Free CRA tool
Classify your product under the CRA in 2 minutes
Describe your product or pick a category to see its EU Cyber Resilience Act class and the Article 32 conformity assessment route. No signup, no data stored. This orients your CRA work, and the assessment workspace builds the evidence behind it, whether you self-assess under Module A or hand the technical file to a notified body.
Step 1 of 2
Is your product in scope at all?
Is a web application covered by the CRA?
Generally no. Commission guidance C(2026) 5252 confirms that software which executes remotely and is merely accessed by the user is not, on that basis alone, a product with digital elements. A web application reached exclusively through a browser therefore falls outside the CRA, and so does a website that only presents information to visitors. For software to be in scope it must be provided to a user, obtained by that user, and operated on or as part of an electronic information system on the user’s side.
What if we also ship a desktop or mobile app?
Then that app is in scope. A client users download and install executes on their device, which makes it a product with digital elements even where it is built with web technologies. A browser extension is in scope on the same reasoning. Where the client relies on data processing at a distance to perform one of its functions, and that software was designed and developed by you or under your responsibility, the processing forms part of the product as a remote data processing solution.
Is hardware plus its companion app one product or two?
One. Software necessary to operate, configure, control or use hardware in accordance with its intended purpose is part of the same product, even when it arrives through a separate channel such as an app store or a download link after the hardware was placed on the market. Printer drivers and companion apps for wearables both fall on this side of the line, and the combination is classified on the core functionality of the product as a whole.
What applies if the CRA does not?
Falling outside the CRA does not mean falling outside EU cybersecurity law. Directive (EU) 2022/2555 covers cloud computing service providers, with requirements specified by Implementing Regulation (EU) 2024/2690. Regulation (EU) 2022/2554 covers financial entities and their ICT service providers. The GDPR continues to apply to any processing of personal data. Your customers may also ask for evidence regardless, because manufacturers must risk-assess their external dependencies and exercise Article 13(5) due diligence on integrated components.
Does free and open-source software count?
Only where it is supplied in the course of a commercial activity. Charging a price, monetising other services through the software, or requiring personal data processing as a condition of use all count. Selling optional professional services around freely downloadable software does not, and donations generally do not unless access or updates are conditioned on donating. Where the software is published but not placed on the market, the publisher may still be an open-source software steward under Article 24, with a narrower set of obligations.