Regulation (EU) 2024/2847 ยท knowledge base
The CRA Knowledge Base
Plain-English answers to the questions the regulation raises for small software and hardware teams. Every claim on every page cites the article, annex, or recital of Regulation (EU) 2024/2847 it rests on, so you, or your lawyer, can check every step.
Check your scope, freeProducts the CRA lists by name
The important (Annex III) and critical (Annex IV) product categories. Landing in one changes your conformity assessment route.
- Is antivirus or EDR software an important product under the CRA?
- Is a boot manager an important product under the CRA?
- Is a browser an important product under the EU CRA?
- Are internet connected toys important products under the CRA?
- What is a critical product with digital elements under the CRA?
- Are firewalls and intrusion detection systems important under the CRA?
- Are hypervisors and container runtimes important products under the CRA?
- Is identity and access management software an important product under the CRA?
- Is a network interface an important product under the CRA?
- Is a network management system an important product under the CRA?
- Is an operating system an important product under the CRA?
- Is a password manager an important product under the CRA?
- Is PKI or certificate issuance software an important product under the CRA?
- Are routers, modems, and switches important products under the CRA?
- Are microprocessors and microcontrollers important products under the CRA?
- Is a SIEM system an important product under the CRA?
- Is a smart home virtual assistant an important product under the CRA?
- Are smart locks, cameras, and alarms important products under the CRA?
- Are tamper-resistant chips important products under the CRA?
- Is a VPN product an important product under the CRA?
- Are health and childrens wearables important products under the CRA?
Common product types
SaaS, apps, extensions, open source, and the other product shapes small teams actually ship, and where each one lands.
- Do AI products fall under the EU CRA?
- Are APIs and backends in scope of the EU CRA?
- Is a browser extension in scope of the EU CRA?
- Are CMS plugins and themes in scope of the EU CRA?
- Is desktop software in scope of the EU CRA?
- Are IoT devices in scope of the EU CRA?
- Is a mobile app in scope of the EU CRA?
- Is open-source software in scope of the EU CRA?
- Does the EU Cyber Resilience Act apply to SaaS?
- Are software libraries and SDKs in scope of the CRA?
- Are video games in scope of the EU CRA?
- Does the EU Cyber Resilience Act apply to a website?
The obligations, one by one
What the CRA actually requires: reporting, SBOM, vulnerability handling, documentation, CE marking, and the deadlines and penalties around them.
- How does CE marking work under the CRA?
- Which CRA conformity assessment route applies to my product?
- What are the key CRA compliance deadlines?
- What are the CRA essential cybersecurity requirements?
- What are the fines under the EU Cyber Resilience Act?
- What are the CRA reporting obligations?
- Does the CRA require a software bill of materials (SBOM)?
- How long is the support period under the CRA?
- What technical documentation does the CRA require?
- What are the CRA vulnerability handling requirements?
By company type
The same regulation lands differently on agencies, SaaS companies, importers, and distributors. Start from your seat.
- What the CRA means for agencies that build and resell software
- What the CRA requires of distributors and resellers
- What the CRA requires of importers
- What the CRA means for small IoT and hardware makers
- What the CRA means for open-source maintainers
- Does the CRA apply to your SaaS company?
- The CRA manufacturer programme for independent software vendors