Skip to content

Scope, classification, and conformity

Everything else in the Cyber Resilience Act hangs off three early decisions: whether the CRA applies to the product at all and where the product's boundary runs, which product category it falls into, and which conformity assessment route follows. The Modulos application framework records those decisions first (MRF-450, MRF-451) and then carries the conformity machinery they select: technical documentation (MRF-473), the EU declaration of conformity and CE marking (MRF-474), and the duty to stay in conformity across a production series (MRF-475).

Applicability and the product boundary — MRF-450

The CRA applies where a product with digital elements is made available on the Union market and its intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. MRF-450 records that decision and the boundary that follows from it:

  • Remote data processing solutions are part of the product where both limbs of Article 3(2) hold: the data processing is designed and developed by the manufacturer, or under the manufacturer's responsibility, and the product could not perform one of its functions without it. A cloud backend the manufacturer runs for an AI-enabled device sits inside the CRA boundary; a necessary third-party service that fails the responsibility limb is an external dependency to risk-assess under MRF-467, not part of the product.
  • Separately placed components are recorded: a component placed on the market on its own is its own product with digital elements.
  • The placing-on-the-market date is recorded, because the transitional rules turn on it. Placing on the market is the first making available of the product on the Union market (Article 3(21)); every later supply is a making available (Article 3(22)).
  • Article 2 exclusions are checked: products covered by certain sectoral regimes (medical devices, civil aviation, motor vehicles, and the other listed acts) sit outside the CRA, as do products developed exclusively for national security or defense purposes.

The requirement is owed by the manufacturer and by any deemed manufacturer: under Article 21, an importer or distributor that places the product on the market under its own name or trademark, or that substantially modifies a product already placed on the market; under Article 22(1), a person in none of those roles that both substantially modifies the product and makes it available on the market. For an Article 22(1) person, the manufacturer duties attach to the affected part of the product or, where the modification affects the cybersecurity of the product as a whole, to the entire product (Article 22(2)).

Legacy products

Under Article 69(2), a product placed on the market before 11 December 2027 is subject to the CRA's requirements only if it undergoes a substantial modification from that date. Article 69(3) is the express derogation: the Article 14 reporting duties apply to all in-scope products placed on the market before 11 December 2027, substantially modified or not. The reporting side is covered in Reporting and economic operators.

Category, modification, and conformity route — MRF-451

MRF-451 records the product's objective core functionality and the category that follows from it:

CategoryDefined byConformity assessment
Outside Annexes III and IV (the default)Neither annex lists the core functionalityAny Article 32(1) route, internal control (module A) included
Important, class IAnnex III, class IModule B+C or module H where the manufacturer has not applied, or has applied only in part, relevant harmonized standards, common specifications, or European cybersecurity certification schemes at assurance level at least "substantial", or where none exist (Article 32(2))
Important, class IIAnnex III, class IIModule B+C, module H, or, where available and applicable, a European cybersecurity certification scheme (Article 32(3))
CriticalAnnex IVA European cybersecurity certification scheme in accordance with Article 8(1) where its conditions are met; otherwise an Article 32(3) procedure (Article 32(4))

One exception softens the Annex III rows: under Article 32(5), a manufacturer of a product qualifying as free and open-source software that falls under an Annex III category may demonstrate conformity using any of the Article 32(1) procedures, provided the technical documentation is publicly available when the product is placed on the market.

Commission Implementing Regulation (EU) 2025/2392 supplies the technical descriptions of the important and critical product categories; the classification decision applies those descriptions to the product's core functionality. The requirement also records whether a substantial modification has occurred and which part of the product it affects, because a substantial modification re-opens the conformity question for a product already on the market.

The Article 12 interplay for high-risk AI systems

For AI-enabled products, the category decision runs through Article 12 of the CRA:

  • A product with digital elements classified as a high-risk AI system under Article 6 of the EU AI Act that meets the CRA's essential cybersecurity requirements is deemed to comply with the cybersecurity requirement in Article 15 of that Regulation, in so far as the EU declaration of conformity demonstrates that those requirements are met.
  • Article 12(2) then applies the conformity assessment procedure of Article 43 of the AI Act to those products, rather than the ordinary CRA module route.
  • Article 12(3) derogates from that for important products subject to Article 32(2), points (a) and (b), or Article 32(3), and for critical products, in the cases where the AI Act's internal-control procedure (Annex VI of that Regulation) would otherwise apply.

In practice: the conformity route recorded in MRF-451 first reflects the Article 12(2) and (3) decision for a high-risk AI system, and then the product category. The deeming works at the conformity level; it does not remove the CRA's substantive duties. The cybersecurity risk assessment may form part of its AI Act counterpart (Article 13(4)), and a single set of technical documentation is drawn up where both acts require one (Article 31(3)).

Technical documentation — MRF-473

The manufacturer draws up the technical documentation before placing the product on the market and continuously updates it, where appropriate, at least during the support period. The documentation contains all relevant data or details of the means used to ensure that the product and the manufacturer's processes comply with Annex I, covering the eight Annex VII content groups as applicable to the product, and it is kept at the disposal of market surveillance authorities for at least 10 years after placing on the market or for the support period, whichever is longer.

Two points worth pinning:

  • Standards status — Annex VII distinguishes harmonized standards whose references have been published in the Official Journal from other technical specifications. No such reference has been published for the CRA, so the documentation must describe the solutions adopted to meet Annex I instead, and no presumption of conformity can be recorded on that basis. The Modulos requirement carries a regulatory watch-marker that updates this position once a reference is published.
  • One documentation set — for products referred to in Article 12 that are also subject to other Union legal acts providing for technical documentation, a single set of technical documentation is drawn up (Article 31(3)).

Declaration of conformity and CE marking — MRF-474

Where the selected procedure has demonstrated conformity, the manufacturer draws up the EU declaration of conformity in accordance with Article 28 and affixes the CE marking in accordance with Article 30 before the product is placed on the market. The declaration follows the Annex V structure, contains the elements the applicable Annex VIII procedure specifies, and is updated as appropriate. It is provided with the product either in full or in the simplified Annex VI form, which must state the exact internet address where the full text can be found.

Because no harmonized standard has been cited in the Official Journal, conformity is demonstrated through the applied procedure and the solutions described in the technical documentation. No presumption of conformity arises from any draft or published EN 40000-series document, and none may be recorded or implied.

Continuous conformity and corrective action — MRF-475

Conformity is not a one-time event. The manufacturer keeps procedures in place so that products that are part of a series of production remain in conformity, taking adequate account of changes in the development or production process, in the design or characteristics of the product, and in the harmonized standards, European cybersecurity certification schemes, or common specifications by reference to which conformity is declared. From the placing on the market and for the support period, where the manufacturer knows or has reason to believe that the product or its processes are not in conformity, it immediately takes corrective measures: bring the product into conformity, or withdraw or recall it, as appropriate.

The organization-side counterpart, including cooperation with market surveillance authorities and the Article 53 access duties, lives in ORF-477 on the reporting and economic operators page.

How this maps in Modulos

RequirementCRA anchorWhat it records
MRF-450 — CRA applicability and product boundaryArticles 2, 3, 21, 22, 69(2)The applicability decision, boundary incl. remote data processing, placing-on-the-market date, exclusions, deemed-manufacturer status
MRF-451 — Product category, modification, and conformity routeArticles 6–8, 12, 22, 32; Implementing Regulation (EU) 2025/2392Core functionality, category, substantial-modification status, Article 12 decision, selected route
MRF-473 — Technical documentation and lifecycle maintenanceArticle 31, Annex VIIThe documentation set, its Annex VII content, retention
MRF-474 — Conformity, declaration, and CE markingArticles 28, 30, Annexes V, VI, VIIIThe completed procedure, declaration, CE marking
MRF-475 — Continuous conformity and corrective actionArticle 13(14), (21)Series conformity, change accounting, corrective measures

All five requirements carry the CRA Phase tags for the market events they attach to, so a project can be filtered to what must be true before placing on the market versus what runs during and after the support period.

Where to go next

Disclaimer

This page is for general informational purposes and does not constitute legal advice. Always verify against the current published text of Regulation (EU) 2024/2847 and consult qualified advisers.