This document is under active development and has not been finalised.
Skip to content

CRA Scope Checker

Use this decision tree to determine whether the Cyber Resilience Act applies to your product and which conformity path to follow.

BAUER GROUP Rule

Every product with digital elements undergoes this assessment before EU market launch. Classification decisions must be documented using the Product Classification Record.

Decision Tree

Gate 1: Product with Digital Elements?

┌───────────────────────────────────────────────┐
│ Does the product contain digital elements?    │
│ (Software, firmware, or hardware with         │
│ logical data connection — Art. 3(1) CRA)      │
│                                               │
│   NO  → CRA not applicable → STOP            │
│   YES ↓                                      │
└───────────────────────────────────────────────┘

"Product with digital elements" means any software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately (Art. 3(1) CRA).

Gate 2: Exemptions (Art. 2(2))

┌───────────────────────────────────────────────┐
│ Does any of the following exemptions apply?   │
│                                               │
│ ☐ Medical device (Reg. 2017/745, 2017/746)   │
│ ☐ Motor vehicle (Reg. 2019/2144)             │
│ ☐ Aviation (Reg. 2018/1139)                  │
│ ☐ Marine equipment (Dir. 2014/90/EU)         │
│ ☐ National security / military product       │
│ ☐ Pure SaaS without product component        │
│                                               │
│   YES → CRA not applicable (sector-specific  │
│          regulation applies) → STOP           │
│   NO  ↓                                      │
└───────────────────────────────────────────────┘

NIS2 Synergy

Pure SaaS services fall under NIS2, not CRA — unless remote data processing is an integral part of a physical or installable product.

Gate 3: Open-Source Assessment (Art. 18–19)

┌───────────────────────────────────────────────┐
│ Is this open-source software?                 │
│                                               │
│   NO  → Continue to Gate 4 ↓                 │
│   YES → Is there a commercial activity?       │
│         (sale, paid support, monetised         │
│          integration, SaaS offering)           │
│                                               │
│     NO  → CRA not applicable → STOP          │
│     YES → Open-Source Steward obligations     │
│           apply (Art. 18–19) → Continue ↓    │
└───────────────────────────────────────────────┘

Note

"Commercial activity" is broadly defined. Accepting donations alone does not constitute commercial activity. However, providing the software as part of a paid product or service does.

Gate 4: Product Classification (Art. 6–7, Annex III & IV)

┌───────────────────────────────────────────────┐
│ Is the product listed in Annex IV?            │
│                                               │
│   YES → CRITICAL                              │
│         → EUCC certification required         │
│         → See: Conformity / EUCC              │
│   NO  ↓                                      │
├───────────────────────────────────────────────┤
│ Is the product listed in Annex III?           │
│                                               │
│   YES → Which class?                          │
│     Class II → Module B+C or Module H         │
│                → See: Conformity / Module B+C  │
│     Class I  → Module A (with hEN) or B+C     │
│                → See: Conformity / Module A    │
│   NO  ↓                                      │
├───────────────────────────────────────────────┤
│ STANDARD (Default Category)                   │
│ → Module A (Self-Assessment)                  │
│ → See: Conformity / Self-Assessment           │
└───────────────────────────────────────────────┘

Results Summary

ResultProduct ClassConformity PathEffort Level
StandardDefaultModule A (Self-Assessment)Low
Class IImportant (Class I)Module A with hEN or Module B+CMedium
Class IIImportant (Class II)Module B+C or Module HHigh
CriticalCritical (Annex IV)EUCC CertificationVery High

Estimated Compliance Effort

RequirementOne-offAnnualApplies to
Security risk assessment (Annex I)20–40h10–20hAll classes
SBOM generation & maintenance8–16h8–16hAll classes
Vulnerability handling process20–40h20–40hAll classes
Incident reporting setup (Art. 14)16–32h8–16hAll classes
Technical documentation (Annex VII)40–80h10–20hAll classes
CE marking & EU DoC8–16h4–8hAll classes
Third-party assessment (Module B+C)40–80h20–40hClass I* / II
QMS establishment (Module H)60–120h30–60hClass II (alt.)
EUCC certification process80–160h40–80hCritical
Total Standard112–224h60–120h
Total Class I (with hEN)112–224h60–120h
Total Class I (without hEN)152–304h80–160h
Total Class II212–424h110–220h
Total Critical252–504h130–260h

* Class I only requires third-party assessment if harmonised standards are not applied in full.

BAUER GROUP Approach

BAUER GROUP relies on a fully automated toolchain (Trivy, Grype, CycloneDX, Cosign, GitHub Actions) to minimise manual effort for Standard and Class I products. See the Tooling Map for details.

Next Steps

Based on your classification result:

  1. Document the decisionProduct Classification Record
  2. Start conformity processConformity Assessment Overview
  3. Prepare documentationTechnical Documentation
  4. Set up reportingENISA Reporting Process

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT