AnyLearn
All lessons

The Cyber Resilience Act: What It Covers and Who It Binds

Regulation (EU) 2024/2847 puts software and connected hardware under product safety law, with a CE mark for cybersecurity. This lesson sets the scope: what counts as a product with digital elements, why a cloud backend can be part of one, what sector law carves out, where open source and stewards sit, the four risk tiers from Annex III and IV, and how a reseller becomes a manufacturer.

Updated · AI-authored, review-gated · how lessons are made

Not signed in: your progress and quiz score won't be saved.
Progress1 / 11

A product law, not an organisation law

Most EU digital rules bind organisations or data. The Cyber Resilience Act, Regulation (EU) 2024/2847, binds products. It sits inside the New Legislative Framework, the same machinery that governs toys, lifts and radio equipment: meet essential requirements, assess conformity, draw up a declaration, affix a CE mark, then place the product on the market. What is new is the subject matter. For the first time, software and connected hardware carry a CE mark for cybersecurity.

The distinction decides who has to do the work.

InstrumentBindsTrigger
GDPRControllers and processorsProcessing personal data
NIS2Entities in listed sectorsBeing an in-scope organisation
Cyber Resilience ActProducts with digital elementsPlacing a product on the EU market

An organisation can sit outside NIS2 entirely and still ship a product squarely inside the CRA. Scoping the company tells you nothing about scoping the catalogue.

Full lesson text

All 11 steps on one page, for reading, reference, and search.

Show

1. A product law, not an organisation law

Most EU digital rules bind organisations or data. The Cyber Resilience Act, Regulation (EU) 2024/2847, binds products. It sits inside the New Legislative Framework, the same machinery that governs toys, lifts and radio equipment: meet essential requirements, assess conformity, draw up a declaration, affix a CE mark, then place the product on the market. What is new is the subject matter. For the first time, software and connected hardware carry a CE mark for cybersecurity.

The distinction decides who has to do the work.

InstrumentBindsTrigger
GDPRControllers and processorsProcessing personal data
NIS2Entities in listed sectorsBeing an in-scope organisation
Cyber Resilience ActProducts with digital elementsPlacing a product on the EU market

An organisation can sit outside NIS2 entirely and still ship a product squarely inside the CRA. Scoping the company tells you nothing about scoping the catalogue.

2. What counts as a product with digital elements

Article 3 defines a product with digital elements as a software or hardware product and its remote data processing solutions, including components placed on the market separately. Two conditions bring it into scope.

First, it must be made available on the market, meaning supplied for distribution or use in the course of a commercial activity. Second, its intended purpose or reasonably foreseeable use must include a direct or indirect logical or physical data connection to a device or network.

The connection test is deliberately wide. Indirect covers a sensor that never touches a network itself but writes to a gateway that does. Logical covers software talking to software with no cable involved. A standalone offline calculator is out; almost nothing else a modern vendor ships is.

Separately placed components count too, so a library sold as a product is assessed as a product, not absorbed into whatever integrates it.

3. The clause teams miss: remote data processing

The definition pulls in remote data processing solutions, and this is the provision engineering teams most often read past.

If a device or application depends on a vendor-operated backend to perform its function, that backend is part of the product. Not an adjacent service governed by other rules. Part of the product, inside the same conformity assessment, the same technical documentation, the same support period.

The test is functional necessity. Telemetry you collect for your own analytics is not the product's function. The message relay without which your chat client cannot deliver a message is.

This cuts against how most teams organise. Firmware and cloud usually sit in different repositories, different release trains, often different business units. The CRA asks for one coherent security story across the boundary, which means the risk assessment has to cross it too.

Pure software as a service with no product attached stays outside the CRA, though it may sit inside NIS2.

4. What sector law carves out

The CRA yields where existing sector law already imposes cybersecurity requirements, so the same product is not assessed twice against two regimes.

Excluded on that basis: medical devices and in-vitro diagnostic devices, motor vehicles, civil aviation equipment, and marine equipment. Each has its own framework. Also excluded are spare parts that restore a product to its original function, products developed or modified exclusively for national security or defence purposes, and products designed exclusively to process classified information.

The list is not frozen. The Commission can narrow scope by delegated act, and has: Commission Delegated Regulation (EU) 2025/1535 removed certain vehicles covered by Regulation (EU) No 168/2013.

The practical error is assuming an exclusion travels. A hospital ships an infusion pump regulated as a medical device and a separate ward-management tablet application. The pump is out. The tablet application is an ordinary product with digital elements, fully in scope.

5. Open source and the commercial activity line

The CRA does not regulate open source as such. It regulates supply in the course of a commercial activity, and that line runs through the ecosystem rather than around it.

A maintainer publishing a library for anyone to use is not a manufacturer and carries no CRA obligations. A company that takes that library, integrates it and sells the result is a manufacturer, and its due diligence duty on third-party components travels with it. The obligation follows the money, not the licence.

Between those poles, Article 24 creates a role with no equivalent in earlier product law: the open-source software steward. A steward is a legal person, typically a foundation, that systematically provides sustained support for the development of open-source products intended for commercial activities and ensures their viability.

Stewards carry a reduced set of duties: a cybersecurity policy, cooperation with market surveillance authorities, and reporting of actively exploited vulnerabilities in products they help develop. They are not subject to CRA penalties at all.

6. Scope, then tier

Scoping runs in two passes, and running them in the wrong order wastes effort.

The first pass asks whether the CRA applies at all. Commercial supply, then a data connection, then whether sector law has already claimed the product. Anything that survives all three is in scope, and every in-scope product owes the same Annex I essential requirements.

Only then does the second pass matter: which tier. The tier is read off two lists. Annex IV names critical products. Annex III splits important products into class II and class I. A product in neither annex sits in the default category, which is where most of the market lands.

The order matters because the tier question is the one people start with, and it is the cheaper question. Tier changes how much independent scrutiny your conformity assessment needs. It never changes what the product itself has to do.

flowchart TD
A["Supplied in a commercial activity?"] --> B["No: outside the CRA"]
A --> C["Yes: data connection to a device or network?"]
C --> D["No: outside the CRA"]
C --> E["Yes: already covered by sector law?"]
E --> F["Yes: that regime applies instead"]
E --> G["No: in scope, now read the tier"]
G --> H["Listed in Annex IV: critical"]
G --> I["Annex III class II: important class II"]
G --> J["Annex III class I: important class I"]
G --> K["In neither annex: default category"]

7. The four tiers and what is on the lists

The default category holds most products: ordinary business software, consumer devices with no security-specific role.

Annex III lists important products in two classes. Class I has nineteen entries, weighted toward things that guard other things. Identity and privileged access management, browsers, password managers, malware detection software, VPN products, network management and SIEM systems, boot managers, public key infrastructure and certificate issuance software, network interfaces, operating systems, internet-connected routers, modems and switches, microprocessors and microcontrollers with security functionality, ASICs and FPGAs with security functions, smart home assistants, smart home security products such as door locks and cameras, internet-connected toys with interactive or location-tracking features, and personal wearable health monitors.

Class II has four entries: hypervisors and container runtime systems, firewalls and intrusion detection or prevention systems, tamper-resistant microprocessors, and tamper-resistant microcontrollers.

Annex IV lists three critical categories: hardware devices with security boxes, smart meter gateways, and smartcards or similar devices including secure elements.

Commission Implementing Regulation (EU) 2025/2392 supplies the technical descriptions that decide borderline cases.

8. Worked example: sorting one catalogue

Take a mid-sized vendor shipping four things.

A team chat desktop application. Commercially supplied, network connected, not in either annex. Default category.

A password manager. Annex III class I. Identical Annex I requirements, restricted conformity route.

A container runtime shipped inside a platform product. Annex III class II. Third-party assessment is mandatory unless a European cybersecurity certification scheme covers it, or the manufacturer qualifies for the open-source documentation route.

The cloud backend the chat application needs to deliver messages. Not a fourth product. It is a remote data processing solution and forms part of the chat application.

Notice what did not move anything. Not company size, not revenue, not how sensitive the data is, not whether customers are regulated. The tier follows the product's function, and only its function. A tiny vendor's password manager sits in class I while a large vendor's project tracker sits in the default category.

9. Manufacturer, importer, distributor, and role migration

The manufacturer carries nearly all the weight: risk assessment, essential requirements, due diligence on third-party components, technical documentation, conformity assessment, the declaration, the CE mark, and reporting.

Importers verify before placing a product on the market that the manufacturer performed the assessment, drew up documentation, and affixed the CE mark. Distributors check the lighter, visible signals: CE marking, contact details, user instructions, and a stated support period.

The trap is role migration. Two acts turn you into a manufacturer for a product you did not build. Placing it on the market under your own name or trademark. Making a substantial modification to it.

A reseller who rebrands a white-label camera inherits the complete Annex I obligation set for hardware it did not design, including vulnerability handling and security updates across the whole support period. That is a due diligence question at supplier selection, not a labelling question at launch.

10. The staged dates, and why the order surprises people

The Regulation entered into force on 10 December 2024 and applies in stages.

From 11 June 2026, Chapter IV applies. Member States designate notifying authorities and conformity assessment bodies can be notified. This is infrastructure, not a manufacturer obligation.

From 11 September 2026, the Article 14 reporting obligations apply.

From 11 December 2027, the main obligations apply: essential requirements, conformity assessment, technical documentation, CE marking.

Two transitional details reorder the work queue. Reporting applies to all products made available on the Union market, including those placed on it before 11 December 2027, so it reaches the estate you already shipped. Meanwhile products placed on the market before that date escape the main obligations until they undergo a substantial modification.

The consequence is counter-intuitive. The first duty to bite is operational rather than architectural, it applies to legacy products, and it needs a process staffed around the clock.

11. What genuinely changes for a software team

Three things are new for teams that have never worked under product law.

Evidence becomes a deliverable. Annex VII technical documentation is not a report written before launch and filed. It is a maintained record of architecture, risk assessment, the software bill of materials, and the reasoning behind the support period, which a market surveillance authority can demand.

The support period becomes a public commitment. Article 13 sets a floor of five years, or the expected use time where that is shorter, stated clearly with month and year at the time of purchase. End-of-life stops being a business decision made quietly.

Vulnerability handling becomes a legal duty rather than a practice. Annex I Part II requires a coordinated disclosure policy, a contact address for reports, regular testing, and security updates disseminated without delay and free of charge.

None of this is unusual engineering. What is unusual is that it is now enforceable against the product.

Check your understanding

The lesson ends with a 5-question quiz. Take it in the player above to see your score.

  1. What brings a product within the scope of the Cyber Resilience Act?
    • The manufacturer is established in the European Union
    • It is supplied commercially on the EU market and has a direct or indirect data connection to a device or network
    • The organisation making it falls within a NIS2 sector
    • The product processes personal data
  2. A connected device relies on a vendor-operated cloud backend to perform its core function. How does the CRA treat that backend?
    • As part of the product, because it is a remote data processing solution
    • As a separate service outside the Regulation
    • As a distributor obligation rather than a manufacturer one
    • As a critical product under Annex IV
  3. What does a product's risk tier actually change?
    • Which essential requirements in Annex I apply to it
    • Whether a CE marking is required
    • Which conformity assessment routes are available
    • The minimum length of the support period
  4. A reseller places its own brand on a third-party connected camera and sells it in the EU. What is its role under the CRA?
    • Distributor, with checks limited to CE marking and documentation
    • Importer, responsible only for verification
    • Open-source steward under Article 24
    • Manufacturer, carrying the full obligation set including vulnerability handling for the support period
  5. Which CRA obligation applies first, and reaches products already on the market?
    • CE marking
    • Conformity assessment by a notified body
    • Reporting of actively exploited vulnerabilities and severe incidents
    • Annex VII technical documentation

Related lessons

Law & Compliance
advanced

Proving It: Conformity Routes, Documentation, and Enforcement

Meeting the essential requirements is not the same as being able to show it. This lesson covers the Annex VIII modules and which one each tier allows, the harmonised-standards lever that keeps class I self-assessable, the public-documentation route open to open-source manufacturers, what Annex VII must contain, when a modification restarts the assessment, and the three penalty tiers.

11 steps·~17 min
Law & Compliance
advanced

Annex I: The Product Properties and the Processes Behind Them

Annex I is two lists doing different jobs: thirteen properties the product must have, and eight things the manufacturer must keep doing. This lesson works through both, including the secure-by-default and automatic-update rules, what the software bill of materials clause actually demands, the five-year support period floor and the ten-year shelf life on each update, and what must reach the user.

11 steps·~17 min
Law & Compliance
advanced

Proof: Disclosure, Presumptions, and the Complexity Rule

Strict liability is worthless if the claimant cannot prove a defect they never saw. Articles 9 and 10 answer that with a disclosure order, three presumptions of defectiveness, a presumption of causation, and a rule turning complexity into the claimant's ally. This lesson works through the cascade, the three-year and ten-year clocks, and what a defendant should be able to produce.

10 steps·~15 min
Law & Compliance
advanced

Who Pays, and For What Damage

The Directive builds a chain of liable operators so an injured person in the EU always has someone to sue. This lesson covers the manufacturer and component manufacturer, the importer and fulfilment service provider route, the distributor's one-month rule, online platforms, how a modification makes you a manufacturer, the heads of damage including data loss, and the exemptions.

10 steps·~15 min