Skip to content

CRA SCOPE CHECKER

Does the Cyber Resilience Act apply to your product?

Enter your website. We read what you make and sell, then ask only the few questions the regulation turns on.

Try an example

About one minute. No account, no obligation.

  • The regulation

    The CRA is the EU's cybersecurity law for products

    Every product with digital elements sold in the EU must be secure by design, patched over its lifetime and documented.

    • In force 2027
    • Fines up to 15 MEUR
    • CE marking required
  • What changes

    Report incidents in 24 hours

    Actively exploited vulnerabilities go to ENISA within a day, with follow-ups at 72 hours and 14 days.

    24hfirst report
  • Who is covered

    Manufacturers, importers, distributors

    Sell under your own brand and you carry the manufacturer's duties — even if someone else built it.

  • Where it applies

    Any route into the EU market

    Direct sales, resellers and OEM customers all place your product on the EU market.

  • Products in scope

    Hardware, software, firmware

    Devices, embedded components, apps and remote data-processing solutions all count.