What Is the Legal Scope of the EU Cyber Resilience Act?
As the European Union moves aggressively to fortify its digital borders, technology leaders worldwide are asking a fundamental question: does our software or connected hardware fall within the regulatory net? Understanding the exact CRA scope products with digital elements is the crucial first step before allocating engineering budgets for compliance.
Under Article 2 of the regulation, the EU Cyber Resilience Act applies to all “products with digital elements” (PDE) made available on the European Union market. This legally defined term encompasses any software or hardware product and its remote data processing solutions whose intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Whether you produce smart consumer gadgets, enterprise microservices, or industrial automation hardware, evaluating your CRA scope products with digital elements is an urgent commercial priority across the global tech sector.
Table of Contents
- Who Does the Cyber Resilience Act Apply To Across the Supply Chain?
- How Are Products Classified Under CRA Risk Categories (Default, Class I, Class II)?
- Which Products and Technologies Are Officially Exempt from the CRA?
- What Are the Specific Obligations for Importers and Non-EU Manufacturers?
- What Is the 5-Step Diagnostic Self-Assessment Checklist for Product Scope?
- How Can Muteki Group Help You Audit Your Product Scope?
Who Does the Cyber Resilience Act Apply To Across the Supply Chain?
The Cyber Resilience Act does not just regulate original equipment manufacturers (OEMs); it establishes a comprehensive chain of custody across the entire commercial lifecycle. When determining who does the Cyber Resilience Act apply to, the regulation assigns distinct legal duties to four primary economic operators across the European single market:
| Economic Operator | Legal Definition Under the CRA | Core Compliance & Due Diligence Obligations |
|---|---|---|
| Manufacturers | Any natural or legal person who develops or manufactures a product with digital elements or has it designed under their name/trademark. | Full cybersecurity-by-design, SBOM generation, technical documentation, CE marking, and mandatory vulnerability reporting. |
| Authorized Representatives | Any natural or legal person established in the EU who has received a written mandate from a non-EU manufacturer. | Maintains EU technical files, liaises with national market surveillance authorities, and verifies conformity declarations. |
| Importers | Any entity established in the EU that places a product from a third country on the European market. | Must verify that the non-EU manufacturer carried out appropriate conformity assessments and generated technical files before import. |
| Distributors | Any natural or legal person in the supply chain (other than the manufacturer or importer) making a product available. | Must act with due care, verify CE markings, and refrain from making non-compliant products available. |
Every commercial entity in this distribution chain is legally responsible for verifying that hardware and software distributed in the EU align with defined European cybersecurity standards.
How Are Products Classified Under CRA Risk Categories (Default, Class I, Class II)?
Not all connected devices carry the same level of societal risk. To prevent excessive burdens on low-risk software while enforcing rigorous oversight on critical infrastructure, the EU has established a multi-tiered CRA product classification framework under Annex III and Annex IV to categorize the broader CRA scope products with digital elements:
- 1. Default (Standard) Products with Digital Elements (90% of Market): Covers general consumer apps, smart home lighting, video editing software, photo management tools, and games. Manufacturers can verify compliance through internal conformity assessment (self-assessment).
- 2. Important Class I Products: Includes identity management systems, password managers, biometric authentication hardware, standalone antivirus software, network interfaces, and virtual private networks (VPNs) falling under the CRA scope products with digital elements. Requires application of harmonized European standards or third-party conformity audits.
- 3. Important Class II Products: Includes operating systems (desktop, mobile, server), hypervisors, industrial firewalls, public key infrastructure (PKI) routers, and tamper-resistant microprocessors. Mandates mandatory third-party assessment by an accredited European Notified Body.
- 4. Critical Products with Digital Elements: Specialized cryptographic modules, smart meters, and hardware security modules (HSMs) directly tied to critical European infrastructure networks.
“Accurate product classification dictates whether you can self-certify under internal QA or if you must spend months undergoing accredited third-party notified body laboratory audits.” — Muteki Group Lead Compliance Architect
Which Products and Technologies Are Officially Exempt from the CRA?
While the CRA scope products with digital elements is broad, the European Commission has established specific statutory exemptions to prevent regulatory overlap with existing sectoral legislation:
- Medical Devices & In Vitro Diagnostics: Products strictly regulated under EU Regulation 2017/745 (MDR) and Regulation 2017/746 (IVDR) are fully exempt from the CRA scope products with digital elements requirements.
- Civil Aviation Equipment: Certified avionics and airborne equipment governed by Regulation (EU) 2018/1139.
- Motor Vehicles & Automotive Systems: Vehicles and type-approved connected components regulated under UNECE cybersecurity regulations (UN R155 / R156) and Regulation (EU) 2019/2144.
- Non-Commercial Open-Source Software: Free and open-source software developed outside the course of a commercial activity (though open-source components integrated into commercial software remain strictly within the CRA scope products with digital elements for the commercial vendor).
- Pure Cloud SaaS Services (Without Local Software): Standalone cloud services that do not supply client software or firmware are governed primarily by the NIS2 Directive rather than the CRA.
What Are the Specific Obligations for Importers and Non-EU Manufacturers?
Non-European software and IoT vendors cannot bypass the CRA scope products with digital elements simply by operating outside EU borders. If your products are sold to European consumers or enterprises via direct distribution or online marketplaces, European importers and authorized representatives are held legally responsible under European product liability directives.
Importers are legally required to verify that the manufacturer has drawn up an EU declaration of conformity, created an accessible Software Bill of Materials (SBOM), and established a designated vulnerability disclosure channel. If an importer discovers a severe vulnerability in a product governed by the CRA scope products with digital elements, they must immediately notify the manufacturer and national market surveillance authorities.
What Is the 5-Step Diagnostic Self-Assessment Checklist for Product Scope?
To determine if your product catalog falls under the CRA scope products with digital elements, run your engineering stack through this diagnostic checklist:
- Connectivity Check: Does the product contain a direct or indirect network connection (Wi-Fi, Bluetooth, Ethernet, Cellular, USB data interface)? (If Yes, in scope).
- Commercial Availability: Is the software or hardware supplied for distribution or use on the EU market in the course of a commercial activity? (If Yes, in scope).
- Sectoral Carve-Out Review: Is the system already certified under medical (MDR), automotive (UN R155), or aviation (EASA) directives? (If No, the CRA scope products with digital elements applies directly).
- Risk Tier Classification: Does the product manage passwords, VPNs, operating systems, or industrial firewalls? (Determines Standard vs. Class I/II audit requirements under CRA product classification rules).
- Reporting Preparedness: Are you ready to meet the mandatory early reporting requirements under the 11 September 2026 CRA Reporting Deadline and the CRA Vulnerability Reporting Timelines?
How Can Muteki Group Help You Audit Your Product Scope?
Navigating the intricate boundaries of CRA scope products with digital elements requires a specialized balance of deep systems engineering and European regulatory mastery. At Muteki Group, our senior cybersecurity architects and software engineers perform comprehensive product scoping audits for global hardware and software enterprises.
We analyze your codebases, microservice architectures, and firmware dependencies to establish your exact risk classification under the CRA scope products with digital elements, generate automated SBOMs, and design lean conformity roadmaps. To explore our full end-to-end compliance framework, read our EU Cyber Resilience Act Pillar Guide.
Clarify your compliance obligations before enforcement deadlines arrive. Contact the senior engineering team at Muteki Group today via our CRA Compliance Consultancy Services or visit our Contact Us Page to schedule an executive audit for all CRA scope products with digital elements in your portfolio.
Houssam Zaki