Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

Which software products are in scope of the CRA?

Updated

A product with digital elements is a software or hardware product and its remote data processing solutions, including components placed on the market separately (Article 3(1)). Class (default, important I/II, critical) changes the Article 32 path, not Article 71 dates. Not legal advice. Does not start a clock.

CRA products-in-scope guide, last verified 9 September 2026 against Regulation (EU) 2024/2847 Articles 2, 3(1)–(2), 7–8, 32 and 71 and Annexes III and IV, Commission Implementing Regulation (EU) 2025/2392 (technical descriptions under Article 7(4); recitals 3–5 and 7 say examples are illustrative and not exhaustive), the European Commission's CRA pages and 27 July 2026 guidance (guidance, not the regulation), and ENISA product-security materials (agency guidance, not the regulation). It is not legal advice, not a filing, not a product-class determination, and not a substitute for counsel.

This is product class, not YOUR class

Audience: a CTO, founder, product, or compliance lead at an organisation that might make products with digital elements available on the Union market. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the CRA applies, that YOU are a manufacturer, that a product with digital elements has been made available on the Union market, or that YOUR product sits in default, important class I, important class II, or critical.

The CRA is Regulation (EU) 2024/2847 of 23 October 2024, OJ L 2024/2847, 20.11.2024. ELI: http://data.europa.eu/eli/reg/2024/2847/2024-11-20. It is a regulation, directly applicable. Last verified 9 September 2026. Not legal advice.

  • Statute versus guidance: Articles 2, 3(1)–(2), 7–8, 32 and 71, and Annexes III and IV, are legal requirements only if they apply. Commission Implementing Regulation (EU) 2025/2392 specifies technical descriptions of those Annex categories under Article 7(4) — an implementing act, not a rewrite of the Annex headings. Its recitals 3–5 and 7 give examples that the act itself calls illustrative and not exhaustive. Commission CRA pages and the 27 July 2026 Commission guidance are Commission materials — guidance, not the regulation. ENISA product-security materials are agency guidance, not the regulation.
  • The CRA overview on this site is the pillar page. The who-is-covered guide on this site is the economic-operator roles page. The SaaS-scope guide on this site is the remote-processing versus service page. The readiness-checklist guide on this site is the end-to-end CRA readiness page. A dedicated vulnerability-management guide is not on this site yet. Naming it is not a link.
  • The statute-clock Article 14 guide on this site is the CRA Article 14 page under breach reporting. The CRA-cluster Article 14 overview on this site is the cluster reporting page. Those two pages agree on the marks. They are not unpublished HC4 siblings.

Product with digital elements — Articles 2 and 3, not YOUR facts

Article 3(1), quoted: 'product with digital elements' means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately. That is the legal requirement. This page does not find that YOUR offering is that product.

Article 3(2), quoted: 'remote data processing' means data processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the product with digital elements from performing one of its functions. This page does not find that YOUR cloud path is in or out.

Article 2(1): this Regulation applies to products with digital elements made available on the market, the intended purpose or reasonably foreseeable use of which includes a direct or indirect logical or physical data connection to a device or network. Articles 2(2)–(7) set exclusions. This page does not run those tests for YOU. Last verified 9 September 2026. Not legal advice.

Risk classes — default, important I, important II, critical

The CRA is risk-based. Default products with digital elements, important products in class I and class II (Annex III), and critical products (Annex IV) take different conformity-assessment paths under Article 32. Class does not change Article 71 dates: Article 14 still applies from 11 September 2026; full essential-requirements application remains 11 December 2027. This page does not classify YOUR product. Last verified 9 September 2026. Not legal advice.

  • Article 7(1) second sentence: integrating a product that has Annex III core functionality does not in itself render the product in which it is integrated subject to Article 32(2) and (3). This page does not run that integration test for YOU.
  • Article 7(2) criteria (cybersecurity function, or a function carrying a significant risk of adverse effects) explain why Annex III categories sit there. They are not a substitute for matching core functionality to a listed category. This page does not score YOUR risk against Article 7(2).
Product classes as Articles 7–8, 32 and Annexes III–IV state them (not YOUR class; not a determination; not legal advice)
ClassWhat the regulation saysWhat this page does not doKind of text
Default products with digital elementsProducts in scope that do not have the core functionality of an Annex III or Annex IV category. Article 32(1): the manufacturer demonstrates conformity by internal control (module A), EU-type examination, full quality assurance, or, where available and applicable, a European cybersecurity certification scheme.Does not find that YOUR product is a default product.Articles 2 and 32(1). Legal requirement only if the CRA applies.
Important — class I (Annex III)Article 7(1): products which have the core functionality of a product category set out in Annex III. Class I is the first list in that annex (nineteen categories). Article 32(2) tightens the path when harmonised standards, common specifications, or a certification scheme at assurance level at least 'substantial' have not been applied.Does not place YOUR product in class I. Does not treat a listed category as YOUR product.Article 7; Annex III class I; Article 32(2). Legal requirement.
Important — class II (Annex III)Annex III class II: four categories (hypervisors and container runtime systems; firewalls, intrusion detection and prevention systems; tamper-resistant microprocessors; tamper-resistant microcontrollers). Article 32(3): EU-type examination, full quality assurance, or a certification scheme at assurance level at least 'substantial'.Does not place YOUR product in class II.Article 7; Annex III class II; Article 32(3). Legal requirement.
Critical (Annex IV)Article 8 and Annex IV: three categories (hardware devices with security boxes; smart-meter gateways and other devices for advanced security purposes, including for secure cryptoprocessing; smartcards or similar devices, including secure elements). Article 32(4): a European cybersecurity certification scheme in accordance with Article 8(1), or, where those conditions are not met, the class II procedures.Does not place YOUR product in Annex IV.Article 8; Annex IV; Article 32(4). Legal requirement.

Annex III class I — statutory list, not YOUR product

Annex III class I is the regulation's list of important class I categories. The headings below are the statutory list. Commission Implementing Regulation (EU) 2025/2392 Annex I adds technical descriptions and 'includes but is not limited to' examples; recital 7 of that implementing act says those examples are for illustrative purposes only and are not an exhaustive list. This page does not treat an implementing example as YOUR product. Last verified 9 September 2026. Not legal advice.

Annex III class I as Regulation (EU) 2024/2847 lists the categories (statutory list; not YOUR class; not a determination; not legal advice)
Annex III class IStatutory categoryKind of textWhat this page does not do
1Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readersStatutory list — Annex III class I.Does not find that YOUR identity or access product is this category.
2Standalone and embedded browsersStatutory list — Annex III class I.Does not find that YOUR browser or embedded webview is this category.
3Password managersStatutory list — Annex III class I.Does not find that YOUR credential store is this category.
4Software that searches for, removes, or quarantines malicious softwareStatutory list — Annex III class I.Does not find that YOUR detection product is this category.
5Products with digital elements with the function of virtual private network (VPN)Statutory list — Annex III class I.Does not find that YOUR tunnel product is this category.
6Network management systemsStatutory list — Annex III class I.Does not find that YOUR management plane is this category.
7Security information and event management (SIEM) systemsStatutory list — Annex III class I.Does not find that YOUR logging product is this category.
8Boot managersStatutory list — Annex III class I.Does not find that YOUR boot path is this category.
9Public key infrastructure and digital certificate issuance softwareStatutory list — Annex III class I.Does not find that YOUR PKI product is this category.
10Physical and virtual network interfacesStatutory list — Annex III class I.Does not find that YOUR interface is this category.
11Operating systemsStatutory list — Annex III class I.Does not find that YOUR OS or runtime is this category.
12Routers, modems intended for the connection to the internet, and switchesStatutory list — Annex III class I.Does not find that YOUR networking product is this category.
13Microprocessors with security-related functionalitiesStatutory list — Annex III class I.Does not find that YOUR processor is this category.
14Microcontrollers with security-related functionalitiesStatutory list — Annex III class I.Does not find that YOUR microcontroller is this category.
15Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalitiesStatutory list — Annex III class I.Does not find that YOUR ASIC or FPGA is this category.
16Smart home general purpose virtual assistantsStatutory list — Annex III class I.Does not find that YOUR assistant is this category.
17Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systemsStatutory list — Annex III class I.Does not find that YOUR home product is this category.
18Internet connected toys covered by Directive 2009/48/EC that have social interactive features (e.g. speaking or filming) or that have location tracking featuresStatutory list — Annex III class I.Does not find that YOUR connected toy is this category.
19Personal wearable products to be worn or placed on a human body that have a health monitoring (such as tracking) purpose and to which Regulation (EU) 2017/745 or (EU) 2017/746 do not apply, or personal wearable products that are intended for the use by and for childrenStatutory list — Annex III class I.Does not find that YOUR wearable is this category.

Annex III class II — statutory list, not YOUR product

Annex III class II is the regulation's shorter important-product list. Article 32(3) is the stricter path. Last verified 9 September 2026. Not legal advice.

Annex III class II as Regulation (EU) 2024/2847 lists the categories (statutory list; not YOUR class; not a determination; not legal advice)
Annex III class IIStatutory categoryKind of textWhat this page does not do
1Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environmentsStatutory list — Annex III class II.Does not find that YOUR hypervisor or container runtime is this category.
2Firewalls, intrusion detection and prevention systemsStatutory list — Annex III class II.Does not find that YOUR firewall or IDS/IPS is this category.
3Tamper-resistant microprocessorsStatutory list — Annex III class II.Does not find that YOUR processor is this category.
4Tamper-resistant microcontrollersStatutory list — Annex III class II.Does not find that YOUR microcontroller is this category.

Annex IV — statutory list of critical products, not YOUR product

Annex IV is the regulation's list of critical products with digital elements. Article 8 and Article 32(4) set the path. Last verified 9 September 2026. Not legal advice.

Annex IV as Regulation (EU) 2024/2847 lists the categories (statutory list; not YOUR class; not a determination; not legal advice)
Annex IVStatutory categoryKind of textWhat this page does not do
1Hardware Devices with Security BoxesStatutory list — Annex IV.Does not find that YOUR hardware is this category.
2Smart meter gateways within smart metering systems as defined in Article 2, point (23) of Directive (EU) 2019/944 and other devices for advanced security purposes, including for secure cryptoprocessingStatutory list — Annex IV.Does not find that YOUR gateway is this category.
3Smartcards or similar devices, including secure elementsStatutory list — Annex IV.Does not find that YOUR card or secure element is this category.

Statutory list versus implementing descriptions and illustrative examples

Do not treat a Commission example as the annex heading, and do not treat the annex heading as optional because a FAQ exists. Last verified 9 September 2026. Not legal advice.

Statute versus implementing act versus guidance (not a ranking; not legal advice; last verified 9 September 2026)
TextWhat it isWhat this page does not do
Regulation (EU) 2024/2847 Annex III and Annex IVStatutory list of important (class I and class II) and critical product categories. Legal requirement only if the CRA applies.Does not add or drop a category. Does not treat a blog paraphrase as the list.
Commission Implementing Regulation (EU) 2025/2392 Annexes I and IITechnical descriptions of those categories, adopted under Article 7(4). An implementing act, not a substitute for the Annex III/IV headings.Does not apply those descriptions to YOUR product.
Implementing Regulation (EU) 2025/2392 recitals 3–5 and 7Recitals of that implementing act. Recital 7: examples of products whose core functionality meets a technical description are for illustrative purposes only and are not an exhaustive list. Recital 3: integrating an embedded browser into a news app does not in itself render the news app subject to the browser class. Recital 5: a smartphone typically integrates an operating system or password manager but is generally not considered to meet those category descriptions because its core functionality is different.Does not treat a recital example as YOUR class. Does not run the news-app or smartphone test for YOU.
Commission CRA pages and 27 July 2026 guidance (C(2026) 5252)Commission materials. Guidance, not the regulation. The Commission page itself calls the July 2026 text non-binding. It addresses remote data processing, substantial modification, support periods, and reporting.Does not treat that guidance as rewriting Annex III, Annex IV, 11 September 2026, or 11 December 2027.
ENISA product-security pagesAgency guidance on product security. Not the regulation.Does not treat an ENISA FAQ as classifying YOUR product.

Decision aid — questions versus cited text, not a class picker

Walk this table with counsel. It is a reading aid for the cited text. It is not a CRA product-class picker, not a determination, and not YOUR class. Last verified 9 September 2026. Not legal advice.

Decision aid (not a determination; not a product-class picker; not legal advice; this page does not place YOUR product)
QuestionWhat the cited text saysWhat this page does not do
Is it a product with digital elements made available on the Union market, with a data connection?Article 3(1) definition; Article 2(1) scope (intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network); Article 3(21)–(22) placing / making available on the market.Does not find that YOUR offering is in scope.
Does another Union act named in Article 2 already cover it?Article 2(2)–(4) and 2(6)–(7) exclusions (quoted in the exclusions table). Article 2(5) lets the Commission limit or exclude other sector Union rules by delegated act where those rules achieve the same or a higher level of protection.Does not run YOUR exclusion. Does not invent a complete exclusion catalogue beyond the articles quoted.
Does it have the core functionality of an Annex III class I category?Article 7(1) first sentence: products with digital elements which have the core functionality of a product category set out in Annex III are important products. Match the statutory heading, then read the 2025/2392 technical description. Recital 4 of that implementing act: additional functions do not in themselves mean the product lacks that core functionality.Does not place YOUR product in class I.
Does it have the core functionality of an Annex III class II category?Same Article 7(1) test against the class II list. Article 32(3) is the path if it does.Does not place YOUR product in class II.
Does it have the core functionality of an Annex IV category?Article 8 and Annex IV. Article 32(4) is the path. Where no Article 8(1) delegated act has been adopted, Annex IV products follow the class II procedures.Does not place YOUR product in Annex IV.
If it is in scope and none of those core-functionality matches hold, is it default?Default is the residual in-scope class. Article 32(1) is the path. Absence from Annex III/IV is not absence from the CRA.Does not find that YOUR product is default.
Does integrating an Annex III or Annex IV component reclassify the host?Article 7(1) second sentence: integration of an Annex III-core-functionality product does not in itself render the host subject to Article 32(2) and (3). Implementing recital 3 uses a news-app-with-embedded-browser example (illustrative, not exhaustive).Does not run YOUR integration test.
Does NIS2 essential-entity or important-entity status classify the CRA product?NIS2 (Directive (EU) 2022/2555) is a different instrument on entities. The CRA is a regulation on products with digital elements. Recital 12 points to NIS2 for in-scope cloud computing services. Recital 12 is a recital, not an operative article.Does not treat NIS2 status as a CRA Annex III/IV class.

Exclusions — Article 2 as quoted, not a complete catalogue

Article 2(2)–(7) name the exclusions this page quotes. Recitals 25–27 explain the sector overlap (medical devices, vehicles, aviation). Footnote 36 to Article 2(4) identifies Directive 2014/90/EU as the marine-equipment directive. This page does not invent a complete exclusion catalogue, and does not run these exclusions for YOU. Last verified 9 September 2026. Not legal advice.

Article 2 exclusions as the regulation states them (not a complete catalogue; not YOUR exclusion; not legal advice)
ProvisionWhat the regulation saysKind of textWhat this page does not do
Article 2(2)(a)–(c)This Regulation does not apply to products with digital elements to which Regulation (EU) 2017/745, Regulation (EU) 2017/746, or Regulation (EU) 2019/2144 apply. Recital 25: medical devices and in vitro diagnostic medical devices. Recital 27: type-approval of vehicles.Legal requirement — Article 2(2). Recitals 25 and 27 are recitals, not operative articles.Does not find that YOUR product is a medical device or a vehicle system.
Article 2(3)This Regulation does not apply to products with digital elements that have been certified in accordance with Regulation (EU) 2018/1139. Recital 27: civil aviation airworthiness, including software.Legal requirement — Article 2(3).Does not find that YOUR product is aviation-certified.
Article 2(4)This Regulation does not apply to equipment that falls within the scope of Directive 2014/90/EU. Footnote 36: Directive 2014/90/EU of 23 July 2014 on marine equipment.Legal requirement — Article 2(4).Does not find that YOUR product is marine equipment.
Article 2(5)Application to products covered by other Union rules that address all or some of the Annex I risks may be limited or excluded where that is consistent with the overall framework and the sectoral rules achieve the same or a higher level of protection. The Commission may adopt delegated acts specifying such limitation or exclusion.Legal requirement — Article 2(5), plus any delegated act that exists. This page does not inventory those delegated acts.Does not invent a further exclusion list.
Article 2(6)This Regulation does not apply to spare parts that are made available on the market to replace identical components in products with digital elements and that are manufactured according to the same specifications as the components that they are intended to replace.Legal requirement — Article 2(6).Does not find that YOUR SKU is a spare part.
Article 2(7)This Regulation does not apply to products with digital elements developed or modified exclusively for national security or defence purposes or to products specifically designed to process classified information.Legal requirement — Article 2(7).Does not find that YOUR product is a national-security product.

Remote data processing and SaaS — named, not decided here

Article 3(1) includes remote data processing solutions in the product. Article 3(2) defines that processing. Recital 12: cloud solutions constitute remote data processing solutions within the meaning of this Regulation only if they meet that definition. Recital 12 continues: websites that do not support the functionality of a product with digital elements, or cloud services designed and developed outside the responsibility of a manufacturer of a product with digital elements, do not fall within the scope of this Regulation. Recital 12 points to NIS2 (Directive (EU) 2022/2555) for cloud computing services and cloud service models, such as Software as a Service (SaaS), Platform as a Service (PaaS) or Infrastructure as a Service (IaaS). Recital 12 is a recital, not an operative article.

This page does not decide that standalone browser-only SaaS is in or out of the CRA. The SaaS-scope guide on this site is the remote-processing versus service page. Commission guidance of 27 July 2026 (guidance, not the regulation) addresses remote data processing. It is not a rewrite of Articles 2 and 3 or of Article 71's dates.

The in-repo CRA control-set comment says standalone browser-only SaaS is generally out of CRA scope. That sentence is this product's own illustrative readiness mapping, not a legal determination. Counsel applies Articles 2 and 3 to YOUR facts.

Article 71 dates — class does not move them

Last verified 9 September 2026 against Article 71 on EUR-Lex. Article 71(2): this Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026. Those dates are not one number. Product class does not change them. This page does not start that clock.

As of last verification on 9 September 2026, Article 14's application date is in two days (11 September 2026). Full essential-requirements / CE / market-surveillance application remains 11 December 2027. The live Article 14 reporting guide on this site is the ladder: 24-hour early warning, 72-hour notification, 14-day final report on the actively-exploited track. This page does not file with a CSIRT or ENISA.

What to do now

As of last verification on 9 September 2026, Article 14 applies from 11 September 2026. Full essential-requirements application remains 11 December 2027. The list below is operational preparation. It is not a determination that the CRA applies to YOU, that you are a manufacturer, that YOUR product has an Annex III or Annex IV class, or that a reporting clock has started. Walk it with counsel.

  • Ask counsel whether YOU make a product with digital elements available on the Union market (Articles 2 and 3). This page does not run that test. Marking CRA in an obligation map is not that determination.
  • Ask counsel which class, if any, YOUR product has under Annex III or Annex IV, reading the statutory heading and then the 2025/2392 technical description. This page does not classify it. This product does not ship a CRA product-class picker.
  • If counsel says Article 14 may apply, open the live Article 14 reporting guide on this site for the 24-hour / 72-hour / 14-day ladder. This page does not start that clock.
  • Do not treat Commission or ENISA guidance as the regulation. Do not treat an implementing-act example as the annex heading. Do not treat this product's CRA control-set as a conformity-assessment file.
  • The who-is-covered guide on this site is the economic-operator roles page. The SaaS-scope guide on this site is the remote-processing versus service page. The readiness-checklist guide on this site is the end-to-end CRA readiness page. A dedicated vulnerability-management guide is not on this site yet. Naming it is not a link.

Checklist

This is a question list, not a filing, and not YOUR class. Walk it with counsel. The live Article 14 reporting guide on this site is the ladder. The reporting-deadlines page on this site is the statute table of clocks.

  • Does the CRA apply? Product with digital elements made available on the Union market — Articles 2 and 3. This page does not run that test.
  • Which class, if any — default, important class I, important class II, or critical? Annexes III and IV, then Implementing Regulation (EU) 2025/2392 technical descriptions. This page does not place YOUR product.
  • Article 14 from 11 September 2026: 24-hour early warning, 72-hour notification, 14-day final report on the actively-exploited track. Class does not change that date. This page does not start that clock.
  • Full application from 11 December 2027: essential requirements, EU declaration of conformity, CE marking. Readiness in this product is not CE marking.
  • Document the assessment, including a not-in-scope or default-class decision. This page does not keep YOUR file.

Where this shows up in ShipReady Metrics

The bundled framework key cra is customer-visible. Its version label is Regulation (EU) 2024/2847 (starter subset). It is not in INTERNAL_TESTER_ONLY_FRAMEWORKS. The control-set is a starter subset, illustrative, to be tailored by a compliance owner; not legal advice; not full conformity-assessment detail. Readiness is not compliance, not CE marking, and not a market-surveillance determination. An in-scope mark on the obligation map is not a product-class determination and is not a finding that a product sits in Annex III or Annex IV.

If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour / 72-hour / 14-day ladder from recorded awareness for findings the organisation classified as CRA-in-scope actively exploited vulnerabilities. That tracker does not start an Article 14 clock, does not decide that the CRA applies, does not classify Annex III/IV, and does not file with a CSIRT or ENISA. A named human still submits. A named human still decides class with counsel.

The obligation map lists frameworks the organisation has marked in-scope, including cra if that mark is set. Marking cra in-scope is not a determination that you are a manufacturer, that a product with digital elements has been made available on the Union market, or that the product is important class I, important class II, or critical.

Asset inventory exists as signed-in app → Lifecycle (End of Life). It lists versioned runtimes and datastores (product, version, hosting, support and end-of-life dates) from declared entries and connector scans. It does not classify those assets against CRA Annex III or Annex IV. AI inventory exists as signed-in app → Compliance → AI governance. It lists org-authored AI systems with EU AI Act-style risk tiers (high / limited / minimal), use-case, and governance artifacts. It does not classify those systems against CRA Annex III or Annex IV. Those inventories can anchor a product register only as a list of what the organisation already tracks. They are vendor-neutral on CRA class. This product does not ship a CRA product-class picker.

The cyber risk register lives under Security. It is not an Article 14 file and not an Annex III/IV classification. This page does not document a public demo URL. There is no public CRA demo path.

Primary sources (last verified 9 September 2026)

Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.

Regulation (EU) 2024/2847 of 23 October 2024 (Cyber Resilience Act), Articles 2, 3(1)–(2), 7–8, 32 and 71 and Annexes III and IV, is a legal requirement only if it applies. Commission Implementing Regulation (EU) 2025/2392 of 28 November 2025 specifies technical descriptions of important and critical categories under Article 7(4); its recitals 3–5 and 7 label examples as illustrative and not exhaustive. The European Commission's CRA policy page and 27 July 2026 guidance (C(2026) 5252) are Commission materials, not the regulation. ENISA's product-security pages are agency guidance, not the regulation. Directive (EU) 2022/2555 is a different instrument; the NIS2 incident-reporting guide is on this site. These are not a complete world list. Not legal advice.

The CRA overview on this site is the pillar page. The who-is-covered guide on this site is the economic-operator roles page. The SaaS-scope guide on this site is the remote-processing versus service page. The statute-clock Article 14 guide on this site is the live ladder. The CRA-cluster Article 14 overview on this site is the cluster page. The reporting-deadlines page on this site is the statute table of clocks. The readiness-checklist guide on this site is the end-to-end CRA readiness page. A dedicated vulnerability-management guide is not on this site yet. Naming it is not a link.

Frequently asked questions

Is this legal advice?

No. It is a products-in-scope guide distilled from Regulation (EU) 2024/2847 Annexes III and IV and from Implementing Regulation (EU) 2025/2392, with Commission and ENISA materials labelled as guidance, not the regulation. Whether the CRA applies to YOUR product, and which class it has, are legal questions for counsel on your facts. This page does not start a clock.

Does ShipReady classify our product?

No. This product does not ship a CRA product-class picker and does not place YOUR product in default, important class I, important class II, or critical. A named human still decides class with counsel. The signed-in app does not file with a CSIRT or ENISA and does not start an Article 14 clock.

Does an in-scope mark mean Annex III?

No. Marking the bundled framework key cra in-scope on the obligation map is not a determination that you are a manufacturer, that a product with digital elements has been made available on the Union market, or that the product has the core functionality of an Annex III or Annex IV category. Counsel applies Articles 2, 3, 7 and 8 to YOUR facts.

Is browser-only SaaS automatically out of the CRA?

This page does not decide that. Recital 12 discusses cloud services designed and developed outside the responsibility of a manufacturer, and points to NIS2 for in-scope cloud computing services. Recital 12 is a recital, not an operative article. The in-repo CRA control-set comment is this product's illustrative mapping, not a legal determination. The SaaS-scope guide on this site is the remote-processing versus service page.

Does NIS2 essential-entity status classify a CRA product?

No. NIS2 (Directive (EU) 2022/2555) is a directive on essential and important entities. The CRA is a regulation on products with digital elements made available on the Union market. Entity status under NIS2 is not an Annex III or Annex IV class. Filing a NIS2 Article 23 report does not discharge CRA Article 14.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.