CRA Article Overview
All relevant articles and annexes on the Cyber Resilience Act in detail. Read summaries and practical explanations for manufacturers and developers.
Article 1: Subject matter
Article 1 describes the CRA scope of regulation: products with digital elements, cybersecurity requirements, vulnerability handling procedures and market surveillance.
Article 2: Scope and exclusions
Article 2 covers products with digital elements involving a direct or indirect data connection and contains several sectoral exclusions.
Article 3: Definitions
Article 3 provides the terms used by the CRA check. Product with digital elements, remote data processing, roles and substantial modification are central.
Article 6: Requirements for products with digital elements
Article 6 links the market availability of products with digital elements to the essential requirements in Annex I Part I and the manufacturer procedures in Annex I Part II.
Article 7: Important products with digital elements
Article 7 links important products to the core functions of the categories in Annex III. Merely integrating such a component is not sufficient by itself.
Article 8: Critical products with digital elements
Article 8 concerns products with core functions listed in Annex IV. A certificate obligation can be set by delegated acts.
Article 13: Manufacturer duties
Article 13 is the central manufacturer article. It links product design, risk assessment and further manufacturer duties to Annex I.
Article 14: Manufacturer reporting obligations
Article 14 applies from 11 September 2026. Documented steps include a 24-hour early warning, 72-hour notification and final reports via the single reporting platform.
Article 19: Importer duties
Article 19 concerns importers. Documented duties include placing only compliant products on the market, verification duties and cooperation on risks.
Article 20: Distributor duties
Article 20 concerns distributors. They must act with due care and perform certain checks before making products available.
Article 24: Open-source stewards
Article 24 concerns open-source software stewards. Documented duties include a cybersecurity policy, cooperation with market surveillance and limited Article 14 links.
Article 32: Conformity assessment procedures
Article 32 describes how conformity with Annex I is demonstrated. For important products, routes depend on Class I or Class II and applied standards/certificates.
Annex I: Essential cybersecurity requirements
Annex I is the central requirements list. Part I concerns product characteristics; Part II concerns vulnerability handling including SBOM.
Annex III: Important products with digital elements
Annex III contains important products. The verified data contains 19 Class I categories and 4 Class II categories.
Annex IV: Critical products with digital elements
Annex IV contains critical products. The verified data contains three categories: security boxes, smart meter gateways/advanced security devices, and smartcards or similar devices including secure elements.