EU Regulation 2024/2847

Does the EU Cyber Resilience Act apply to your product?

Answer nine short questions to find out if you’re in scope, which risk class you fall in, the deadlines that apply, and exactly what you’ll need to comply.

See the deadlines
  • 3 minutes
  • No signup
  • Based on the official regulation text
Sample resultCRA-SCOPE
In scope — Default class
11 Sep 2026
Reporting obligation
T−41 days
11 Dec 2027
Full compliance
T−497 days

Your obligations

  • SBOM per product
  • Vulnerability monitoring & 24h reporting
  • CE marking + 5 years of security support

How it works

1

Answer 9 questions

Product type, market, and security functionality — no jargon.

2

Get your risk class

Default, Important (Class I/II) or Critical — computed instantly.

3

Receive your obligations report

Deadlines, SBOM, CE marking and reporting duties, tailored to you.

Two deadlines that matter

The Cyber Resilience Act phases in over two dates. Reporting duties come first — including for products already on the market.

11 Sep 2026T−41 days

Reporting obligation

24h early-warning and 72h notification of actively exploited vulnerabilities and severe incidents to ENISA.

11 Dec 2027T−497 days

Full compliance

All essential requirements apply: SBOM, security-by-design, technical documentation, CE marking and conformity assessment.

Frequently asked questions

Does the CRA apply to SaaS?

Pure cloud services with no installable component generally fall outside the CRA — those are addressed by NIS2. But a SaaS with a mandatory local agent, app or firmware, or backend processing essential to a physical product, is in scope. The checker asks about exactly this.

What are the fines?

Non-compliance with the essential requirements can be penalised with fines of up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher.

Is this legal advice?

No. This tool gives an indicative scope assessment based on the text of Regulation (EU) 2024/2847. It does not constitute legal advice — confirm your classification with qualified counsel before relying on it.

Who built this?

An independent tool for hardware and software makers preparing for the CRA. It is not affiliated with, nor endorsed by, the European Union, the European Commission or ENISA.

Check your product in 3 minutes

No signup to start. Enter your email only if you want the full report as a PDF.