The regulation
The CRA is the EU's cybersecurity law for products
Every product with digital elements sold in the EU must be secure by design, patched over its lifetime and documented.
- In force 2027
- Fines up to 15 MEUR
- CE marking required
CRA SCOPE CHECKER
Enter your website. We read what you make and sell, then ask only the few questions the regulation turns on.
About one minute. No account, no obligation.
Every product with digital elements sold in the EU must be secure by design, patched over its lifetime and documented.
Actively exploited vulnerabilities go to ENISA within a day, with follow-ups at 72 hours and 14 days.
Sell under your own brand and you carry the manufacturer's duties — even if someone else built it.
Direct sales, resellers and OEM customers all place your product on the EU market.
Devices, embedded components, apps and remote data-processing solutions all count.