Calculator · CRA / 2024/2847
Three questions decide it: is this a product with digital elements, what role you have, and what is its core functionality. We go through them and show the result.
We go through the scope of the regulation, your role in the supply chain and the product category, one step at a time. At the end you see which conformity assessment route you should take and which deadlines concern you. The result is free and nobody asks for your e-mail.
The calculator works with Regulation (EU) 2024/2847 and with the technical description of the categories in Implementing Regulation (EU) 2025/2392. It does not reproduce the text of the legislation — every statement cites the article or annex where you can verify it.
The regulation applies to products with digital elements made available on the Union market whose intended purpose or reasonably foreseeable use includes a data connection (Article 2(1)). This is where it is decided whether it makes sense to go on.
Most CRA disputes are not about technology, they are about roles. The role changes when you place the product on the market under your own name or modify it substantially — that is the most common surprise for integrators and importers.
The category is determined by the core functionality of the product as a whole (Article 7(1)). It drives the conformity assessment procedure under Article 32 — and therefore whether you can manage on your own or will need a notified body.
This output is a guide for orientation, not a legal assessment. It is based only on what you entered in the form; the actual classification of the product and your role in the supply chain are decided on details that a form cannot capture. Borderline cases need an individual assessment and the binding text is always Regulation (EU) 2024/2847.
CypherOn provides cybersecurity consulting services and is not a law firm. For legal opinions, turn to an attorney registered with the Czech Bar Association.
The staggered dates in Article 71, the difference between entry into force and application, who counts as a manufacturer, the Annex I requirements, the software bill of materials, the support period and reporting under Article 14.
Open the guideWhat SCA, SAST, DAST or image scanning actually find, how a software bill of materials and VEX are produced, what to block in CI/CD and how KEV and EPSS lead to a decision to report under Article 14.
Open DevSecOpsBespoke development, SaaS, open source, hardware with third-party firmware, integration of third-party components and reporting under Article 14 in specific situations.
Open the FAQThe decision logic of the calculator is based on these sources, as of 8 August 2026. What binds is the text of the legislation, not our reading of it.
When the result comes out as manufacturer
Product threat modelling, secure development reviews, vulnerability management and inputs for the technical documentation under Annex VII. Tell us what the calculator gave you and where you stand today.