Recently, whether you are a seller of cross-border charging products or someone living in the EU who buys digital accessories, you have most likely heard of the term “Cyber Resilience Act (CRA)”. Some say all USB-C cables need to be compliant, others say only connected products are covered, with all kinds of conflicting statements that are easy to confuse.
In this article, we will use charging products that people most commonly interact with—such as chargers, USB-C cables, and wireless chargers—as core examples to explain this matter thoroughly. Content is updated as of December 2024. For specific implementation, please refer to the latest official EU announcements, and this article cannot replace professional legal advice tailored to your specific product.
If you only need to know roughly whether your product is affected, reading up to this point is enough. If you are a merchant who needs to implement compliance, or want to understand the details of the rules and key points to avoid pitfalls, we will break it down in detail next.
Step-by-Step Check: 4 Steps to Verify Detailed Applicability Boundaries
If you are still unsure after a quick judgment, you can follow these four steps to check one by one, which will greatly improve accuracy.
Step 1: Verify Applicable Markets and Placing on the Market Activities
First, confirm whether your product falls within the scope of jurisdiction:
• Core applicable markets are the 27 EU member states; for EEA countries, check the inclusion progress of EFTA separately;
• Covered “placing on the market activities” include: commercial sales, free gifting for promotion purposes, and distance sales (such as direct mail from cross-border e-commerce to the EU);
• Situations that do not trigger first-time placing on the market obligations: personal carry-on for own use, non-commercial second-hand transactions, and samples for R&D and testing;
• If a product is re-placed on the market after significant modification, the applicability of the CRA needs to be re-evaluated.
Step 2: Check Whether the Product is a Product with Digital Elements
This step is the most error-prone. The core criterion is not simply whether the product has internet connectivity, nor only whether the chip can be programmed or updated. Instead, it requires a comprehensive assessment of whether the product contains digital hardware or software, and whether it can directly or indirectly establish a logical or physical connection with devices or networks.
You cannot conclude that a product has no digital elements just because its chip cannot be updated or its functions are fixed. Fixed-protocol controllers, digital identification chips, or other digital components may still make the product a product with digital elements. You should verify whether the chip is digital hardware, whether it has direct or indirect logical or physical connection capabilities, and whether the product falls under the CRA exclusion clauses.
You can check from these common points: whether it supports firmware upgrades, whether it has APP control, whether it can intelligently adjust power, whether it has digital protocol interaction, and whether it has wireless connectivity. However, these are only clues for checking, not the sole criteria.
Also note the boundary of supporting software: embedded software necessary for the product and OTA upgrade services shall be included in the assessment, but non-essential cloud services and independent APPs provided by third parties are not counted.
Key Verification Points for Typical Charging Products

Different charging products have different verification focuses:
• **USB-C cables with E-Marker**: You cannot directly assume exemption just because their functions are fixed. You should obtain chip and product technical documentation to verify their digital functions, connection capabilities, and whether they fall within the scope of the CRA; only purely passive cables without digital components can be judged as products without digital elements;
• **PD fast chargers**: Focus on the type of protocol controller, digital communication mechanism, and whether the firmware can be updated;
• **Wireless chargers**: Only wireless chargers that have no digital components and are implemented solely by analog or passive hardware may be classified as products without digital elements; models with digital controllers, identification chips, or communication protocol processing functions should be further evaluated for CRA applicability even if they are not connected to the internet.
Reference Judgment Cases

We have compiled several common reference cases for you to compare:
• Basic fixed-voltage chargers (no digital chips): Most likely not affected, but if a later revision adds a digital chip, re-evaluation is required;
• Smart connected chargers (with APP/OTA/cloud scheduling): Most likely affected, generally classified as ordinary products, but if used for critical infrastructure, reclassification is required;
• USB-C cables with E-Marker: You cannot assume exemption just because “it only has a fixed protocol identification function”. The judgment should be based on chip specifications and product technical documentation, verifying its digital functions, connection capabilities, placing method, and whether regulatory exclusion clauses apply. Only ordinary cables that are purely passive and have no digital components can be judged as products without digital elements.
Step 3: Verify Exemptions and Priority Application Scenarios
Some products may be exempt or have priority application of other regulations even if they contain digital elements:
• **Direct exemption**: Purely passive charging cables, adapters, and basic connectors that have no digital components or programmable digital functions;
• **Priority of industry-specific regulations**: The CRA may not apply only to products that meet the explicit exclusion conditions of the CRA, or are fully covered by the listed specific EU regulations. Ordinary chargers used in the medical, automotive, or aviation industries cannot be exempted solely based on the usage scenario; you must verify the product type and the scope of specific regulations item by item;
• Customized charging products that are only used for industrial supporting purposes and are not intended for end users require verification of the classification in the regulatory annex to confirm applicability.
Step 4: Confirm Product Classification and Conformity Assessment Path
The product classification of the CRA is not based on power or consumer/industrial grade. Instead, it must be judged strictly against the product categories and functional definitions in the CRA annex, and is divided into three levels:
• **Ordinary products**: The vast majority of consumer-grade smart charging accessories fall into this category;
• **Important products (Class I/II)**: Must be judged against the specific entries in the annex; you cannot classify them yourself solely based on the function name;
• **Critical products**: The CRA limits critical products to specific product categories listed in the regulatory annex. Whether a product is a critical product must be confirmed against the annex based on product type and function; it cannot be classified as a critical product just because it is used in critical infrastructure.
The corresponding conformity assessment paths are also different:
• Most ordinary consumer-grade products may be eligible for the “internal production control” path, which is self-declaration, but this is not unconditionally applicable;
• The conformity assessment path depends on the product category, applicable harmonized standards or common technical specifications, and whether an applicable European cybersecurity certification scheme is adopted;
• Important products and critical products may require the involvement of a notified body; you cannot deny the internal production control path for all products solely on the grounds that “harmonized standards are not adopted”.
Don’t Get the Timing Wrong: Transition Period and Entry into Force Rules
Many people have misunderstandings about the timeline of the CRA. Let’s clarify the key milestones and common misconceptions.
Key Timing Milestones (Updated as of December 2024)
• December 10, 2024: The CRA officially enters into force;
• September 11, 2026: The obligation to report vulnerabilities and serious security incidents becomes mandatory;
• December 11, 2027: Most CRA obligations (including compliance requirements for ordinary products) become mandatory;
• If there are subsequent adjustments, the official EU announcement shall prevail.
Special Rules for the Transition Period
The period between official entry into force and mandatory implementation is the transition period, and there are several rules to note:
• During the transition period, enterprises may voluntarily comply in advance;
• After mandatory implementation, new products placed on the applicable market for the first time must be compliant;
• The specific applicable rules for inventory products, repair spare parts, and significantly revised products are still awaiting clarification in subsequent EU guidelines;
• If a product undergoes significant revision, such as adding new smart functions, replacing the core digital chip, or updating the core firmware, the applicability of the CRA needs to be re-evaluated.
Timing Rules That Are Easy to Get Wrong
These three misconceptions are the most common, so avoid them:
• **It is not necessary to comply immediately upon entry into force in 2024**: Mandatory implementation for ordinary consumer-grade products will not start until the end of 2027, and there is still a transition period now;
• **Products produced before entry into force are not permanently exempt from compliance**: The judgment criterion is the time of first placing on the market, not the production time. For example, a product produced in 2024 that is first sold in the EU in 2028 must also comply with the CRA;
• **Products placed on the market before 2027 are not permanently compliant**: If a product is re-placed on the market after significant revision, it must comply with the new rules.
Responsibilities and Response Key Points for Different Roles
The responsibilities under the CRA do not fall solely on one party; different roles have different responsibilities.
Boundaries of Main Responsibilities
First, we need to clarify the division of responsibilities of each entity:
• **Manufacturer**: The entity that designs and produces the product and places it on the market under its own name. If it is a private label brand owner, as long as it labels its own brand, it must bear the main responsibility of the manufacturer and cannot shift all responsibility to the contract manufacturer;
• **Importer**: The entity that introduces the product into the EU market, responsible for verifying the manufacturer’s qualifications, compliance documents, and product consistency;
• **Distributor**: The entity in the supply chain responsible for selling the product, which must fulfill the obligations stipulated in the CRA such as verification, information provision, cooperation with supervision, and preservation of relevant documents within the applicable period. Distributors shall ensure that relevant documents can be obtained as required by supervision, but they are not necessarily required to hold complete technical documentation;
• **Authorized representative**: The manufacturer may designate an authorized representative within the EU through a written entrustment. The authorized representative mainly performs tasks such as preserving documents and providing information to regulatory authorities within the scope of the entrustment, and cannot replace the manufacturer in bearing responsibilities for product design, risk assessment, and conformity.
Ordinary Consumers
For consumers, the CRA is actually a good thing:
• You can buy products with better digital security guarantees, as well as clear security update commitments;
• When purchasing, you can pay attention to: whether there is clear manufacturer information, product model, security support period, update channels, and vulnerability feedback methods;
• In daily use, install official security updates in a timely manner, and do not install third-party firmware of unknown origin;
• If you encounter non-compliant products, you can defend your rights in accordance with EU consumer protection rules.
Cross-border Sellers/Distributors
If you are a seller or distributor operating in the EU market, you can prepare from the following points:
• Gradually switch to suppliers that can provide complete CRA compliance documents before 2027 to avoid being caught off guard;
• The function promotion on the sales page must be consistent with the actual hardware, software, connection capabilities, and intended use of the product. False or exaggerated promotion of smart functions may lead to product information, risk assessment, and other regulatory compliance issues, but the applicability of the CRA should still be judged based on the actual characteristics of the product and regulatory definitions;
• Importers and distributors shall fulfill the obligations stipulated in the CRA such as verification, information provision, cooperation with supervision, and preservation of relevant documents within the applicable period. The manufacturer is responsible for establishing and preserving technical documentation and the EU declaration of conformity; distributors shall ensure that relevant documents can be obtained as required by supervision, rather than being required to hold complete technical documentation as a matter of course;
• It is prohibited to sell known non-compliant products, and cooperate with regulatory traceability requirements.
Importers/Brand Owners

Importers and brand owners bear heavier responsibilities, and should note the following:
• Importers shall verify the manufacturer’s qualifications, CE marking, technical documentation, and compliance of product instructions;
• Private label brand owners shall bear the ultimate compliance responsibility and cannot shift all responsibility to contract manufacturers or chip suppliers;
• Agree on the obligation to provide technical materials with suppliers, and obtain summaries of core documents such as risk assessments and SBOMs;
• After the product’s core digital chip is replaced, major firmware updates are made, or new functions are added, the applicability of the CRA shall be re-evaluated.
Avoid These Common Misconceptions
We have compiled several of the most easily misunderstood concepts to help you avoid pitfalls.
Three Core Misconceptions
• **Misconception 1: Only connected products need to comply** → Wrong. Products do not need to have internet connectivity; as long as they contain software or hardware and can directly or indirectly establish a logical or physical connection with devices or networks, they may fall within the scope of the CRA. Fixed-function protocol controllers, digital identification chips, etc., also cannot be directly excluded just because they cannot be updated;
• **Misconception 2: The CRA is a new certification independent of CE** → Wrong. The CRA is a digital security regulation under the CE framework. Compliance results are reflected by affixing the CE marking after the manufacturer completes the applicable conformity assessment, but the CE marking itself is not a certification certificate issued by the EU, nor can it alone prove compliance with the CRA;
• **Misconception 3: All USB-C cables/chargers are affected** → Wrong. Purely passive products without digital components are usually not products with digital elements, such as ordinary pure-wire charging cables, basic adapters, etc. They should not be deemed subject to CRA jurisdiction just because the name contains USB-C.
Clarification of Vague Perceptions About Charging Products
There are also several common questions about charging products, which we will clarify uniformly:
• **Supporting PD fast charging ≠ definitely affected**: It is necessary to confirm the digital controller, protocol processing, and connection capabilities in the product. Conclusions cannot be drawn solely based on “supports fast charging” or “cannot be updated”;
• **USB data cables ≠ definitely affected**: Ordinary cables that are pure wires and have no digital components are usually not within the scope of the CRA;
• **Not connected to the internet ≠ not affected**: Even if a product does not have internet connectivity, as long as its digital components can establish direct or indirect logical or physical connections with other devices via USB or other means, it may still fall within the scope of jurisdiction. For example, some chargers do not need to be connected to the internet, but their parameters can be changed when connected to a computer, so they may also need to comply.
Pitfall Avoidance Tips for Small Businesses
If you are a small business, you must pay attention to these points:
• Do not trust the verbal promises of suppliers; be sure to request a written EU declaration of conformity and a summary of technical documents;
• Sort out the digital functions of products on sale in advance, and prepare for compliance in batches according to risk level, no need to do everything at once;
• Promotional content must be consistent with the actual hardware, software, connection capabilities, and intended use of the product. False or exaggerated descriptions of “smart” or “programmable” may cause inconsistencies between product information, risk assessments, and other regulatory documents, but the applicability of the CRA cannot be judged solely based on promotional text.
Appendix: Ready-to-Use Compliance Self-Checklist
You can follow the steps below to check one by one and quickly judge your situation:
1. **Product Attribute Self-Check**
□ Purely passive/no digital components → Most likely not a product with digital elements
□ With digital components or software, may have direct or indirect logical or physical connection capabilities → Proceed to the next step
2. **Market Placing Self-Check**
□ Not sold to EU/EEA markets → Not applicable
□ Commercially placed in the 27 EU member states → Proceed to the next step
□ Sold to EEA markets → First verify the official applicable status of EFTA
3. **Exclusion Scenario Self-Check**
□ Specialized products for medical/automotive/aviation, etc. → Verify the explicit exclusion clauses of the CRA and the coverage of industry regulations; exemption cannot be assumed solely based on usage scenarios
□ Only used for R&D and testing, not commercially placed → Usually not applicable
□ Ordinary consumer/industrial charging products → Proceed to the next step
4. **Product Classification Self-Check**
□ Ordinary product according to the regulatory annex → General obligations apply
□ May be an important/critical product → Verify the specific entries in the regulatory annex to confirm the assessment path
□ Only because the product is used in critical infrastructure → Cannot be directly deemed a critical product
5. **Compliance Document Self-Check**
□ Has cybersecurity risk assessment, product technical documentation (including SBOM where applicable)
□ Has vulnerability handling policy and security update mechanism
□ Has EU declaration of conformity including CRA content
6. **Timing Milestone Self-Check**
□ Confirm requirements against the timeline based on the placing date and type of obligation
7. **Role Responsibility Self-Check**
□ Consumers: Verify support period, update channels, and manufacturer information
□ Sellers/distributors: Fulfill obligations such as document verification, information provision, and cooperation with supervision
□ Brand owners/importers: Bear main responsibility, re-evaluate after significant revision
Quick Answers to Frequently Asked Questions
Do I need to replace the charger I already bought?
Usually, there is no need to replace products that have already been purchased and placed on the market before the applicable date solely because the CRA has entered into force. However, if the product undergoes substantial modification as referred to in the regulation, is re-placed on the market as a new product, or involves other applicable regulatory obligations, it shall be re-evaluated.
Are chargers that have no APP but can communicate with mobile phones affected?
Not necessarily. If it is only fixed-function protocol identification, exemption cannot be assumed solely for that reason; if the product contains digital components and can establish direct or indirect logical or physical connections with other devices, further judgment is required in combination with specific hardware, connection capabilities, usage, and exclusion clauses. If there are also configurable and updatable digital functions, it is usually necessary to focus on evaluating the applicability of the CRA.
Do charging products sold only in China need to comply with the CRA?
No. The CRA mainly applies to products placed on the EU or applicable EEA markets; other regions shall follow local regulations.
Can the CE marking prove that a product complies with the CRA?
It cannot prove compliance alone. It needs to be judged in combination with materials such as product category, conformity assessment method, technical documentation, security support period description, and EU declaration of conformity.
Core Summary
In short, **charging products that have digital elements, can directly or indirectly establish logical or physical connections with devices or networks, and are commercially placed on the EU market may need to comply with the CRA requirements**. Most obligations for ordinary consumer-grade products will become mandatory on December 11, 2027, but the specific situation still needs to be judged in combination with the first placing date of the product, actual hardware and software, product classification, and regulatory exclusion clauses.
Basic charging accessories that are purely passive and have no digital components, as well as products not sold to the EU, will basically not be affected by the CRA.
If you are unsure about your product situation, it is recommended to find a professional compliance agency for a targeted assessment, and do not judge solely based on experience to avoid subsequent pitfalls.