Free scope check

Check whether the CRA applies to your product

Answer questions about your product to see whether the Cyber Resilience Act applies to it.

Your answers stay in this browser and are never sent anywhere.

The questions

  1. What are you putting on the EU market?

    A product with digital elements is a software or hardware product together with its remote data processing solutions, including a software or hardware component placed on the market on its own. Pick the closest match.

  2. Can the product exchange data with another device or a network?

    Answer yes if a data connection is what the product is for, or something users could reasonably do with it. A wired, optical or radio link counts, and so does a software interface to another program. A product with no connection at all falls outside the Regulation.

  3. Does any of these describe your product?

    Select every description that applies, or select none of these.

  4. Do you supply the product in the course of a commercial activity?

    The Regulation only reaches products supplied for distribution or use on the EU market in the course of a commercial activity, whether you charge for them or not. Signals that you are in a commercial activity: you charge a price for the product, you charge for technical support beyond recovering your actual costs, you intend to monetise it, for example by monetising other services through it, you require processing of personal data as a condition of use for reasons other than only improving security, compatibility or interoperability, or you accept donations above the costs of designing, developing and providing the product. Accepting donations with no intention of making a profit is not a commercial activity.

  5. When was this product first placed on the EU market?

    Placing on the market is the first making available of a product on the EU market, and it is read per item, not per product line. For hardware, every unit you supply is placed on the market the day you first make it available. For software, all copies of one unchanged version count as placed when that version is first offered, and a later version whose changes affect compliance with this Regulation is a new placing when first offered. Give the date of the first placing of the product in its current form, or the planned date if it is not out yet. A date before 11 December 2027 does not by itself settle which duties you carry: the next question records whether placing continues or the product is substantially modified from that date, and the two answers decide it together. The reporting duties in Article 14 are the exception either way: they apply from 11 September 2026 to every product in scope, however old, and they keep applying after support for it has ended.

    Enter a date as day, month, year.

  6. From 11 December 2027, will you still place this product on the EU market, or substantially modify it?

    Answer yes if any of these happens on or after 11 December 2027: you supply further hardware units, because each unit is placed on the market on its own date; you first offer a version whose changes affect compliance with this Regulation, because that version is a new placing; or the product is substantially modified, which by Article 69(2) brings a product placed before that date under the full requirements. A substantial modification is a change you make after the product is on the market that affects how secure it is, or that changes what it is meant to be used for. Answer no only if every unit and every such version is placed before 11 December 2027 and no substantial modification follows from that date. Existing stock may keep being sold, and unchanged software may keep being supplied, because neither is a new placing on the market. Until you answer, the affected duties remain undecided. The reporting duties for actively exploited vulnerabilities and severe incidents apply from 11 September 2026 either way and keep applying after support has ended.

  7. Which EU countries is this product sold in?

    Tick every country where the product is sold, including the ones where a reseller, a distributor or a shop sells it for you rather than you selling it yourself. Two things follow from the answer. Each country decides for itself which languages your declaration of conformity has to exist in, so this list is what those languages are worked out from. And if a vulnerability in this product is ever being exploited, the early warning you file within 24 hours names the countries you know the product has been made available in. Leaving this blank leaves both of those open rather than answering them for you.

  8. What is your role for this product on the EU market?

    Pick the relationship your organisation has to this product when it is supplied on the EU market. The checklist uses this answer to show the duties that belong to that role. The option help explains where each role starts and ends.

  9. Do you place the product on the market under your own name or trademark?

    An importer or distributor who does this is treated as the manufacturer and carries the full manufacturer duties, including the conformity assessment and the reporting duties.

  10. Have you changed the product after it was first placed on the market?

    Answer yes if you changed the product yourself after it was first put on the EU market, and the change affects how secure the product is or what it is meant to be used for. A change like that makes you its manufacturer, so the technical documentation, the assessment, the declaration of conformity and the CE marking become yours. A change that affects neither of those leaves the duties where they are, and so does an update the maker of the product issues that you only pass on.

  11. Is this product free and open source software?

    That means the source code is openly shared, under a licence granting all rights to make it freely accessible, usable, modifiable and redistributable.

  12. Do you monetise this open source product?

    Providing free and open source software that its manufacturers do not monetise is not a commercial activity, so it stays outside the Regulation. How the software was developed or financed does not decide this, and neither does having regular releases. If it is a component meant for other manufacturers to integrate, it counts as made available on the market only if you, the original manufacturer, monetise it.

  13. Is the product developed by a not for profit organisation whose earnings after costs all go to its not for profit objectives?

    Development of free and open source software by such an organisation is not a commercial activity.

  14. Do you provide sustained support for the development of this open source product, and play a main role in keeping it viable?

    Sustained support includes, and is not limited to, hosting and managing software development collaboration platforms, hosting source code or software, governing or managing the product, and steering its development. The steward regime only covers free and open source products that are ultimately intended for commercial activities, for example integration into commercial services or into monetised products.

  15. Do you take part in developing this product yourself?

    Taking part in development means writing, reviewing or merging the code, or deciding what goes into a release. Hosting the code, paying for the work or governing the project is support without being development. Answer no if your project is supported by you and built by other people, and the reporting duty for an actively exploited vulnerability stays with them.

  16. Will you publish the technical documentation when you place the product on the market?

    This matters only for a free and open source product whose core function is one of the categories that carry a heavier check, for example an operating system, a password manager or a firewall. Publishing the technical documentation at the time you place the product on the market lets you use the same conformity assessment route as an ordinary product, instead of the heavier one that would otherwise apply.

  17. Which of these is the core function of your product?

    Pick the one category that describes what your product itself does at its core. A product has one core function. Building in a part with one of these functions does not put your product in that category. A match narrows the conformity assessment routes open to the product. Pick none of these if nothing matches.

  18. Is your product an artificial intelligence system that EU law treats as high risk?

    Answer yes only if it is an AI system that works as a safety part of a machine or device that EU product law already has an outside body check, or it is listed as high risk in the AI rules. The listed high-risk uses are: recognising people at a distance by face, voice or body, sorting them by inferred traits, reading emotions keeping a country's digital backbone, road traffic, water, gas, heating or electricity safe deciding who gets into a school or training course, marking work, or catching cheating in a test recruiting, promoting or dismissing workers, or handing out and monitoring their work deciding eligibility for public benefits or healthcare, scoring credit, pricing life or health insurance, sorting emergency calls police work border, migration and asylum decisions helping a court decide a case or influencing an election A system in that second group is not high risk after all if it poses no significant risk of harm to health, safety or fundamental rights, which is the case where it only performs a narrow procedural task, only improves work a person has already finished, only spots patterns in earlier decisions without replacing the human review, or only prepares an assessment for a person to make. That way out never applies to a system that profiles people, and if you rely on it you have to write your reasoning down before the product goes on sale. The AI assessment normally covers the CRA cybersecurity requirements too. If your product requires an independent CRA assessment and the AI assessment is based on your own checks, the CRA assessment still applies. To rely on CRA compliance for the AI cybersecurity requirements, your EU declaration of conformity must show that the product meets the cybersecurity protection level required by the AI rules. Keep one set of technical documentation covering both sets of rules.

  19. Which check does your AI system have to go through before it is sold?

    Pick the assessment route that applies to this AI system. This answer shows whether the AI assessment also covers the Cyber Resilience Act requirements or whether a separate assessment under that Act remains required. Choose Not known yet if the route has not been established.

  20. Is this product an electronic health record system under the European Health Data Space rules?

    Answer yes when the manufacturer intends the software, or the hardware and software together, to let healthcare providers caring for patients or patients themselves store, pass on, export, import, convert, edit or view the priority categories of personal electronic health data.

Prepare your dossier

DossierForge uses your product answers and component list to draft your technical file, vulnerability handling policy and declaration. The desktop app is in private beta.

How it works