The CRA applies to products with digital elements placed on the EU market commercially: hardware and software that connect to networks, either directly or indirectly. This covers a wide range of products, from consumer devices and industrial equipment to operating systems, applications, firmware, and software components. The Regulation applies regardless of whether the product is sold to consumers or businesses.
Several categories fall outside scope, including products already covered by sector-specific EU regulations with equivalent cybersecurity requirements, such as certain medical devices and civil aviation equipment. Open source software released in a genuinely non-commercial context is also excluded. The boundaries are not always obvious, particularly for software components, embedded firmware, and products that connect only indirectly to networks. The five-day CRA Diagnostic works through these questions against your specific portfolio.