All Articles Cybersecurity & Compliance

CRA Scope Products with Digital Elements Explained

August 27, 2026
6 min read
Houssam Zaki Houssam Zaki
4.9/5
CRA Scope Products with Digital Elements Explained

What Is the Legal Scope of the EU Cyber Resilience Act?

As the European Union moves aggressively to fortify its digital borders, technology leaders worldwide are asking a fundamental question: does our software or connected hardware fall within the regulatory net? Understanding the exact CRA scope products with digital elements is the crucial first step before allocating engineering budgets for compliance.

Under Article 2 of the regulation, the EU Cyber Resilience Act applies to all “products with digital elements” (PDE) made available on the European Union market. This legally defined term encompasses any software or hardware product and its remote data processing solutions whose intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Whether you produce smart consumer gadgets, enterprise microservices, or industrial automation hardware, evaluating your CRA scope products with digital elements is an urgent commercial priority across the global tech sector.

Hardware circuit board and embedded microcontrollers evaluated for CRA scope products with digital elements
Embedded hardware microcontrollers and connected IoT architectures evaluated under the EU CRA product classification scope

Who Does the Cyber Resilience Act Apply To Across the Supply Chain?

The Cyber Resilience Act does not just regulate original equipment manufacturers (OEMs); it establishes a comprehensive chain of custody across the entire commercial lifecycle. When determining who does the Cyber Resilience Act apply to, the regulation assigns distinct legal duties to four primary economic operators across the European single market:

Economic OperatorLegal Definition Under the CRACore Compliance & Due Diligence Obligations
ManufacturersAny natural or legal person who develops or manufactures a product with digital elements or has it designed under their name/trademark.Full cybersecurity-by-design, SBOM generation, technical documentation, CE marking, and mandatory vulnerability reporting.
Authorized RepresentativesAny natural or legal person established in the EU who has received a written mandate from a non-EU manufacturer.Maintains EU technical files, liaises with national market surveillance authorities, and verifies conformity declarations.
ImportersAny entity established in the EU that places a product from a third country on the European market.Must verify that the non-EU manufacturer carried out appropriate conformity assessments and generated technical files before import.
DistributorsAny natural or legal person in the supply chain (other than the manufacturer or importer) making a product available.Must act with due care, verify CE markings, and refrain from making non-compliant products available.

Every commercial entity in this distribution chain is legally responsible for verifying that hardware and software distributed in the EU align with defined European cybersecurity standards.

How Are Products Classified Under CRA Risk Categories (Default, Class I, Class II)?

Not all connected devices carry the same level of societal risk. To prevent excessive burdens on low-risk software while enforcing rigorous oversight on critical infrastructure, the EU has established a multi-tiered CRA product classification framework under Annex III and Annex IV to categorize the broader CRA scope products with digital elements:

  • 1. Default (Standard) Products with Digital Elements (90% of Market): Covers general consumer apps, smart home lighting, video editing software, photo management tools, and games. Manufacturers can verify compliance through internal conformity assessment (self-assessment).
  • 2. Important Class I Products: Includes identity management systems, password managers, biometric authentication hardware, standalone antivirus software, network interfaces, and virtual private networks (VPNs) falling under the CRA scope products with digital elements. Requires application of harmonized European standards or third-party conformity audits.
  • 3. Important Class II Products: Includes operating systems (desktop, mobile, server), hypervisors, industrial firewalls, public key infrastructure (PKI) routers, and tamper-resistant microprocessors. Mandates mandatory third-party assessment by an accredited European Notified Body.
  • 4. Critical Products with Digital Elements: Specialized cryptographic modules, smart meters, and hardware security modules (HSMs) directly tied to critical European infrastructure networks.

“Accurate product classification dictates whether you can self-certify under internal QA or if you must spend months undergoing accredited third-party notified body laboratory audits.” — Muteki Group Lead Compliance Architect

Which Products and Technologies Are Officially Exempt from the CRA?

While the CRA scope products with digital elements is broad, the European Commission has established specific statutory exemptions to prevent regulatory overlap with existing sectoral legislation:

  • Medical Devices & In Vitro Diagnostics: Products strictly regulated under EU Regulation 2017/745 (MDR) and Regulation 2017/746 (IVDR) are fully exempt from the CRA scope products with digital elements requirements.
  • Civil Aviation Equipment: Certified avionics and airborne equipment governed by Regulation (EU) 2018/1139.
  • Motor Vehicles & Automotive Systems: Vehicles and type-approved connected components regulated under UNECE cybersecurity regulations (UN R155 / R156) and Regulation (EU) 2019/2144.
  • Non-Commercial Open-Source Software: Free and open-source software developed outside the course of a commercial activity (though open-source components integrated into commercial software remain strictly within the CRA scope products with digital elements for the commercial vendor).
  • Pure Cloud SaaS Services (Without Local Software): Standalone cloud services that do not supply client software or firmware are governed primarily by the NIS2 Directive rather than the CRA.

What Are the Specific Obligations for Importers and Non-EU Manufacturers?

Non-European software and IoT vendors cannot bypass the CRA scope products with digital elements simply by operating outside EU borders. If your products are sold to European consumers or enterprises via direct distribution or online marketplaces, European importers and authorized representatives are held legally responsible under European product liability directives.

Importers are legally required to verify that the manufacturer has drawn up an EU declaration of conformity, created an accessible Software Bill of Materials (SBOM), and established a designated vulnerability disclosure channel. If an importer discovers a severe vulnerability in a product governed by the CRA scope products with digital elements, they must immediately notify the manufacturer and national market surveillance authorities.

What Is the 5-Step Diagnostic Self-Assessment Checklist for Product Scope?

To determine if your product catalog falls under the CRA scope products with digital elements, run your engineering stack through this diagnostic checklist:

  1. Connectivity Check: Does the product contain a direct or indirect network connection (Wi-Fi, Bluetooth, Ethernet, Cellular, USB data interface)? (If Yes, in scope).
  2. Commercial Availability: Is the software or hardware supplied for distribution or use on the EU market in the course of a commercial activity? (If Yes, in scope).
  3. Sectoral Carve-Out Review: Is the system already certified under medical (MDR), automotive (UN R155), or aviation (EASA) directives? (If No, the CRA scope products with digital elements applies directly).
  4. Risk Tier Classification: Does the product manage passwords, VPNs, operating systems, or industrial firewalls? (Determines Standard vs. Class I/II audit requirements under CRA product classification rules).
  5. Reporting Preparedness: Are you ready to meet the mandatory early reporting requirements under the 11 September 2026 CRA Reporting Deadline and the CRA Vulnerability Reporting Timelines?

How Can Muteki Group Help You Audit Your Product Scope?

Navigating the intricate boundaries of CRA scope products with digital elements requires a specialized balance of deep systems engineering and European regulatory mastery. At Muteki Group, our senior cybersecurity architects and software engineers perform comprehensive product scoping audits for global hardware and software enterprises.

We analyze your codebases, microservice architectures, and firmware dependencies to establish your exact risk classification under the CRA scope products with digital elements, generate automated SBOMs, and design lean conformity roadmaps. To explore our full end-to-end compliance framework, read our EU Cyber Resilience Act Pillar Guide.

Clarify your compliance obligations before enforcement deadlines arrive. Contact the senior engineering team at Muteki Group today via our CRA Compliance Consultancy Services or visit our Contact Us Page to schedule an executive audit for all CRA scope products with digital elements in your portfolio.

Houssam Zaki

Houssam Zaki

Muteki Group

Houssam Zaki is a strategic leader and the Growth Lead at AI Tech Partners, specializing in building high-impact partnerships at the intersection of technology and business expansion. With a strong academic background from the National Aviation University and deep expertise in the UK tech ecosystem, Houssam focuses on scaling AI-driven solutions and driving long-term organizational growth. His writing offers insights into strategic development, AI integration, and the future of tech-enabled partnerships.