CRA Scope Assessment

Determine if your product falls under the Cyber Resilience Act

Answer a few questions about your product to find out if the CRA applies, and if so, which category it falls into. This determines your compliance obligations.

Input Parameters

Product Type
Market Presence
Business Model
Existing Regulation
Primary Use
Product Function
Connectivity
Data Handling
Hardware Interaction
Target Users

Results

Default Category

Your product falls under the default category. Self-assessment is allowed.

Confidence: Needs legal review

Key Obligations

  • Cybersecurity risk assessment
  • Technical documentation
  • Vulnerability handling process
  • Security updates for product lifetime (min. 5 years)
  • Self-assessment and EU declaration of conformity
  • CE marking
  • Report actively exploited vulnerabilities to ENISA within 24h

Compliance Timeline

Most CRA requirements apply from December 2027.

Vulnerability reporting obligations apply earlier (September 2026).

Note: This is a simplified assessment tool. For definitive classification, consult the regulation text or legal counsel.

Get PDF Report

We'll email you a PDF with your assessment results.