Most CRA projects start in the wrong place: with a risk assessment, a standard or a template. The first job is simpler and decides everything that follows. Three questions, in this order:

  1. Scope. Does the CRA apply to this product at all?
  2. Role. Who are we for this product: manufacturer, importer, distributor?
  3. Class. How risky is the product type, and does an outside body have to assess it?

Answer them per product, write down why, and keep the record. An answer without a reason cannot be defended later.

1. Scope: is it a product with digital elements?

The CRA covers products with digital elements made available on the EU market (Article 2). Three conditions must all be met.

It is software or hardware. That includes components placed on the market separately: a firmware image, a microcontroller, a software library sold as a product (Article 3(1)).

It has a data connection. Direct or indirect, logical or physical. Wi-Fi, Bluetooth, a cable, a fieldbus, an app, a cloud link, or a USB port to a PC. A sensor that only talks to a gateway still has a data connection, because the gateway talks on.

It is supplied in the course of a commercial activity. Paid or free. A free app that earns money from ads, data, subscriptions or paid support is commercial. Open source is outside the CRA only when those who supply it do not monetise it.

The backend counts. If your product needs a cloud or app service that you designed, or had designed, for it to work, that service is part of the product (remote data processing, Article 3(2)). Your risk assessment and vulnerability handling must cover it. A website that only advertises the product does not count. A pure software service that is not tied to a product you supply is generally not a product with digital elements; it may fall under NIS2 instead.

What is excluded

Products already covered by their own sector rules: medical devices, vehicles under EU type-approval, certified aviation products and marine equipment. Spare parts that replace identical components made to the same specification. Products developed exclusively for national security or defence (Article 2).

Read the vehicle exclusion carefully. Type-approved vehicles and their systems are out. Aftermarket accessories, diagnostic dongles, dashcams and many charging stations are not type-approved, so they can be in scope. This is a common gap for automotive suppliers.

2. Role: who are you for this product?

Your role decides your duties. One company can hold several roles for one product.

RoleWho it isExample
ManufacturerDevelops or has the product made, and markets it under its own name or trademark.A company in Bursa designs a smart thermostat and sells it in Germany under its own brand.
ImporterEstablished in the EU, places on the EU market a product carrying the name of a non-EU manufacturer.A German company imports that thermostat.
DistributorMakes the product available without changing it, and is neither manufacturer nor importer.An electronics retailer in the Netherlands.
Authorised representativeEstablished in the EU, holds a written mandate from the manufacturer for specific tasks.A compliance service that keeps the technical file available for authorities.

Two rules surprise people. Your own brand makes you the manufacturer: an importer or distributor that sells a product under its own name carries every manufacturer obligation (Article 21). White-labelling does not avoid the CRA. A substantial modification makes you the manufacturer of the modified product (Articles 21 and 22).

Manufacturers outside the EU carry the full manufacturer obligations. Where an importer brings their products into the EU, the importer must check their work before selling (Article 19).

3. Class: how risky is the product type?

ClassWhat it isExamplesConformity route
DefaultMost productsSmart plug, printer, connected coffee machine, industrial sensor, most appsSelf-assessment (Module A)
Important, Class IListed in Annex III, Class IRouter, operating system, VPN, password manager, smart door lock, security camera, baby monitorSelf-assessment only if harmonised standards, common specifications or certification are applied in full; otherwise a notified body
Important, Class IIListed in Annex III, Class IIFirewall appliance, intrusion detection system, hypervisor, tamper-resistant microcontrollerNotified body, or certification at level "substantial"
CriticalListed in Annex IVSmartcard, secure element, smart meter gatewayEuropean certification where required; otherwise as Class II

The class follows the core functionality (Article 7(1)). A product falls into a category only if that category is what it is essentially for. A home router with a firewall feature is a router, not a firewall appliance. A thermostat with a secure element inside stays in the default class. The secure element's own manufacturer deals with the secure element's class. Building an important component into your product does not make your product important. The Commission's Implementing Regulation (EU) 2025/2392 describes each category in technical terms; use it for borderline cases.

Why Class I matters right now. Self-assessment for Class I depends on applying a harmonised standard, a common specification or a certification scheme in full (Article 32(2)). As of autumn 2026, no harmonised standard for the CRA has been cited in the Official Journal. Unless that changes before you place the product on the market, a Class I product needs a notified body, and notified-body capacity is limited. Check early.

The most common mistakes

  • "It's only a component." Components placed on the market separately are products with digital elements.
  • "It only connects by USB." A physical data connection is a data connection.
  • "Our app is free." Free with monetisation is commercial.
  • "We are only the distributor", while selling under your own brand. Then you are the manufacturer.
  • Choosing the class by a feature instead of the core functionality.
  • Forgetting the backend your device needs to work.
  • Not writing down the reasoning.

If the answer is yes

Two dates apply. Article 14 reporting already applies, since 11 September 2026, to every in-scope product on the market, whatever its class and whenever it was sold. Everything else applies from 11 December 2027: the essential requirements of Annex I, vulnerability handling, the technical file, the EU declaration of conformity and the CE marking. Units placed on the market before that date stay outside the product requirements unless they are substantially modified later (Article 69(2)), but reporting covers them.

If the answer is no, keep the record anyway. Products change. Adding Bluetooth to next year's model can bring it into scope.

This article explains Regulation (EU) 2024/2847 in plain words. It is not legal advice.