← Back to list

A Step-by-Step Guide to Determining Whether the EU Cyber Resilience Act (CRA) Applies to Your…

If you build embedded devices, IoT products, or software that ships with connected hardware, you’ve probably asked the same question your…

Epteck GmbH · 2026-05-04 12:12 · 0 claps · 1.9 min read
#cra #eu-cyber-resilience-act #cyber-resilience-act #iot-security #embedded-security
Open on Medium ↗
Wiki topics: CRY · Crypto & Web3 📟 · Gadgets & IoT 🚀 · Self Improvement

A Step-by-Step Guide to Determining Whether the EU Cyber Resilience Act (CRA) Applies to Your Product

If you build embedded devices, IoT products, or software that ships with connected hardware, you’ve probably asked the same question your peers are asking right now:

“Does the EU Cyber Resilience Act apply to your product and what exactly counts as ‘in scope’?”

The CRA introduces mandatory cybersecurity requirements for products with digital elements placed on the EU market, and it becomes fully applicable on 11 December 2027. Some obligations start earlier (notably reporting obligations from 11 September 2026).

We have explained in detail a practical, engineer-friendly way to assess, EU Cyber Resilience Act Applies to Your Product without drowning in legal jargon.

The CRA “Applicability Test” Explained:

Think of CRA scope like a gate with four checks:

  1. Are you placing the product on the EU market?
  2. Is it a “product with digital elements” (PDE)?
  3. Can it connect (directly or indirectly) to a device or network?
  4. Is it excluded because another EU regime already governs it?

If the answer is “yes” to the first three, and “no” to the fourth, you’re likely in scope and your next step becomes product classification (Default vs Important vs Critical), because that affects conformity assessment and whether you may need a Notified Body.

Step 1: Will Your Product Be Made Available on the EU Market?

CRA applies when a product is made available in the EU as part of a commercial activity; even if it’s free of charge.

So yes, CRA can still apply if you:

  • Bundle firmware tools with a device “for free,”
  • Provide a companion app to EU users,
  • Ship evaluation units into the EU,
  • Distribute software downloads to EU customers in a commercial context.

The key idea is the “marketplace principle”: if it’s supplied for distribution or use in the EU as part of commercial activity, CRA can apply regardless of whether your company is EU-based.

For example; a U.S. industrial OEM selling an edge gateway into Germany is in scope. A non-european start-up distributing a paid firmware tool to EU manufacturers can also be in scope.

If you’re building embedded devices, IoT products, firmware-based systems, or connected software for the EU market, understanding whether your product falls under the EU Cyber Resilience Act is now a critical first step. In the full guide, we break down the CRA applicability test in simple terms — EU market placement, products with digital elements, connectivity, exemptions, product classification, and what comes next for compliance readiness.

To explore the complete step-by-step breakdown, read the full CRA applicability guide for embedded and IoT products


메타데이터
post_id
48d2cc20eef7
slug
a-step-by-step-guide-to-determining-whether-the-eu-cyber-resilience-act-cra-applies-to-your-48d2cc20eef7
url
https://medium.com/@epteckgmbh/a-step-by-step-guide-to-determining-whether-the-eu-cyber-resilience-act-cra-applies-to-your-48d2cc20eef7
canonical_url
https://medium.com/@epteckgmbh/a-step-by-step-guide-to-determining-whether-the-eu-cyber-resilience-act-cra-applies-to-your-48d2cc20eef7
author_url
https://medium.com/@epteckgmbh
status
ok
fetched_at
2026-06-13 07:35:29