Which products are in scope: products with digital elements
This requirement involves determining whether your products fall under the definition of "products with digital elements" as defined in Article 2. If a product meets this criteria, it is subject to the mandatory security requirements, conformity assessments, and reporting obligations of the Cyber Resilience Act (CRA).
What it means
The CRA applies to almost all hardware and software products placed on the EU market that contain digital components. This includes "standalone" software (e.g., an app or a SaaS platform) as well as hardware that incorporates software (e.g., IoT devices, smart appliances, or industrial controllers).
The intent is to ensure that any product capable of connecting to a network or performing digital functions cannot be sold in the EU without meeting baseline cybersecurity standards. The scope is broad and focuses on the functionality of the product rather than its specific industry vertical.
In practice, this means you must perform a scoping exercise across your entire portfolio. If a product contains software or electronic circuitry that processes data or connects to other systems, it is likely in scope unless specifically exempted by other EU legislation (such as certain medical device regulations).
How to meet it
- Conduct a comprehensive inventory of all hardware and software products offered for sale or provided within the EU market.
- Analyze each product against the Article 2 definition to determine if it constitutes a "product with digital elements."
- Categorize products into those that are standalone software and those that are hardware containing digital elements.
- Review existing legal exemptions to identify if any products fall under other specific EU regulations that supersede the CRA.
- Document the rationale for why each product is either included in or excluded from the scope of the Act.
- Establish a review process to evaluate new products during the design phase to determine their CRA status before they reach the market.
Evidence an auditor asks for
- A complete Product Catalog or Inventory listing all software and hardware assets sold in the EU.
- A Scope Analysis Document that maps each product to the specific criteria of Article 2.
- Technical specifications or architecture diagrams demonstrating the digital nature (or lack thereof) of the products.
- Written legal justifications for any products claimed as "out of scope" based on existing EU exemptions.
Common pitfalls
- Assuming that software-only services (SaaS) are exempt; standalone software is explicitly included in the scope.
- Overlooking embedded components or firmware within larger hardware systems that trigger the PDE definition.
- Failing to account for products distributed via third parties or resellers into the EU market, which still triggers compliance obligations for the manufacturer.