In scope, default category ยท Regulation (EU) 2024/2847

Are IoT devices in scope of the EU CRA?

Verified against the Official Journal text on

In scope, default category (usually) (Art. 2(1), Art. 3(1))

Yes. Hardware with software that connects to a device or network is the paradigm product with digital elements, so a connected device supplied to EU users in the course of business is in scope. Most IoT devices are default-category and can self-assess, but several consumer categories are listed as important products, including smart home assistants, smart home security devices, connected toys with social or tracking features, and health wearables, and a few security devices are critical. Whichever category applies, the vulnerability handling duties oblige you to keep firmware secure and updatable across the support period.

Basis: Art. 2(1), Art. 3(1), Annex III

Judgment call: Whether a device "has the core functionality of" a listed category is a classification judgment; the technical descriptions in Implementing Regulation (EU) 2025/2392 control the match.

Connected hardware is squarely in scope Art. 2(1), Art. 3(1), Art. 3(2)

The CRA applies to products with digital elements made available on the market whose intended purpose or reasonably foreseeable use includes a direct or indirect data connection to a device or network. A hardware product that runs software and connects is exactly that. Even indirectly connected devices are caught, so a sensor that talks only to a hub still qualifies.

Supply covers the course of a commercial activity whether the device is sold or given away, so bundled or free hardware within a commercial offering is in scope. The device and any remote data processing the manufacturer provides for its functions are assessed together.

Default, unless a listed category applies Annex III Class I (16), (17), (18), (19), Annex IV, Art. 7(1)

Many connected devices are default-category products with digital elements and can self-assess under internal control. But Annex III lists several consumer IoT categories as important products: smart home general purpose virtual assistants, smart home products with security functionalities (such as smart door locks, security cameras, baby monitors, and alarm systems), connected toys with social interactive or location tracking features, and personal wearables with a health monitoring purpose.

A small set of devices is critical under Annex IV, including hardware devices with security boxes, smart meter gateways, and smartcards or secure elements. If your device matches one of these, a stricter conformity route applies, so classify carefully against the implementing act.

Judgment call: Whether a specific device matches a listed category is decided by the technical descriptions in Implementing Regulation (EU) 2025/2392, not the plain-language labels.

Firmware, updates, and the support period Annex I Part II, Annex I Part I (2)(c)

The vulnerability handling requirements apply to the device in its entirety, including its firmware and components. You must handle vulnerabilities effectively during the support period, distribute updates securely, and disseminate security updates without undue delay once available.

The product must also be designed so vulnerabilities can be addressed through security updates, including, where applicable, automatic security updates enabled by default with an easy opt-out. For connected hardware that often means an update mechanism has to be part of the design from the start, not bolted on later.

The manufacturer programme and the dates Art. 13, Art. 14, Art. 71(2)

As the device's manufacturer you build to the essential cybersecurity requirements, handle vulnerabilities (including a coordinated vulnerability disclosure policy), draw up technical documentation, run the conformity assessment for your category, and affix the CE marking. Reporting duties start 11 September 2026 and the full obligations apply from 11 December 2027.

What you must do

  • Design, develop, and produce the device in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities in the device, including its firmware and components, across the support period, and distribute security updates securely and without undue delay. (Art. 13(8), Annex I Part II)
  • Draw up technical documentation, carry out conformity assessment, and affix the CE marking. (Art. 13(12), Art. 32)
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

Our device only connects through a hub, not directly to the internet. Is it in scope?

Very likely yes. Scope covers a direct or indirect data connection to a device or network, and indirect counts. A device that reaches a network through a hub, an app, or another device still qualifies as a product with digital elements. (Art. 2(1))

When is a connected device an important or critical product?

When it matches a listed category: smart home assistants, smart home security devices, connected toys with social or tracking features, and health wearables are important, while security boxes, smart meter gateways, and secure elements are critical. The implementing act decides the match. (Annex III, Annex IV)

How long do we have to support firmware?

You must handle vulnerabilities across the support period, which should reflect how long the device is expected to be in use. Design the device so security updates can be delivered, ideally automatically by default with an easy opt-out. (Annex I Part II, Annex I Part I (2)(c))

Classify your device in three minutes

The Vexwatch Scope Checker walks the same cited decision tree: whether your device is in scope, whether it is default, important, or critical, and which obligations hit on which date.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.