Know your CRA classSee whether your product is Default, Important (I/II) or Critical, and the conformity route that follows.
Grounded in the regulationMapped to the category definitions of Implementing Regulation (EU) 2025/2392 — not guesswork.
No strings attachedNo account, no payment, no sales call. Just answer the questionnaire.
PDF in your inboxA clear, shareable assessment lands in your email within the hour.
How it works
Three steps to clarity
1
Tell us about your productName, version, connectivity, category and a little context — about five minutes.
2
Optionally add documentsA datasheet or manual sharpens the result, but the form alone is enough.
3
Get your assessment by emailWe generate an indicative CRA classification PDF and send it to you within the hour.
Why start here
A head start on the CRA, in minutes
~5 minto complete
€0no account, no card
2027compliance deadline — start now
Built by Nord CS GmbH. Based on Regulation (EU) 2024/2847 (Cyber Resilience Act) and Implementing Regulation (EU) 2025/2392.
FAQ
EU Cyber Resilience Act, in plain terms
The Cyber Resilience Act (Regulation (EU) 2024/2847) is an EU law setting mandatory cybersecurity requirements for products with digital elements — any hardware or software that can connect to a device or network — placed on the EU market. It entered into force in December 2024 and applies in two stages: reporting obligations from 11 September 2026, and the full set of compliance obligations from 11 December 2027.
Almost any product with digital elements sold in the EU: connected hardware, embedded software, standalone software and their remote data-processing solutions. Narrow exceptions apply to products already covered by sectoral rules such as medical devices, motor vehicles and aviation, and to certain non-commercial open-source software.
The CRA sorts products into four risk tiers: Default (the majority, eligible for self-assessment), Important class I and Important class II (listed in Annex III), and Critical (Annex IV). Higher tiers require stricter conformity assessment, up to mandatory third-party assessment for critical products.
There are two dates. Reporting obligations under Article 14 — notifying actively exploited vulnerabilities and severe incidents to ENISA and your CSIRT — apply from 11 September 2026, and under Article 69(3) they apply retroactively to products already placed on the market, so they are not limited to new products. The full compliance obligations, including the essential cybersecurity requirements and conformity assessment, apply from 11 December 2027.
Yes. Article 69(3) makes the Article 14 reporting obligations applicable from 11 September 2026 to products with digital elements that were already placed on the EU market, not only to products released after that date. In practice this means you need a vulnerability and incident reporting process in place for your existing portfolio well before the full 11 December 2027 compliance deadline.
It depends on the product’s function and cybersecurity risk — for example whether it performs a security function, processes sensitive data, or could give access to other devices. The important and critical categories are defined in Annex III and IV of the CRA and detailed in Implementing Regulation (EU) 2025/2392.
The assessment is free, with no account, payment or sales call. It provides an indicative classification to help you understand your likely obligations. It is not legal advice — a binding classification requires a formal conformity assessment.
Get your assessment
Answer a few questions about your product and get an indicative CRA classification emailed to you within the hour.
CRA assessment
Close
Legal disclaimer
Please read and accept before proceeding with the CRA applicability assessment.
This CRA applicability assessment is provided free of charge and for general informational purposes only. It does not constitute legal advice, regulatory advice, or a conformity assessment within the meaning of Regulation (EU) 2024/2847 (Cyber Resilience Act) or any other legislation.
The information and documents you provide are processed by an AI service provider acting as our data processor to generate your assessment, as described in our Privacy Policy. The results are generated by this automated, AI-supported system on the basis of the information you provide. We do not verify the accuracy or completeness of your inputs, and AI-generated output may contain errors. The results reflect a non-binding, indicative evaluation only. Nord CS GmbH makes no representation or warranty of any kind, express or implied, as to the accuracy, completeness, reliability, or fitness for any particular purpose of the report or its results.
Sole responsibility for verifying the applicability of the CRA and any other regulatory requirements to your product remains with you. You must independently verify all results, where appropriate with the assistance of qualified legal counsel or a notified body, before making any business, compliance, or product decisions.
To the maximum extent permitted by applicable law, Nord CS GmbH excludes all liability for damages arising from the use of, or reliance on, this tool or its results. This exclusion does not apply to liability for intent or gross negligence, for injury to life, body or health, or where liability cannot be excluded under mandatory law (including the German Product Liability Act).
A binding CRA classification is established only through a formal conformity assessment. This tool and its report do not substitute for that process.