Calculator · CRA / 2024/2847

DOES THE CRA APPLY TO YOUR PRODUCT?

Three questions decide it: is this a product with digital elements, what role you have, and what is its core functionality. We go through them and show the result.

The calculator builds on what is explained in the CRA guide

We go through the scope of the regulation, your role in the supply chain and the product category, one step at a time. At the end you see which conformity assessment route you should take and which deadlines concern you. The result is free and nobody asks for your e-mail.

The calculator works with Regulation (EU) 2024/2847 and with the technical description of the categories in Implementing Regulation (EU) 2025/2392. It does not reproduce the text of the legislation — every statement cites the article or annex where you can verify it.

A guide for orientation, not a legal assessment The result is a guide for orientation, not a legal assessment and not an official determination. The classification of a specific product, the role in the supply chain and the substantial modification threshold are all decided on details that a form cannot capture — borderline cases need an assessment of the specific product, and sometimes an opinion from a lawyer. The binding text is Regulation (EU) 2024/2847 as published in the Official Journal; the links are in the Official sources section. CypherOn is a cybersecurity consulting firm, not a law firm.
1Scope
2Role
3Category
4Result

Is the product within the scope of the regulation?

The regulation applies to products with digital elements made available on the Union market whose intended purpose or reasonably foreseeable use includes a data connection (Article 2(1)). This is where it is decided whether it makes sense to go on.

What exactly do you supply?

A product with digital elements is software as well as hardware, including components placed on the market separately, together with any remote data processing solution designed and developed by the manufacturer without which the product would not perform one of its functions (Article 3, points (1) and (2)).

What role do you have in relation to the product?

Most CRA disputes are not about technology, they are about roles. The role changes when you place the product on the market under your own name or modify it substantially — that is the most common surprise for integrators and importers.

What is your relationship to the product?

A manufacturer is not only the one who develops or manufactures the product, but also the one who has it developed and markets it under its own name or trademark (Article 3, point (13)). A distributor is the one who makes the product available further down the chain without affecting its properties (Article 3, point (17)).

What is the core functionality of the product?

The category is determined by the core functionality of the product as a whole (Article 7(1)). It drives the conformity assessment procedure under Article 32 — and therefore whether you can manage on your own or will need a notified body.

Your role
Which category does the core functionality of the product fall into?

What decides is the core functionality of the product as a whole. A built-in component that would fall into one of the categories on its own does not turn the product into an important product (Article 7(1)) — a browser inside an application does not make the application a browser. The technical description of the individual categories was added by Implementing Regulation (EU) 2025/2392.

In the official Czech version, the second item of Annex IV reads „přístroje pro účely zajištění větší bezpečnosti, mj. pro bezpečné přijímání plateb v kryptoměně" — the same item, only with „secure cryptoprocessing" rendered unfortunately as the receipt of cryptocurrency payments; what is meant is secure cryptographic processing, not payments.

An indicative result. It replaces neither a legal assessment nor an official determination, and borderline cases need an individual assessment.

What to do next

    This output is a guide for orientation, not a legal assessment. It is based only on what you entered in the form; the actual classification of the product and your role in the supply chain are decided on details that a form cannot capture. Borderline cases need an individual assessment and the binding text is always Regulation (EU) 2024/2847.

    Open the CRA guide →

    Guide to the CRA

    The staggered dates in Article 71, the difference between entry into force and application, who counts as a manufacturer, the Annex I requirements, the software bill of materials, the support period and reporting under Article 14.

    Open the guide

    How it is done in development

    What SCA, SAST, DAST or image scanning actually find, how a software bill of materials and VEX are produced, what to block in CI/CD and how KEV and EPSS lead to a decision to report under Article 14.

    Open DevSecOps

    My case is different

    Bespoke development, SaaS, open source, hardware with third-party firmware, integration of third-party components and reporting under Article 14 in specific situations.

    Open the FAQ

    Official sources

    The decision logic of the calculator is based on these sources, as of 8 August 2026. What binds is the text of the legislation, not our reading of it.

    Regulation (EU) 2024/2847 (Cyber Resilience Act) ↗ The binding text in English. Scope in Article 2, definitions in Article 3 (including points 1, 2, 13, 14, 16, 17, 22 and 30), categories in Articles 7 and 8, manufacturer obligations in Article 13, reporting in Article 14, authorised representative in Article 18, importers in Article 19, distributors in Article 20, change of role in Articles 21 and 22, open-source software stewards in Article 24, presumption of conformity in Article 27, conformity assessment in Article 32, penalties in Article 64, transitional provisions in Article 69, dates in Article 71, category lists in Annexes III and IV. Commission Implementing Regulation (EU) 2025/2392 ↗ The technical description of the categories of important and critical products from Annexes III and IV. Dated 28 November 2025, published 1 December 2025. The basis for the product category step. Commission — CRA implementation ↗ An overview of the implementing and delegated acts and their status. The source for the statement that the delegated act on European cybersecurity certification schemes under Article 27(9) is planned for the fourth quarter of 2026 and has not been adopted as of 8 August 2026. Commission — CRA standardisation ↗ The status of the harmonised standards and standardisation request M/606. The source for the statement that as of 8 August 2026 no harmonised standard for the CRA is cited in the Official Journal, and therefore that standards cannot be "fully applied" for class I. Commission guidance on the application of the CRA (27 July 2026) ↗ Communication C(2026) 5252 — scope, remote data processing solutions, open source, substantial modification, support period, reporting. Non-binding, but the best available steer on borderline cases. Commission — reporting under the CRA ↗ The official overview of the reporting obligations applicable from 11 September 2026, the recipients of notifications and the status of the single reporting platform. ENISA — single reporting platform (SRP) ↗ The status of the platform under Article 16 and guidance on registering manufacturer representatives. The basis for the recommendation to arrange access in advance. Commission Recommendation 2003/361/EC ↗ The definition of microenterprises and small and medium-sized enterprises referred to in Article 3, point (19), of the regulation. The basis for the note on simplified documentation and on the exemption from the fine for a missed early warning. Ministry of Industry and Trade — draft Czech implementing act ↗ The draft act on cybersecurity requirements for products with digital elements, published 3 July 2026. Not adopted as of 8 August 2026; that changes nothing about the obligations under the regulation, which is directly applicable.
    Content valid as of 8 August 2026

    When the result comes out as manufacturer

    Annex I requirements
    belong in development,
    not in documents.

    Product threat modelling, secure development reviews, vulnerability management and inputs for the technical documentation under Annex VII. Tell us what the calculator gave you and where you stand today.