Connected hardware is in scope Art. 2(1), Art. 3(1), Art. 3(2)
The CRA covers software and hardware products with a direct or indirect data connection to a device or network (Art. 2(1), Art. 3(1)). Indirect counts: a sensor that talks to a hub, or a device that syncs through a phone app, is connected for these purposes (Art. 3(10)). Very few modern IoT or smart devices fall outside that.
The software in your device, its firmware, is the regulated part alongside the hardware. If a cloud backend you provide is needed for the device to perform a function, that backend is in scope with it as a remote data processing solution (Art. 3(2), Recital 12).
The annex categories that commonly bite Art. 7, Annex III
Check your device's core functionality against Annex III. Several everyday consumer categories are listed as important products, which restricts your conformity route beyond plain self-assessment (Art. 7, Art. 32(2)). Merely including a listed component does not by itself put the whole device in the category (Art. 7(1)), but a device whose core function is a listed one does.
- Smart home assistants and smart home products with security functionality. (Annex III)
- Internet-connected toys with social interaction or location tracking features. (Annex III)
- Wearables with a health monitoring purpose (where the medical device rules do not apply; if they do, the product is excluded from the CRA entirely), and wearables for children. (Annex III Class I (19), Art. 2(2))
- Routers, modems intended for the connection to the internet, and switches, with no limit to home or small office equipment. (Annex III Class I (12))
Support period and firmware updates Art. 13(8), Art. 13(9), Art. 13(19)
You must handle vulnerabilities effectively across a support period, and for hardware that means shipping firmware security updates for its duration (Art. 13(8), Annex I Part II). Set the support period to reflect how long the device is expected to be in use; it must be at least five years unless the device is used for less (Art. 13(8)).
Two practical duties follow. Security updates must remain available for at least ten years after issue, or the rest of the support period if longer (Art. 13(9)). And the end date of the support period must be stated clearly at the time of purchase (Art. 13(19)), which for physical products means planning packaging and listings around it.
If you manufacture outside the EU Art. 19(1), Art. 19(2), Art. 18
A non-EU maker still carries the manufacturer obligations for products placed on the EU market. In practice, the EU-based importer who brings your device in cannot place it on the market unless it is compliant, and must verify that you carried out the conformity assessment, drew up the technical documentation, and affixed the CE marking (Art. 19(1), Art. 19(2)).
That makes your paperwork the importer's gating item. Expect to hand over the declaration of conformity, technical documentation, and support-period information, or the importer legally cannot ship your product. Appointing an authorised representative in the EU can smooth this (Art. 18).