2 of the CRA or a subsequent delegated
act applies.
If the answer is yes, you must still determine whether the product is
is a product with digital elements, is an important product with digital elements in class I or II, or is
a critical product with digital elements. Classification mainly affects the conformity
assessment route; the CRA’s essential requirements apply to every
product within scope.
What is a product with
digital elements?
Article 3(1) of the CRA defines it as a software or hardware product
and its remote data processing solutions, including software or hardware
components being placed on the market separately.
Typical examples that may be in scope when the other
tests are met include:
Software
- a mobile app downloaded from an app store;
- a desktop app, or an app built with web technologies but installed
and executed locally; - an operating system, firmware, device driver or browser
extension; - a commercially supplied library, SDK, source code or other
component; - a VPN tool, password manager, browser, firewall or SIEM system.
Hardware
- a connected appliance, wearable, baby monitor or smart lock;
- a router, modem, managed switch, network printer or industrial
control component; - a laptop, tablet, IoT device or device containing firmware;
- a separately supplied integrated circuit, motherboard,
microprocessor or microcontroller.
It does not matter whether software is supplied on physical media,
through an app store or as a download. The relevant question is whether
the product is supplied to the user and operates on, or as part of, the
user’s electronic information system.
What is usually
not a standalone CRA product?
- a website that only presents information;
- a web app that executes remotely and is accessed exclusively through
a browser; - a general cloud, SaaS, PaaS or IaaS service merely because it is
accessed online; - unfinished code shared during development for testing or
review; - sample code in a tutorial or training material;
- a purely internal tool that is not supplied to another person on the
EU market.
These items may nevertheless be part of a product as remote data
processing, a component, or a source of cybersecurity risk. The result
depends on the specific architecture.
The connection test
A product meets the connection test where its intended purpose or
reasonably foreseeable use includes a data connection to a device or
network. The connection may be:
- direct, such as Ethernet, USB, Wi‑Fi, a mobile
network or Bluetooth; - indirect, such as exchange through a gateway, hub,
synchronisation service or another device; - physical, through a port, cable or physical
interface; or - logical, through a protocol, API, software
interface or virtual network.
A manufacturer’s “offline” label may not be decisive if connection or
data exchange is part of reasonably foreseeable use.
Making available and
placing on the market
Making available on the market means supplying a
product for distribution or use on the EU market in the course of a
commercial activity, whether in return for payment or free of charge.
Placing on the market is the first such making
available of an individual product.
A free product is therefore not automatically outside the CRA. The
business context, not only the price, matters. Ask:
- do you charge for the product, or for access to its current version
or security updates? - does the product monetise other products or services through
advertising, commission, subscriptions or paid features? - is use conditional on processing personal data for purposes other
than the software’s security, compatibility or interoperability? - is access to the product, an essential function or an update
effectively conditional on a “donation” or other consideration? - is it regularly supplied in a business-related context?
Commercial activity requires a case-by-case assessment. A business
can make a product available commercially even when it is free of
charge. Conversely, optional standalone consulting around a freely
available open-source project does not by itself necessarily mean that
the software is placed on the market.
Remote data processing
A cloud or remote function forms part of the product as a
remote data processing solution only when three
elements are present:
- data is processed at a distance;
- without that processing, the product could not perform one
of its functions; and - the remote processing software was designed and developed by, or
under the responsibility of, the manufacturer.
Potential functions include sending commands to a device,
synchronising files, onboarding users, configuration and
personalisation, automated distribution of updates, or identity and
access management.
Example: an authentication portal that issues a
token required for a locally installed app to operate may be remote data
processing. A product information page is not.
If the remote processing is not necessary for any function, it is not
a remote data processing solution under the CRA, although the
manufacturer may need to address the related risk in its risk
assessment. If it is necessary but uses a general third-party service
not designed or developed by or for the manufacturer, the service will
generally not be the manufacturer’s remote data processing solution. Its
integration should nevertheless be assessed similarly to a third-party
component.
Free and open-source
software
The CRA has a specific approach to free and open-source software
(FOSS). For CRA purposes, FOSS is software whose source code is openly
shared and which is made available under a licence that provides rights
to make it freely accessible, usable, modifiable and
redistributable.
Use this sequence:
- Is the source code openly shared and does the licence grant
all of those rights? If not, the CRA’s FOSS treatment does not
apply. - Who publishes the project and exercises primary control over
development, releases and distribution? A contributor without
such control is not responsible merely because they submitted code. - Does that person monetise the supply of the
software? If yes, they may be a manufacturer subject to the
ordinary CRA regime even though the software has an open-source
licence. - If the software is not monetised, is it published by a legal
person that systematically provides sustained support for its
development for intended commercial use and ensures its
viability? That person may be an open-source software steward
with specific obligations under Article 24. - Is it only a natural person publishing non-monetised FOSS
outside a commercial activity? Such publication will generally
not amount to placing a product on the market under the CRA.
Practical orientation examples:
- A free community version and a paid enterprise version are assessed
separately. The paid version may be placed on the market; the
non-monetised community version may not be. - Optional consulting or training that is not a condition for
accessing the software or its updates does not by itself monetise the
software. - A free app that monetises advertising, paid servers or another
service may be supplied in the course of a commercial activity. - Voluntary donations without an intention to make a profit will
generally not constitute commercial activity. If the current version, an
essential feature or a security fix is available only to donors, payment
may in substance be the price. - Funding development through a grant, sponsorship or bounty does not
by itself determine whether subsequent open and non-monetised
publication is commercial activity. - A business integrating a FOSS component into its own commercial
product is responsible for its resulting product and must exercise due
diligence when integrating the component.
These examples follow the European Commission’s non-binding guidance
of 27 July 2026. Every project requires its own assessment.
Exclusions and
sector-specific rules
The CRA does not apply in the following situations:
- medical devices within Regulation (EU)
2017/745; - in vitro diagnostic medical devices within
Regulation (EU) 2017/746; - products with digital elements within Regulation (EU)
2019/2144 on motor-vehicle type approval; - products with digital elements certified under Regulation
(EU) 2018/1139 on civil aviation; - certain L-category vehicles, and systems, components, separate
technical units, parts and equipment designed exclusively for them,
within Regulation (EU) No 168/2013, excluded by
Delegated Regulation (EU) 2025/1535; - products developed or modified exclusively for national
security or defence, and products specifically designed to
process classified information; - spare parts that replace identical components and
are manufactured according to the same specifications as the components
they replace; - marine equipment within Directive 2014/90/EU.
The Commission may exclude further categories by delegated act where
other EU rules achieve the same or a higher level of protection. Verify the exclusion list against the current legislation and after every relevant legislative change.
Components require care: a generic component also
sold outside an excluded sector may not benefit from the exclusion. The
Commission, for example, distinguishes an automotive component designed
and distributed exclusively for the vehicles concerned from a generic
product offered to the public.
Parallel legislation: unless there is an express
exclusion, the CRA may apply alongside other EU legislation, including
rules on radio equipment, machinery, artificial intelligence, general
product safety, data protection and product liability. Compliance with
one instrument does not automatically establish compliance with all
others. Article 69(1) of the CRA contains a transitional rule for
existing EU type-examination certificates and approval decisions
concerning cybersecurity requirements under other Union harmonisation
legislation, but it is not a general exemption from the CRA.
Which product category
applies?
Classify only after confirming that the product with digital elements is in scope.
Product with digital elements
Products with digital elements that fall within the scope of the CRA and do not have the core functionality of the categories of important or critical products with digital elements set out in Annexes III or IV of the CRA.
Critical product with digital elements
Check whether the core functionality of the whole
product with digital elements meets a category in Annex IV of the CRA and its
technical description in Implementing Regulation (EU) 2025/2392:
- hardware devices with security boxes, such as certain payment
terminals or hardware security modules; - smart meter gateways and other devices for advanced security
purposes, including secure cryptoprocessing; - smartcards or similar devices, including secure elements such as
certain TPMs, UICCs, payment cards or identity cards.
Important product with digital elements — class II
If the product with digital elements is not critical, check Annex III class II of the CRA:
- hypervisors and container runtime systems;
- firewalls and intrusion detection or prevention systems;
- tamper-resistant microprocessors and microcontrollers meeting the
technical description.
Important product with digital elements — class I
If it is not in the categories above, check Annex III class I of the CRA.
Examples include:
- identity and privileged-access management, authentication and access
control; - standalone and embedded browsers, password managers, antimalware,
VPN, SIEM, network-management systems and boot managers; - PKI and certificate-issuance software, operating systems and
physical or virtual network interfaces; - routers, modems and managed switches;
- certain microprocessors, microcontrollers, ASICs and FPGAs with
security-related functionality; - smart-home general-purpose virtual assistants, smart locks, security
cameras, baby monitors and alarm systems; - internet-connected toys with social interactive or location-tracking
features; - certain health-monitoring wearables that are not medical devices,
and wearables intended for children.
Key rule: integrating one important or critical
component does not automatically make the whole product important or
critical. Classification follows the core functionality of the product with digital elements
as a whole. The manufacturer must still consider the security of the
integrated component when assessing and securing the whole product.
Decision aid: does the
CRA apply to me?
-
Do I supply software, hardware or a separately supplied
digital component?- No → it is probably not a product with digital elements. Check whether
you provide necessary remote data processing for another product. - Yes → continue.
- No → it is probably not a product with digital elements. Check whether
-
Does its intended purpose or reasonably foreseeable use
include a data connection to a device or network?- No → the CRA will generally not apply under Article 2(1).
- Yes → continue.
-
Do I supply the product for distribution or use on the EU
market?- No; it is used only internally and not supplied to another person → this
is generally not making available on the market. - Yes → continue.
- No; it is used only internally and not supplied to another person → this
-
Is the supply part of a commercial activity, even if free
of charge?- No → for FOSS, still check whether you are an open-source software
steward. - Yes or unclear → continue and document the business model.
- No → for FOSS, still check whether you are an open-source software
-
Does an express sectoral or purpose-based exclusion
apply?- Yes → the CRA does not apply, or applies only to requirements not
covered; verify the exact scope of the sectoral instrument. - No → the product with digital elements is likely within scope.
- Yes → the CRA does not apply, or applies only to requirements not
-
Does the product’s core functionality meet a technical
description of a category of important or critical product with digital elements?- Yes → specify the category in accordance with Annexes III and IV and Regulation 2025/2392.
- No → it is a product with digital elements that is neither important nor critical.
-
What is my role?
- I market the product with digital elements under my name or trademark → likely
manufacturer. - I place a third-country manufacturer’s product on the EU market → likely
importer. - I supply the product with digital elements in the distribution chain → likely
distributor. - I systematically provide sustained support for non-monetised FOSS
intended for commercial use → assess the open-source software steward
role.
- I market the product with digital elements under my name or trademark → likely
The result is not a legal determination. Keep the
answers, product version, intended purpose, architecture, distribution
model, business model, components and legal sources. This record will
support the product’s risk and conformity assessment.
Key definitions
- Product with digital elements: a software or
hardware product and its remote data processing solutions, including
separately placed software or hardware components. - Remote data processing: data processing at a
distance whose software is designed and developed by, or under the
responsibility of, the manufacturer and whose absence would prevent the
product from performing one of its functions. - Intended purpose: the use intended by the
manufacturer, including the specific context and conditions of use
stated in information, instructions, sales or promotional material and
technical documentation. - Reasonably foreseeable use: use that is not
necessarily the intended purpose but is likely to result from reasonably
foreseeable human behaviour, technical operations or interactions. - Making available on the market: supplying a product
for distribution or use on the EU market in the course of a commercial
activity, whether paid or free of charge. - Placing on the market: the first making available
of a product on the EU market. - Core functionality: a function essential for the
product’s purpose and without which the product would not fulfil that
purpose. - FOSS under the CRA: software whose source code is
openly shared and whose licence grants rights to make it freely
accessible, usable, modifiable and redistributable. - Open-source software steward: a legal person other
than a manufacturer whose purpose or objective is to provide systematic
and sustained support for the development of FOSS intended for
commercial activities and to ensure its viability.
What to do next
- I am a manufacturer → go to Manufacturer
obligations. - I am an importer or distributor → go to Importer and
distributor obligations. - I publish or steward FOSS → go to Open source and the
CRA. - I know the product category → go to Conformity
assessment. - I need to know when the rules apply → go to the CRA
timeline.