Connected hardware is squarely in scope Art. 2(1), Art. 3(1), Art. 3(2)
The CRA applies to products with digital elements made available on the market whose intended purpose or reasonably foreseeable use includes a direct or indirect data connection to a device or network. A hardware product that runs software and connects is exactly that. Even indirectly connected devices are caught, so a sensor that talks only to a hub still qualifies.
Supply covers the course of a commercial activity whether the device is sold or given away, so bundled or free hardware within a commercial offering is in scope. The device and any remote data processing the manufacturer provides for its functions are assessed together.
Default, unless a listed category applies Annex III Class I (16), (17), (18), (19), Annex IV, Art. 7(1)
Many connected devices are default-category products with digital elements and can self-assess under internal control. But Annex III lists several consumer IoT categories as important products: smart home general purpose virtual assistants, smart home products with security functionalities (such as smart door locks, security cameras, baby monitors, and alarm systems), connected toys with social interactive or location tracking features, and personal wearables with a health monitoring purpose.
A small set of devices is critical under Annex IV, including hardware devices with security boxes, smart meter gateways, and smartcards or secure elements. If your device matches one of these, a stricter conformity route applies, so classify carefully against the implementing act.
Judgment call: Whether a specific device matches a listed category is decided by the technical descriptions in Implementing Regulation (EU) 2025/2392, not the plain-language labels.
Firmware, updates, and the support period Annex I Part II, Annex I Part I (2)(c)
The vulnerability handling requirements apply to the device in its entirety, including its firmware and components. You must handle vulnerabilities effectively during the support period, distribute updates securely, and disseminate security updates without undue delay once available.
The product must also be designed so vulnerabilities can be addressed through security updates, including, where applicable, automatic security updates enabled by default with an easy opt-out. For connected hardware that often means an update mechanism has to be part of the design from the start, not bolted on later.
The manufacturer programme and the dates Art. 13, Art. 14, Art. 71(2)
As the device's manufacturer you build to the essential cybersecurity requirements, handle vulnerabilities (including a coordinated vulnerability disclosure policy), draw up technical documentation, run the conformity assessment for your category, and affix the CE marking. Reporting duties start 11 September 2026 and the full obligations apply from 11 December 2027.