The CRA is Regulation (EU) 2024/2847. It sets horizontal cybersecurity requirements for relevant hardware and software made available on the EU market and places duties on economic operators.
The question to ask first
Is a product with digital elements being made available on the Union market, and does its intended or reasonably foreseeable use include a direct or indirect connection to a device or network? Scope also depends on exclusions and the circumstances of supply.
- Identify the product and its components.
- Map the route to the EU market.
- Check connections, commercial activity and any applicable exclusion.
Who should use this resource?
Manufacturers, software teams, importers, distributors and governance teams can use the guides to organise questions and evidence. The applicable duties differ by role.
What follows scope?
Manufacturers address cybersecurity risk, essential requirements, technical documentation, conformity and vulnerability handling. Importers and distributors have distinct verification and response duties.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.