EU Cyber Resilience Act · In force

Find out if your product is in scope for the CRA.

Answer a few questions about your product and get an indicative EU Cyber Resilience Act classification — emailed to you within the hour.

See how it works
Free~5 minutesNo account required
Know your CRA classSee whether your product is Default, Important (I/II) or Critical, and the conformity route that follows.
Grounded in the regulationMapped to the category definitions of Implementing Regulation (EU) 2025/2392 — not guesswork.
No strings attachedNo account, no payment, no sales call. Just answer the questionnaire.
PDF in your inboxA clear, shareable assessment lands in your email within the hour.
How it works

Three steps to clarity

1
Tell us about your productName, version, connectivity, category and a little context — about five minutes.
2
Optionally add documentsA datasheet or manual sharpens the result, but the form alone is enough.
3
Get your assessment by emailWe generate an indicative CRA classification PDF and send it to you within the hour.
Why start here

A head start on the CRA, in minutes

~5 minto complete
€0no account, no card
2027compliance deadline — start now

Built by Nord CS GmbH. Based on Regulation (EU) 2024/2847 (Cyber Resilience Act) and Implementing Regulation (EU) 2025/2392.

FAQ

EU Cyber Resilience Act, in plain terms

  • The Cyber Resilience Act (Regulation (EU) 2024/2847) is an EU law setting mandatory cybersecurity requirements for products with digital elements — any hardware or software that can connect to a device or network — placed on the EU market. It entered into force in December 2024 and applies in two stages: reporting obligations from 11 September 2026, and the full set of compliance obligations from 11 December 2027.

  • Almost any product with digital elements sold in the EU: connected hardware, embedded software, standalone software and their remote data-processing solutions. Narrow exceptions apply to products already covered by sectoral rules such as medical devices, motor vehicles and aviation, and to certain non-commercial open-source software.

  • The CRA sorts products into four risk tiers: Default (the majority, eligible for self-assessment), Important class I and Important class II (listed in Annex III), and Critical (Annex IV). Higher tiers require stricter conformity assessment, up to mandatory third-party assessment for critical products.

  • There are two dates. Reporting obligations under Article 14 — notifying actively exploited vulnerabilities and severe incidents to ENISA and your CSIRT — apply from 11 September 2026, and under Article 69(3) they apply retroactively to products already placed on the market, so they are not limited to new products. The full compliance obligations, including the essential cybersecurity requirements and conformity assessment, apply from 11 December 2027.

  • Yes. Article 69(3) makes the Article 14 reporting obligations applicable from 11 September 2026 to products with digital elements that were already placed on the EU market, not only to products released after that date. In practice this means you need a vulnerability and incident reporting process in place for your existing portfolio well before the full 11 December 2027 compliance deadline.

  • It depends on the product’s function and cybersecurity risk — for example whether it performs a security function, processes sensitive data, or could give access to other devices. The important and critical categories are defined in Annex III and IV of the CRA and detailed in Implementing Regulation (EU) 2025/2392.

  • The assessment is free, with no account, payment or sales call. It provides an indicative classification to help you understand your likely obligations. It is not legal advice — a binding classification requires a formal conformity assessment.

Get your assessment

Answer a few questions about your product and get an indicative CRA classification emailed to you within the hour.