EU Cybersecurity Comparison: CRA vs GPSD

If you are in the business of selling charging products in the EU market, or have purchased charging accessories in the EU, you have certainly heard the terms CRA and GPSD recently. Many people compare the two but end up more confused the more they look: which one regulates cybersecurity? Which one regulates charger fires? Didn’t GPSD get abolished, why do people still bring it up? What is the newly launched GPSR anyway?

In this article, we will start with the most familiar charging products — charging cables, USB-C cables, chargers, power adapters, connectors, etc. — to thoroughly explain the positioning, scope of application, core requirements, and penalty rules of CRA and GPSD. We will also clarify the current general safety regulation GPSR that replaces GPSD, to help entry-level cross-border practitioners and ordinary consumers quickly sort out the relationship and avoid common compliance pitfalls.

Get Started First: Three Core Regulations and Judgment Logic

Before the formal comparison, we will first explain the three most easily confused regulatory terms using the charging product scenario, to avoid getting more confused later.

The first is **CRA**, short for the . You can think of it as an EU regulation specifically governing “the cybersecurity of products with digital functions”. For example, if the smart charger you sell can connect to WiFi and be controlled via an App, could a hacker remotely adjust its power? Could it leak your charging data? These are all matters regulated by the CRA.

The second is **GPSD**, the old version of the . It was officially abolished on December 13, 2024. Now most mentions of it are as a historical reference, used to compare changes between old and new rules.

The third is **GPSR**, the current , which is the “catch-all safety regulation” that directly replaces GPSD. What does “catch-all” mean? It means that if there is a special regulation governing a safety issue, the special regulation applies first; consumer safety risks not covered by any special regulation fall under the GPSR. For example, if the insulation layer of an ordinary charging cable is too thin and causes electric shock, if the special electrical safety regulation already covers this, the GPSR does not need to regulate it repeatedly; if there is a safety risk that is not covered by all special regulations, the GPSR will act as the catch-all.

Scope of This Comparison and Target Audience

The scope of this comparison is limited to consumer-grade charging products sold in the EU market, including common charging cables, USB-C cables, chargers, power adapters, connectors, etc. The target audience is mainly two groups: first, ordinary consumers in the EU region, and second, entry-level practitioners engaged in cross-border sales of charging products. The core of the comparison is the cross-cutting requirements of cybersecurity-related regulations, and we will not go into other unrelated compliance content.

Core General Principles of Judgment

Before talking about specific differences, you can first remember three core judgment principles, so that you can build a basic framework for any product you encounter later:

First, first check whether the product has connectable digital elements to determine whether it will trigger CRA requirements. Simply put, if the product can connect to the internet or devices, and has upgradable software, it is very likely that CRA needs to be considered.

Second, special harmonized legislation takes priority, and GPSR only acts as a catch-all. As long as there is a special regulation governing a certain type of safety risk (for example, electrical safety is governed by the LVD Directive), the special regulation applies first, and GPSR only supplements the parts not covered by all special laws.

Third, multiple regulations may apply in parallel, but it is not a simple either-or choice, nor do all regulations automatically apply cumulatively. The CRA can apply in parallel with applicable regulations such as LVD, EMC, and RED; while the GPSR only applies supplementally when relevant consumer safety risks, risk categories, or risk aspects are not covered by EU harmonized legislation. You cannot directly determine that the GPSR also applies in parallel to all safety matters just because a product is subject to both the CRA and special regulations.

Basic Positioning: The Two Types of Regulations Govern Completely Different Risks

Many people cannot figure out the core difference between CRA and GPSR (formerly GPSD), essentially because the types of risks they regulate are not on the same dimension at all.

CRA: Governs Digital Vulnerabilities and Cyber Attack Risks

The core regulatory logic of the CRA is to cover the entire life cycle of products from design, production to post-sales vulnerability remediation — it is not enough that the product has no problems when it leaves the factory; vulnerabilities that appear later must be fixable and updatable. The core risks it aims to prevent include: product vulnerabilities being exploited by hackers, unauthorized access to products by others, user data leakage, remote manipulation of products, product function failure due to attacks, etc.

In the scenario of charging products, for example, for a smart charger controlled by an App, if a hacker remotely adjusts the charging power to exceed the upper limit that the product can withstand through a vulnerability, or steals the user’s charging habit data, or directly makes the charger unable to charge normally, these are typical scenarios regulated by the CRA.

GPSR: Governs Consumer Personal and Property Safety (Catch-all)

The core regulatory logic of the GPSR is that products must be safe when placed on the market. If safety risks are found, they must be promptly removed from shelves, recalled, and consumers must be warned. The core risks it aims to prevent are all physical, such as electric shock, overheating, fire, short circuit, structural damage and other problems that can directly hurt people.

Does the GPSR regulate cybersecurity-related issues? It is not that it does not regulate them at all, but the boundary is very narrow: only when a cyber vulnerability causes a physical hazard, and no special legislation covers this risk, will the GPSR apply supplementally. For example, if a firmware vulnerability of a smart charger causes overheating and fire, but neither the special cybersecurity regulation nor the electrical safety regulation covers this specific risk scenario, then the GPSR will step in as the catch-all.

Quick Distinction of Risk Boundaries

You can quickly distinguish the boundaries between the two with two sentences:

The CRA regulates “whether the product will be attacked and whether vulnerabilities can be fixed”, with a focus on digital security;

The GPSR regulates “physical safety not covered by special laws”, with a focus on physical-level catch-all.

If you encounter a situation where a vulnerability causes physical harm, there is no need to panic: the CRA regulates whether the cybersecurity itself is compliant, special safety regulations (such as LVD for electrical safety) regulate physical safety requirements, and only the parts not covered by all special laws are supplemented by the GPSR. Let’s take a specific example: if the Bluetooth vulnerability of a Bluetooth smart charger only leaks the user’s charging data and does not cause physical danger, then pure data leakage is usually not a product safety risk regulated by the GPSR; if the product is subject to the CRA, the CRA can apply to the relevant cybersecurity vulnerabilities. If the leaked content constitutes personal data, the GDPR and personal data breach notification obligations must also be assessed separately. If this vulnerability is exploited and causes the charger to overheat and catch fire, then the CRA must regulate the compliance of the vulnerability, the LVD Directive must regulate electrical safety requirements, and if there are still uncovered physical risks, the GPSR will apply supplementally.

Comparison of Scope of Application: How to Determine Which Regulation Applies to Charging Products

Now that we have clarified the positioning differences, the next part is the most practical: how to determine which regulation applies to your charging product? We will explain it from the logic of GPSR and CRA respectively.

GPSR Application Judgment: The Core is the Catch-all Logic

To judge whether the GPSR applies, the first step is not to look directly at the product, but to first check whether the product is covered by special harmonized legislation. For example, common LVD (Low Voltage Directive, governing electrical safety), EMC (Electromagnetic Compatibility Directive, governing electromagnetic interference), RED (Radio Equipment Directive, governing wireless functions), RoHS (Restriction of Hazardous Substances Directive) for charging products are all special harmonized legislation.

Only when a certain consumer safety risk is not covered by these special laws does the GPSR need to be used to supplement it. For example, will the material of an ordinary charging cable cause allergies? If there is no special regulation governing this, then the GPSR will act as the catch-all.

Also note that the scope of subjects of the GPSR includes not only pure consumer-grade products, but also B2B products that can reasonably be foreseen to be used by consumers. For example, a charger originally intended for industrial equipment, but which ordinary consumers can also buy and use, must also meet the consumer-side requirements of the GPSR. For products with special safety regulations such as industrial and medical products, the GPSR only supplements the consumer-side risks not covered by those special laws, and will not regulate repeatedly.

CRA Application Judgment: Two Levels of Logic (Exclusive for Charging Products)

The application judgment of the CRA is divided into two steps, and you cannot make a decision just by looking at “whether it is connected to the internet”:

The first level is initial screening: is your product, or a component sold separately, a “product with digital elements”? Simply put, can the product’s software and hardware directly or indirectly connect to devices or networks? For example, a charger that can connect to WiFi definitely has digital elements; an ordinary pure copper charging cable without any chips does not have digital elements.

The second level is verification: even if it seems to meet the first level, you still need to check the statutory exclusion scope, whether there are special cybersecurity systems with equivalent effect, and the specific guidelines issued by the EU authorities, and you cannot draw a conclusion directly.

For charging products, we can divide them into three categories for initial screening:

The first category is **highly likely to be subject to the CRA**: for example, smart chargers with WiFi, Bluetooth, App control, or upgradable firmware, and networked charging stations. These products have clear digital functions and are almost certain to meet the CRA requirements.

The second category is **needs to be confirmed in combination with the architecture**: for example, USB-C cables with only E-Marker chips, and ordinary PD chargers with fixed logic power control. Although these products have digital chips or digital control logic, their functions are relatively fixed. Whether they trigger the CRA needs to be confirmed in combination with the specific product architecture and EU official guidelines, and cannot be generalized.

The third category is **usually not subject to the CRA**: purely passive cables without electronic or digital components, and whose intended or reasonably foreseeable use does not include direct or indirect logical or physical data connection with devices or networks, are usually not within the scope of the CRA. For chargers, non-networked, fixed-function or non-upgradable models must be judged item by item according to the actual software, hardware and data communication architecture, and the CRA cannot be directly excluded just because it is a “basic model” or “non-smart”.

Here is a special reminder: even if the product is not subject to the CRA, it does not mean that other regulations do not need to be followed. Electrical safety, hazardous substance restriction and other requirements that should be met still need to be met.

Typical Scenarios of Parallel Application of Multiple Regulations

In many cases, it is not only one regulation that applies, but multiple regulations in parallel. The most typical ones in the charging category are WiFi smart fast chargers, App-controlled power adapters, networked charging stations and other products. They may simultaneously meet the cybersecurity requirements of the CRA and the requirements of special regulations such as LVD, EMC, and RED.

As for the GPSR, it does not automatically apply fully and cumulatively just because the product is targeted at the EU consumer market and has digital elements. Only when a certain consumer safety risk, risk category or risk aspect is not covered by EU harmonized legislation will the GPSR play a catch-all role for this uncovered part.

Application Matrix of Typical Charging Products

To facilitate your quick reference, we have organized the application status of 5 types of common charging products into a table. You can directly correspond to your own products for initial screening:

Product TypeInitial Screening of Digital ElementsCRA Applicability LevelGPSR Supplementary ScenariosOther Special RegulationsCore Retained Evidence
Ordinary passive charging cableNoneUsually not applicablePhysical safety risks not covered by special lawsRoHS (usually applicable; confirm based on product scope); whether LVD and EMC apply must be judged based on rated voltage, whether it constitutes relevant statutory equipment, and product functions. If it is a mains power cord, a cable with independent electronic functions, or a combined product, it may additionally trigger requirements such as LVD and EMCElectrical safety test report, material inspection report
USB-C cable with E-MarkerContains simple digital chips, with limited functionsNeeds to be confirmed in combination with architecture and guidelinesPhysical safety risks not covered by special lawsRoHS (usually applicable; confirm based on product scope); whether LVD and EMC apply must be judged based on rated voltage, whether it constitutes relevant statutory equipment, and product functions. If it is a mains power cord, a cable with independent electronic functions, or a combined product, it may additionally trigger requirements such as LVD and EMCChip specification sheet, electrical test report
Fixed-function PD chargerFixed logic power control, no upgradable firmwareNeeds to be confirmed in combination with architecture and guidelinesPhysical safety risks not covered by special lawsLVD, EMC, RoHS, Ecodesign (if applicable)Circuit design documentation, electrical test report
Charger with upgradable firmwareWith updatable software, can connect to devicesUsually highly likely to applyPhysical safety risks not covered by special lawsLVD, EMC, RoHS, Ecodesign (if applicable)Cybersecurity assessment report, firmware update mechanism documentation
WiFi/App smart chargerWith wireless networking function, can be remotely controlledClearly applicablePhysical safety risks not covered by special lawsLVD, EMC, RED, RoHS, Ecodesign (if applicable)Full life cycle cybersecurity documentation, wireless test report

Item-by-Item Comparison of Core Requirements (From the Perspective of Charging Products)

Now that we have clarified the scope of application, we will compare the differences between the two from several core requirement dimensions, all of which are the content that charging product practitioners are most concerned about.

Comparison of Cybersecurity Requirements

The CRA’s cybersecurity requirements do not end when the product leaves the factory. It requires manufacturers to meet cybersecurity requirements during the design, development, production and support period, and to effectively handle vulnerabilities and provide timely security updates during the support period. In principle, the support period shall correspond to the expected life of the product, usually at least five years from the date of placing on the market; but if the expected life of the product is less than five years, it can be determined according to the shorter life.

Security updates can be provided with an automatic update mechanism, but users should be able to choose not to install them automatically. In other words, what the regulation requires is the timely provision of security updates and the user’s right to choose, not that updates must be carried out in the form of “forced push installation”.

The GPSR has very limited requirements for cybersecurity. Only when a digital vulnerability causes a physical hazard and no special law covers it, is it required to eliminate the vulnerability. It does not regulate pure digital-level risks. For example, data leakage that does not involve physical harm is usually not treated as a product safety risk by the GPSR.

It is easy to understand with the example of charging products: if the vulnerability of a Bluetooth charger only leaks the user’s charging data and does not cause physical danger, then pure data leakage is usually not a product safety risk regulated by the GPSR; if the product is subject to the CRA, the CRA can apply to the relevant cybersecurity vulnerabilities. If the leaked content constitutes personal data, the GDPR and personal data breach notification obligations must also be assessed separately. If this vulnerability causes the charger to overheat and catch fire, then the CRA must regulate the remediation of the vulnerability and compliance during the support period, the special electrical safety law regulates physical safety requirements, and only the remaining uncovered parts are supplemented by the GPSR.

If your product is subject to the CRA, the core compliance documents you need to prepare include: cybersecurity risk assessment report; software and hardware architecture description, interface list, third-party components and SBOM (Software Bill of Materials) management documentation; vulnerability handling process, security update mechanism and statement of support period; security test records, safety prompt information for users; as well as technical documentation and EU Declaration of Conformity (DoC).

If the catch-all requirements of the GPSR are involved, the content that needs to be assessed includes: assessment of physical risks such as overheating, fire, and electric shock; testing of material and structural safety, and foreseeable misuse; instructions and warning labels, batch traceability information; safety information disclosure on online product pages, accident handling and recall processes.

Comparison of Responsible Subjects

The core responsible party of the CRA is the manufacturer, that is, the brand owner. Importers shall verify the compliance of the product, and distributors shall ensure that the products they sell meet the requirements. Simply put, the brand owner bears the main responsibility, and the upstream and downstream parties bear their respective responsibilities.

The responsibility of the GPSR covers the entire supply chain. From manufacturers, importers, distributors to e-commerce platforms, each link must bear corresponding safety responsibilities.

For the cross-border charging product scenario, we will clarify the boundaries of several core roles to avoid everyone shifting blame or bearing responsibilities they should not:

• **Manufacturer (Brand Owner)**: Bears the ultimate compliance responsibility. The full life cycle obligations of the CRA are the core responsibilities of the brand owner.

• **Importer**: Shall verify the compliance documents of the product. When a non-EU manufacturer places relevant products on the EU market, it shall ensure that there is a corresponding economic operator or responsible entity within the EU in accordance with applicable regulations; otherwise, the product shall not be placed on the EU market in accordance with relevant regulations. The specific roles assumed by importers, authorized representatives or other statutory subjects shall be determined in accordance with applicable regulations and supply chain arrangements.

• **Authorized Representative**: Only performs part of the compliance obligations on behalf of the manufacturer, and cannot replace the core responsibility of the brand owner. The brand owner is still responsible if problems arise.

• **Fulfillment Service Providers, E-commerce Platforms**: Shall perform corresponding obligations in accordance with their statutory roles. Online marketplaces in particular shall set up contact points, cooperate with supervision, and handle Safety Gate-related notifications and dangerous product disposal; they do not automatically assume the obligation to conduct comprehensive pre-sale compliance verification of all products on the platform. Whether fulfillment service providers assume economic operator obligations shall be confirmed according to the supply chain structure and applicable regulations.

Comparison of Post-Market Obligations

The post-market obligations of the CRA are continuous: it is necessary to continuously monitor product vulnerabilities, provide timely security updates when vulnerabilities are found, and clearly tell users how long the security support period of the product is, and no updates will be provided after the period expires.

The post-market obligations of the GPSR are aimed at physical safety risks: if physical safety risks are found, it is necessary to stop sales in a timely manner, recall products, warn consumers, and for online channels, publicize and remove them from shelves.

Comparison of Compliance Certification Methods

For CRA compliance certification, you need to prepare cybersecurity technical documentation, risk assessment reports, and EU Declaration of Conformity (DoC), and the CE marking of the product must cover the CRA requirements. Note that it is not enough to just have CE; CE must correspond to specific regulations.

For GPSR compliance certification, you need to prepare safety assessment reports, risk analysis documents, warning instructions, traceability information and other documents corresponding to the catch-all risks.

Here is a special reminder for charging product practitioners: if multiple regulations apply in parallel, technical documents and evidence must cover each applicable regulation, but it does not mean that all documents must be completely separate. Common tests, risk analyses and documents can be used in an integrated manner as long as they can meet the content requirements of each regulation; one EU Declaration of Conformity can also cover multiple applicable regulations. The CE mark is a unified mark, and there is no need to affix separate “LVD CE” or “CRA CE” marks. However, you cannot presume that the CRA has been complied with just because CE compliance for other regulations has been completed.

Comparison of Violation Penalties

The penalties for the CRA are EU-unified graded penalties, with a maximum amount of 15 million euros, or 2.5% of the global turnover in the previous fiscal year, whichever is higher.

The penalty standards for the GPSR are formulated by each member state itself. There is no unified maximum limit in the EU, and the penalty intensity may vary from country to country.

Under both the CRA and the GPSR, competent authorities may require rectification, warning, restriction or prohibition of supply, withdrawal or recall and other measures according to the circumstances of violations and risks; the specific measures taken do not mean that all serious violations will automatically receive exactly the same treatment. If damage is caused, civil liability under applicable law may also arise, and it is not just a matter of paying a fine.

Timeline and Transition Period: Entry into Force Does Not Mean Full Implementation

Many people confuse “regulation entry into force” with “the start of implementation of all obligations”, thinking that as soon as a regulation enters into force, all requirements must be met immediately. In fact, this is not the case. Both the GPSR and the CRA have transition periods. Let’s sort out the key time points.

Transition Node from GPSD to GPSR

The old GPSD was officially abolished on December 13, 2024, and on the same day, the new GPSR was implemented simultaneously. Compared with the old GPSD, the GPSR has strengthened the compliance requirements for online sales, product traceability requirements, and the requirements for economic operators within the EU, making it stricter than before.

Phased Implementation Nodes of the CRA

The entry into force date of the CRA regulation is December 10, 2024, with the regulation number (EU) 2024/2847. But entry into force does not mean that all obligations must be fulfilled immediately; it is implemented in phases:

The first phase starts from September 11, 2026, when the obligation to report exploited vulnerabilities and serious incidents begins to apply, that is, serious cybersecurity incidents must be reported.

The second phase starts from December 11, 2027, when most of the core requirements of the CRA will be mandatory, that is, the full life cycle cybersecurity requirements, which must be fully met by then.

Pitfall Avoidance Rules for Timeline Use

You must first distinguish several easily confused concepts: regulation entry into force, start of application of obligations, placing of products on the market, continued sale of inventory, and major modifications to software and hardware — these are completely different things.

The first rule is the **old inventory rule**: for products that have been placed on the EU market before December 13, 2024 and comply with the old GPSD, the transitional provisions of the GPSR stipulate that member states shall not hinder their continued supply. Documents proving the time of first placing on the market and compliance with the old GPSD shall be retained. “Placing on the market” is not the same as having been sold to end consumers.

The second rule is the **major modification rule**: if your product has undergone major updates, such as adding networking functions or adding digital functions, then compliance must be re-done in accordance with the latest regulations, and you cannot follow the old ones.

It is also particularly important to note that whether products placed on the EU market before December 11, 2027 need to comply with the subsequent obligations of the CRA still needs to be subject to the specific implementation guidelines issued by the EU authorities later. You can pay more attention to official updates.

Relationship Between CRA, GPSR and Other Special Regulations

Many people will ask: what is the relationship between regulations such as LVD and EMC and the CRA and GPSR? Will there be duplication? Let’s sort out this logic.

Common Special Regulations for Charging Products (Must-Know for Beginners)

• **Low Voltage Directive (LVD)**: Governs the electrical safety of products, such as whether it will cause electric shock, fire and other electrical-level safety issues.

• **Electromagnetic Compatibility Directive (EMC)**: Governs the electromagnetic interference and immunity of products, such as whether it will interfere with other devices, or be interfered by other devices.

• **Radio Equipment Directive (RED)**: Products with wireless functions such as WiFi and Bluetooth must comply with this, which governs the safety of wireless functions and spectrum use.

• **RoHS Directive**: Governs the restriction of hazardous substances in products, such as lead, mercury, etc., which must not exceed the standard.

• **Common Charger Regulation and External Power Supply Ecodesign Requirements**: The two shall be judged separately. The Common Charger Regulation mainly targets the USB-C interface and charging protocol requirements of specific radio equipment listed in Annex IA of the RED; the External Power Supply Ecodesign Regulation may stipulate energy efficiency, no-load power consumption and other requirements for applicable external power supplies. It cannot be generally assumed that all USB-C chargers are subject to the “unified interface” requirement.

Regulation Priority and Application Logic

First, special harmonized legislation takes priority over the GPSR. As long as there is a special regulation governing a certain type of risk, the special regulation applies first, and the GPSR only acts as a catch-all.

Second, the CRA is a special regulation for cybersecurity, which is parallel to special laws such as electrical safety and radio safety, and there is no conflict. For example, a smart charger must meet both the cybersecurity requirements of the CRA and the electrical safety requirements of the LVD, and the two are not contradictory.

Third, the GPSR only covers consumer safety risks that are not involved in all special laws, and is the last line of defense.

Clarification of Two Most Common Misconceptions

The first misconception: if you comply with the CRA, you don’t need to do electrical safety certification. This is completely wrong. The CRA only regulates cybersecurity and does not replace special safety requirements such as LVD and EMC. Conformity assessment required by applicable electrical safety regulations must still be completed; for example, products subject to LVD are usually subject to internal production control by the manufacturer, with technical documentation prepared, EU Declaration of Conformity signed and CE mark affixed, and third-party “certification” is not always required.

The second misconception: having the CE mark means complying with all regulations. This is also wrong. The CE mark is not a general mark; it must correspond to specific applicable regulations, and the substantive requirements and conformity assessment obligations of different regulations are independent. The CE is a unified mark, and there is no need to affix separate CE marks for different regulations; however, existing CE compliance under regulations such as LVD or EMC does not mean that the CRA requirements have been met.

Practical Judgment and Pitfall Avoidance

After talking so much, finally we will give you several tools that can be used directly to help you quickly self-check and avoid pitfalls.

Three-Step Self-Check Method for Charging Products (Usable for Beginners)

Step 1: First determine whether your product is targeted at the EU market and may be used by consumers? If the product is not targeted at consumers and will not be used by consumers under reasonably foreseeable conditions, it is usually not within the product scope of the GPSR; but the CRA still needs to be judged independently. As long as the product is placed on the EU market and is a product with digital elements, the CRA may still apply, regardless of whether it is used by consumers.

Step 2: Check whether the product has connectable digital elements? You can refer to the previous product matrix for initial screening. If not, you only need to assess the special regulations plus the catch-all requirements of the GPSR, and do not need to consider the CRA.

Step 3: Check the statutory exclusion scope and EU official guidelines to confirm the final scope of applicable regulations. Do not make decisions on your own, especially for products that are between applicable and non-applicable, you must follow the official guidelines.

5 Common Cognitive Misconceptions (Pitfall Avoidance for Semi-Proficient Practitioners)

Misconception 1: After the CRA is implemented, you don’t need to worry about the GPSR and electrical safety regulations. The truth is that the CRA only regulates cybersecurity, and physical safety, electrical safety and other matters that should be regulated still need to be regulated. Parallel application of multiple regulations is the norm.

Misconception 2: Only networked charging products need to comply with the CRA. The truth is that even if the product is not connected to the internet, but has upgradable firmware and connectable digital elements, it may also need to comply with the CRA, not only networked ones.

Misconception 3: All charging cables are passive and definitely do not need to comply with the CRA. The truth is that many charging cables now have chips, such as USB-C cables with E-Marker, and some cables with digital functions. Whether the CRA applies needs to be confirmed in combination with the product architecture, and cannot be generalized.

Misconception 4: Having the CE mark means complying with the CRA. The truth is that the CE mark must correspond to specific regulations. Previous compliance with regulations such as LVD and EMC does not mean that the CRA has been complied with. Technical documents and EU Declaration of Conformity can be integrated on the premise of meeting the requirements of each regulation, but they must be able to prove that the requirements of each applicable regulation have been met.

Misconception 5: GPSD and GPSR only have different names, and the content is similar. The truth is that the GPSR is much stricter than the GPSD. It has strengthened the compliance requirements for online sales, product traceability, and the requirements for economic operators within the EU. It is not just a change of name.

Quick Checklist for Beginners

□ Targeted at the EU consumer market → First assess special regulations such as LVD/EMC, then supplement with GPSR catch-all requirements

□ With connectable digital elements → Add CRA cybersecurity requirements

□ Cyber vulnerabilities may cause physical danger → Simultaneously check CRA, special safety regulations and GPSR supplementary requirements

□ Retain compliance documents corresponding to applicable regulations, and establish security update and vulnerability reporting mechanisms when the CRA applies

Summary

At this point, you should be able to sort out the relationship between CRA, GPSD and GPSR: GPSD is the old general product safety directive that has been abolished, and now it is replaced by GPSR, which acts as a catch-all for general safety; the CRA is a special regulation specifically governing the cybersecurity of products with digital functions, and it is not a simple either-or choice with the GPSR.

For charging products, you can combine the product’s functions and launch time, refer to the product matrix we provided, first conduct an initial screening of applicable regulations and core obligations, and then confirm with official guidelines. The most important thing is not to confuse cybersecurity requirements with physical safety requirements, nor to think that complying with one regulation is enough. A complete market launch assessment needs to combine multiple special regulations such as LVD and EMC, and then independently judge the scope of application of the CRA and GPSR, to ensure compliance.

If you are an entry-level practitioner, it is recommended to start with the three-step self-check method, avoid the 5 common misconceptions, and gradually build basic compliance judgment ability, so that you will not step into big pitfalls.

Scroll to Top