Skip to main content

CRA Article Overview

All relevant articles and annexes on the Cyber Resilience Act in detail. Read summaries and practical explanations for manufacturers and developers.

Article 1: Subject matter

Article 1 describes the CRA scope of regulation: products with digital elements, cybersecurity requirements, vulnerability handling procedures and market surveillance.

Article 2: Scope and exclusions

Article 2 covers products with digital elements involving a direct or indirect data connection and contains several sectoral exclusions.

Article 3: Definitions

Article 3 provides the terms used by the CRA check. Product with digital elements, remote data processing, roles and substantial modification are central.

Article 6: Requirements for products with digital elements

Article 6 links the market availability of products with digital elements to the essential requirements in Annex I Part I and the manufacturer procedures in Annex I Part II.

Article 7: Important products with digital elements

Article 7 links important products to the core functions of the categories in Annex III. Merely integrating such a component is not sufficient by itself.

Article 8: Critical products with digital elements

Article 8 concerns products with core functions listed in Annex IV. A certificate obligation can be set by delegated acts.

Article 13: Manufacturer duties

Article 13 is the central manufacturer article. It links product design, risk assessment and further manufacturer duties to Annex I.

Article 14: Manufacturer reporting obligations

Article 14 applies from 11 September 2026. Documented steps include a 24-hour early warning, 72-hour notification and final reports via the single reporting platform.

Article 19: Importer duties

Article 19 concerns importers. Documented duties include placing only compliant products on the market, verification duties and cooperation on risks.

Article 20: Distributor duties

Article 20 concerns distributors. They must act with due care and perform certain checks before making products available.

Article 24: Open-source stewards

Article 24 concerns open-source software stewards. Documented duties include a cybersecurity policy, cooperation with market surveillance and limited Article 14 links.

Article 32: Conformity assessment procedures

Article 32 describes how conformity with Annex I is demonstrated. For important products, routes depend on Class I or Class II and applied standards/certificates.

Annex I: Essential cybersecurity requirements

Annex I is the central requirements list. Part I concerns product characteristics; Part II concerns vulnerability handling including SBOM.

Annex III: Important products with digital elements

Annex III contains important products. The verified data contains 19 Class I categories and 4 Class II categories.

Annex IV: Critical products with digital elements

Annex IV contains critical products. The verified data contains three categories: security boxes, smart meter gateways/advanced security devices, and smartcards or similar devices including secure elements.