Are you ready for the
Cyber Resilience Act?
4 steps, 5 minutes. Check your obligations, measure your maturity, get an action plan.
Your market role
Tip: if you have the product designed and sell it under your brand, you are a Manufacturer, even without a factory.
Product scope
YES: smartwatch, IP camera, mobile app with backend, IoT sensor, SaaS API
NO: static PDF document, fully offline software with no network interface
Examples: MDR / IVDR (medical) Β· EASA (aviation) Β· Vehicle type-approval Β· Defence equipment
Class I: residential gateways, web browsers, antivirus, password managers, VPNs, wearables
Class II: industrial OS, secure microprocessors, smart cards, TPMs, critical industrial routers
Default: all others β smart TVs, connected toys, consumer applicationsβ¦
Life cycle & support
Caution: paid support, SaaS, or a component embedded in a sold product means the CRA applies.
Your security maturity
Honestly evaluate your current level on each of the 10 key CRA requirements.
Product out of CRA scope
Your product has no digital connectivity and does not fall within the scope of the Cyber Resilience Act (Art. 2 Β§1 & Art. 3 Β§1).
Total sectoral exclusion
Your product is fully covered by a specific EU sectoral regulation (MDR, EASA, vehicle type-approvalβ¦) β total exclusion from the CRA (Art. 2 Β§2).
Non-commercial Open Source
Open source software developed entirely outside any commercial activity is excluded from the Cyber Resilience Act scope (Art. 3 Β§14a).