Scope of Electronic Products Subject to the EU Cyber Resilience Act (CRA)

Hardware sellers and product managers operating in the EU market have most likely heard of the CRA recently, but many people get overwhelmed after flipping through a few pages of the regulation: do the headphones, cameras, and routers I sell need to comply with the CRA? Could I accidentally violate the rules?

In fact, you don’t have to plow through hundreds of pages of legal provisions. The core logic for determining whether an electronic product is subject to the CRA is very clear. As long as you conduct step-by-step checks, you can draw conclusions for most ordinary products on your own. In this article, we will explain the judgment rules in plain language, covering everything from beginner-level quick self-checks to advanced judgments for products with ambiguous boundaries.

Before we officially start, let’s clarify a few most easily confused basic boundaries to avoid going astray at the very beginning:
First, the CRA regulates the cybersecurity capabilities of products, such as vulnerability management, security updates, and attack resistance. It does not address issues such as video content moderation, illegal content governance, advertising compliance, or user data privacy protection—these fall under the jurisdiction of the DSA (Digital Services Act), GDPR (General Data Protection Regulation), or other specialized regulations respectively.
Second, not all electronic products are regulated by the CRA; only those with digital functions are included, while purely mechanical and purely analog products are out of scope.
Third, it is not only products of EU local enterprises that need to comply. As long as they are sold to EU users, they may be subject to jurisdiction regardless of the place of production or shipment.
Fourth, “being subject to the CRA” does not mean having to comply with the highest-level compliance obligations. Different categories of products are classified by risk level. Scope determination only confirms first whether the product is subject to regulation; the subsequent stringency of compliance is a separate matter.

A quick note in advance: this article focuses on tangible electronic products (including embedded digital components). Standalone pure software and pure digital services are only mentioned for boundary clarification and will not be discussed in detail.

Step 1: Determine whether the product is an electronic product with digital elements

In EU regulations, such products are called “products with digital elements”, abbreviated as PDE. You don’t need to memorize this term; you just need to grasp two core conditions that must be met simultaneously:
First, the product has built-in digital chips, firmware, or embedded programs, and has the capability to store and process digital data;
Second, in the intended use of the product, or in reasonably foreseeable usage scenarios for ordinary users, it will have direct or indirect data connections with other devices or networks—such as connecting to the public Internet, pairing with a mobile phone, updating firmware via a USB flash drive/memory card, etc.

Only when both conditions are met is the product an electronic product with digital elements subject to CRA jurisdiction.

Many people’s first misunderstanding of “digital functions” is that “only products that can directly connect to WiFi or plug in an Ethernet cable count”. In fact, there are two types of data connections:
One is direct connection, meaning the product itself has built-in WiFi, cellular network, or Ethernet interface, and can directly connect to the public Internet, such as mobile phones and routers;
The other is indirect connection, meaning the product itself cannot directly connect to the public Internet, but can connect to a mobile phone via Bluetooth or NFC, or connect to the network via a gateway, relying on other devices to complete data interaction, such as ordinary Bluetooth headsets, Bluetooth door locks, and temperature and humidity sensors that connect to the network via a gateway.

The key conclusion here is: as long as such indirect data connections exist in intended use, the connection requirement for digital elements is met; it is not required to be able to directly connect to the public Internet. Put simply, as long as it is not completely isolated and can exchange data with other devices with digital functions, it meets the connection condition.

Non-digital electronic products that are directly excluded

There are two categories of products that are directly excluded and definitely not electronic products with digital elements subject to CRA jurisdiction:
The first category is products with purely mechanical structures and no digital chips, such as ordinary mechanical door locks, manual flashlights, and old-fashioned mechanical clocks and watches. These have no digital processing capabilities at all, and there is no possibility of digital data interaction, so they do not need to be considered.
The second category is products that only contain analog circuits and cannot process digital data, such as old-fashioned rotary dial landline phones, the most basic plug-in radios (that can only receive analog broadcasts, cannot save stations, and cannot connect to Bluetooth), and traditional analog walkie-talkies. Although these are electronic products, they only process analog signals, have no digital chips, and do not have digital data processing capabilities, so they do not count.

Two common pitfalls in this step

Let’s emphasize two common judgment misunderstandings:
First pitfall: “Only products with WiFi count”. Products with Bluetooth, NFC, or the ability to transmit digital data with other devices all count, such as Bluetooth mice and wireless headsets, which are all within the scope.
Second pitfall: “Offline products definitely don’t count”. For example, an electronic combination lock that does not connect to the public Internet has a digital chip that can process password data and can update firmware via a USB flash drive—this scenario of data interaction via storage media also falls under reasonably foreseeable data connections, so it is still a product with digital elements. After all, hackers may exploit vulnerabilities through physical contact, storage media, and other means; it is not only connected products that have security issues.

Step 2: Determine whether the product is “placed on the EU market”

After confirming that the product has digital elements, the second step is to check whether the product is “placed on the EU market”. The core of this step’s judgment is whether the operator actively offers the product to the EU market, which has no necessary connection with the company’s registered location, place of production, or place of shipment.

Specifically, whether it is “actively targeted” can be judged from several dimensions: whether orders from EU addresses are allowed, whether product descriptions in official EU languages are provided, whether settlement in EU currencies such as the euro is supported, whether the product is listed on EU e-commerce platform sites, whether targeted advertising is placed to EU users, whether local EU delivery or after-sales service is provided, etc. If only occasional passive orders are received from individual EU users, and the operator clearly does not conduct business targeting the EU market, it is usually not deemed to be placing the product on the EU market.

Scenarios that clearly count as “placing on the EU market”

The following typical scenarios are usually deemed to be placing the product on the EU market:

  1. Sold in physical stores within the EU, or listed on EU sites of third-party e-commerce platforms such as Amazon Europe and AliExpress EU;
  2. Directly mailed from outside the EU to individuals or enterprises within the EU, and the operator clearly provides purchase channels to EU users;
  3. Setting up warehouses in the EU to ship goods to EU users (i.e., the overseas warehouse model), with delivery completed by local EU warehouses;
  4. Providing product usage rights to EU users in profitable ways such as leasing and paid trials.

Applicable rules for second-hand/refurbished electronic products

The rules for second-hand and refurbished products that people often ask about are also very clear:
If it is a resale of personal unused items, with no price difference profit or only a small amount of cost recovery, it is a non-profit personal transaction and does not need to comply with the CRA.
If a merchant collects old products, refurbishes them, and then sells them for profit, it is equivalent to a new placement on the market and needs to comply with the CRA.
There are also brand-new unopened products that merchants buy and then resell commercially, which belong to normal market circulation, also count as being placed on the market, and need to meet the requirements.

Scenarios that clearly do not count as “placing on the EU market”

Conversely, the following situations clearly do not count as placing on the EU market, and the application of the CRA does not need to be considered:
First, equipment developed and used internally by enterprises and not sold to the outside world, such as production and testing equipment assembled by factories themselves that are only used in their own factories and not sold, does not count.
Second, products only produced in the EU, not offered on the EU market, and all exported to third countries usually do not constitute placement on the EU market in the sense of the CRA; however, it is still necessary to separately confirm whether other EU rules such as export control, industry safety, and production compliance apply.
Third, personal DIY electronic products that are only for one’s own use, or given to friends for free, and not sold commercially, do not count.
Fourth, non-commercially shared open source hardware, such as a circuit board designed by an enthusiast with public drawings for everyone to make for fun, which is non-profit and does not enter market circulation, does not count.
Fifth, independent stations that only serve markets outside the EU, such as only the US and Southeast Asia, whose websites do not support EU languages, do not accept orders from EU addresses, and clearly do not sell to the EU, also do not count as placing products on the EU market.

A reminder for cross-border sellers: if you do intend to sell to the EU market, do not take chances. The jurisdiction of the CRA does not depend on the location of the operator. If a product is deemed to have been offered to the EU market and does not meet the applicable compliance requirements, you may face subsequent risks such as market supervision investigations, customs entry inspections, platform compliance review and delisting, and recalls. Conversely, if you really do not do any business in the EU market at all, you must clearly state on your website and product pages that you do not ship to the EU or serve EU users, to avoid being misjudged as actively targeting the EU market due to occasional passive orders.

Common major categories of electronic products clearly included in the jurisdiction

After explaining the two-step judgment criteria, many people may still want to directly match their products to the categories. Below are several categories of common electronic products clearly included in the jurisdiction, and most ordinary products can find their corresponding category.

The first and most common category is consumer-grade smart electronic hardware. For example, smartphones, smart home appliances (smart refrigerators, robot vacuums, smart air conditioners), wearable devices (smart watches, fitness bands), home surveillance cameras, game consoles, wireless headsets with Bluetooth, smart door locks, etc. Their common feature is that they are sold to ordinary consumers and have networking, wireless connection, or smart interaction functions. A supplementary note: if the product involves sensitive groups (such as children’s smart watches) or critical functions, the compliance requirements will be stricter, but this does not affect the judgment of “whether the CRA applies”; it only means the subsequent compliance stringency is different.

The second category is network and connection electronic hardware. For example, routers, switches, wireless access points (APs), modems, network attached storage (NAS) devices, IoT gateways, etc. Their function is to transmit data and allow other devices to access the network, and they themselves are core components of digital networks, so they are of course within the scope of jurisdiction.

The third category is commercial/industrial-grade electronic devices with digital functions. Many people think the CRA only regulates consumer-grade products, but that is not the case. Commercial and industrial equipment sold to enterprises and institutions is also regulated. For example, commercial access control systems, industrial sensors, POS cash registers, enterprise-level routers, office conference terminals, etc., all count as long as they have data transmission or remote control functions.

The fourth category, which is easily overlooked, is digital components, which are divided into two situations according to sales method:
One is embedded components, that is, chips and firmware installed inside the product and not sold separately on the market, such as the operating system of a smart watch and the built-in firmware of a camera. Such components are regulated together with the whole device.
The other is standalone digital accessories, that is, hardware components with digital functions sold separately, such as Bluetooth modules, smart sensors, and control boards sold in independent packaging. These are judged as standalone products.

The specific boundary judgment method will be explained in detail in the advanced section later.

Let’s clarify the boundary here again: pure software sold separately (such as separately sold apps and computer software) does not fall into the category of tangible electronic products discussed in this article. The CRA has separate rules for pure software, which will not be elaborated here.

Step 3: Check for exemptions or situations where other regulations take priority

If your product meets the previous two conditions—having digital elements and being placed on the EU market—don’t rush to start compliance yet. You still need to go through the third step: check whether there are exemptions or situations where other industry regulations take priority. Not all products that meet the first two conditions are directly subject to the general requirements of the CRA.

Products with exclusive industry cybersecurity regulations

The first category is products with exclusive industry cybersecurity regulations, to which the principle of “specialized regulations take priority” applies. The judgment is divided into three steps:
Step 1: First confirm whether the product belongs to an industry with existing specialized cybersecurity rules, such as medical electronic devices that comply with the EU Medical Device Regulation (MDR) (e.g., ECG monitors, ventilators), automotive electronics that comply with UN R155 (e.g., infotainment systems, autonomous driving-related electronic devices), avionics that comply with EU aviation regulations, marine electronic devices that comply with maritime supervision rules, etc.;
Step 2: Then confirm whether these specialized regulations have systematically covered the cybersecurity requirements of the product;
Step 3: If the specialized regulations have fully covered the corresponding cybersecurity obligations, it is usually not necessary to repeatedly comply with the general requirements of the CRA; if the specialized regulations only cover part of the cybersecurity matters, or there are uncovered blank areas, it is necessary to evaluate whether the CRA applies supplementally.

Simply put, it is “specialized laws take priority, no repetition for covered areas, supplementation for uncovered areas”—it is not completely unrelated to the CRA. For beginner users, you just need to first judge whether the product belongs to these industries with specialized regulations, then check the corresponding industry rules, and don’t need to plow through the CRA first.

Statutorily excludable special-purpose products

The second category is statutorily excludable special-purpose products. Note that they can be excluded from the general scope of application of the CRA when statutory conditions are met, not just by claiming to be for special purposes arbitrarily.
There are two main types that meet the exclusion conditions: one is products specially designed for national defense or national security purposes, such as military communication equipment and special radars, which are subject to regulations related to national defense and national security; the other is products specially used for processing confidential information and subject to specific security rules, such as special encrypted computers for government departments to process classified documents, confidential communication equipment, etc.
The core criterion for judgment is: the product is designed from the very beginning for special official duties, national security, or confidential purposes, and is subject to corresponding specialized security rules. If it is just an ordinary civilian or commercial product, even if it is ultimately sold to government departments for use, it cannot automatically exclude the application of the CRA on the grounds of special purpose.

Situations easily misjudged as exemptions

In this step, there are many “exemptions” that people take for granted, but they actually don’t count at all. They are listed specifically to avoid pitfalls:

  • Low product price or small size: for example, a Bluetooth module that costs a few yuan, as long as it has digital functions and is placed on the EU market, is subject to the CRA, which has nothing to do with price or size.
  • Products only targeting enterprise customers: commercial and industrial equipment are all within the scope of the CRA, but the compliance stringency may be different from that of consumer-grade products, not that they are completely unregulated.
  • Products mainly running offline: as long as they have digital processing and connection capabilities, even if they are offline most of the time, they may still be subject to the CRA; it is not only always-online products that are regulated.
  • Products using open source solutions: open source is just a code licensing method, and has nothing to do with whether to comply with the CRA. As long as they are sold commercially, they must meet the requirements; open source cannot be used as a reason for exemption.
  • Products are accessories/components: as long as they are accessories or components with digital functions placed separately on the market, they are subject to the CRA; not all accessories are excluded.

Advanced: Judgment logic for products with ambiguous boundaries

What we discussed earlier are relatively clear situations, and most ordinary products can be clearly judged by following the steps. But in actual business, there will always be some products with ambiguous boundaries, such as small modules, supporting apps, or old products with upgraded functions. At this time, more detailed judgment logic is needed.

Judgment method for accessories, modules, and components

The first common ambiguous scenario is whether accessories, modules, and components count as standalone products, and whether they need to be judged separately for CRA application.
There is only one core judgment point: whether it is placed separately on the EU market as a standalone product.
If it is a product with digital functions sold separately—such as Bluetooth modules, smart sensors, and development control boards that are independently packaged, priced, and sold to end users or downstream customers—then it is a standalone product with digital elements and needs to comply with the CRA requirements on its own.
If it is just an embedded part inside a certain product and not sold separately on the market—such as the Bluetooth chip inside a Bluetooth headset or the built-in firmware in a smart watch—then it usually does not undergo separate CRA scope judgment as a standalone product, but is evaluated together with the whole device, and the whole device manufacturer bears the main compliance responsibility for placing the product on the market. But note: this does not mean that component suppliers have no relevant obligations at all. Component suppliers may still need to provide necessary information such as security technical documents, vulnerability repair support, and firmware update packages to the whole device manufacturer according to contract or regulatory requirements, to cooperate with the whole device to complete compliance.
There is also a special case: if the same component is both sold separately on the market by the manufacturer and integrated into its own whole device for sale, then they need to be evaluated separately: the separately sold version is judged as a standalone product, and the version integrated into the whole device is evaluated together with the whole device, and they cannot be lumped together.

Boundary between pre-installed software and supporting applications

The second common ambiguous scenario is whether software paired with hardware counts as part of the product.
There are three situations here:
First, firmware, operating systems, and control programs pre-installed in the hardware at the factory are definitely part of the electronic product, and are included in the CRA jurisdiction together with the hardware, without separate judgment.
Second, for supporting apps provided by the manufacturer themselves, if the app is necessary to realize the hardware functions and is sold bundled with the hardware—for example, the supporting app for a smart door lock, without which you cannot set the door lock or view unlock records—then this app also counts as part of the hardware product and is evaluated together with the hardware.
Third, independent applications developed by third parties, such as third-party music apps and third-party smart home control apps that can be installed on smart speakers, do not fall into the scope of this electronic product, and do not need to be judged for CRA application together with the hardware; their own compliance follows the rules for pure software.

Scope changes after product function upgrades

The third easily overlooked point is that the applicable scope of a product is not static. After function upgrades, it may change from “not regulated” to “regulated”.
For example, ordinary kettles in the past were purely mechanical, with no digital chips, so they were definitely not regulated; but new models have added WiFi modules, which can control temperature and timing via mobile phones, so they become products with digital elements and need to be subject to the CRA.
There are also different models in the same series, and you cannot draw conclusions just by looking at the product name. For example, for a certain brand’s headset series, the basic model is a pure wired analog headset with no digital chip, so it is not regulated; the high-end model has Bluetooth and active noise cancellation, with digital processing functions, so it is regulated. You must check the actual functions of the specific model, and cannot take it for granted.

Quick comparison of application probability

To facilitate quick judgment, we divide common products into three tiers according to application probability. You can first match your product to the tier, then decide whether to conduct in-depth checks:

Application ProbabilityTypical Product CategoriesDescription
High probability of applicationConsumer electronics with connectivity/updatable firmware, network equipment, smart home devices, commercial smart terminalsFor example, mobile phones, routers, smart door locks, POS machines, basically all meet the two core criteria
Requires secondary confirmationIndustrial control equipment, professional instruments with digital functions, traditional electrical appliances integrated with digital components, products subject to multiple regulationsFor example, industrial machine tools with digital displays, medical auxiliary equipment, need to first check whether there are exclusive industry regulations
Low probability of applicationSimple electronic accessories without digital chips/connectivity functions, purely mechanical products, equipment only for internal use and not sold externallyFor example, ordinary mechanical screwdrivers, old-fashioned analog radios, equipment made and used by factories themselves, can basically be directly excluded

This table is only for quick reference. Ultimately, the judgment must be based on the previous three-step criteria, and conclusions cannot be drawn solely from the table.

Reminder on the time node for scope determination

The last advanced knowledge point is the time node for scope determination—not all products need to comply with the CRA requirements now. The EU has set phased transition periods, and the core node for judgment is the time when the product is first placed on the EU market.
Specifically:

  1. For products that have been first placed on the EU market before the official application date of the corresponding obligations, the rules for subsequent inventory sales and normal vulnerability patch updates shall be subject to the transition provisions issued by the EU official and the interpretations of the competent authorities, and cannot be generalized.
  2. New products first placed on the EU market after the official application date of the corresponding obligations need to comply with the corresponding CRA requirements.
  3. For old products already placed on the market, if only routine vulnerability repairs and security patch updates are carried out, there is no need to re-judge them as new products; but if major hardware modifications are carried out, or a major software version update causes essential changes to the product’s core functions and security attributes, it is necessary to re-judge them as new products and comply with the latest CRA requirements.

According to the arrangements in the final CRA text published by the EU, the application dates of different obligations are different: vulnerability reporting obligations take effect earlier, and the transition period for core compliance obligations of general products is longer; the specific application dates and differentiated transition arrangements for different product categories are subject to the text, errata, and subsequent guidelines finally issued by the EU official.

Practical operation: 3-step quick self-check and pit avoidance

After explaining all the rules, finally we have sorted out a set of practical methods that can be used directly, so you don’t have to flip through the entire article every time.

3-step quick self-check process

Beginner users can directly follow these 3 steps and make a preliminary judgment in 1 minute:
Step 1: Check whether there are digital functions. See if the product has a digital chip, whether it can connect to the Internet/Bluetooth, whether it can store and process data, and whether there are foreseeable data connection scenarios. If none, directly exclude it and don’t consider the CRA; if yes, proceed to the next step.
Step 2: Check whether the product is placed on the EU market. See if you actively sell to EU users, whether the product is listed on EU e-commerce platforms, whether you ship from EU warehouses, and whether you support orders from EU addresses. If none, directly exclude; if yes, proceed to the next step.
Step 3: Check whether there are exclusive regulations or special exemptions. See if the product belongs to industries with specialized cybersecurity regulations such as medical, automotive, aviation, and maritime, or is for special purposes such as national defense and confidentiality. If yes, the corresponding rules take priority; if not, it needs to comply with the general requirements of the CRA.

Solutions when unsure

If you encounter a product with particularly ambiguous boundaries and are unsure by yourself, there are two reliable solution channels:
First, consult official documents such as CRA implementation guidelines, FAQs, harmonized standards, and product category descriptions issued by the European Commission and member state market supervision authorities. If there are officially released product judgment examples, the official examples shall prevail.
Second, consult professional service providers specializing in EU market compliance, or local EU market competent authorities, to obtain targeted professional opinions.

The 5 most common judgment pitfalls

Finally, let’s list the 5 most common judgment pitfalls, which you can refer to for pit avoidance during self-check:

  1. Only looking at whether the product can directly access the Internet, ignoring data interaction scenarios such as indirect connections and storage media updates—for example, Bluetooth devices connecting to the Internet via mobile phones, and electronic locks updating firmware via USB flash drives, all count as having data connections.
  2. Directly equating “electronic products” with CRA application, forgetting that they must have digital functions—purely analog and purely mechanical products are out of scope.
  3. Thinking that non-EU production and non-EU shipment mean no regulation, forgetting that “actively offering to the EU market” is the core criterion—it counts as long as it targets EU users.
  4. Confusing scope determination with compliance stringency—being subject to the CRA does not mean having to comply with the highest requirements, and the stringency levels vary for different products.
  5. Thinking that accessories and components definitely don’t count, ignoring that separately sold digital accessories are also standalone products—those sold separately on the market need to comply.

Summary

After reading this article, you should have mastered the core judgment ability for the scope of electronic products subject to the CRA:
First, you can independently judge whether most common electronic products fall within the scope of CRA application through the three core dimensions of “digital functions + placement in the EU + specialized regulation check”;
Second, you can quickly identify product categories with high probability of application, requiring secondary confirmation, and low probability of application, improving daily self-check efficiency;
Third, you can avoid the most common scope judgment misunderstandings, such as confusing cybersecurity with content compliance, ignoring indirect data connections, misjudging cross-border sales jurisdiction, confusing application with compliance level, ignoring the responsibilities of independently sold accessories, etc.;
Fourth, when encountering products with ambiguous boundaries, you know to verify conclusions through reliable channels such as official documents and professional institutions.

发表评论

您的邮箱地址不会被公开。 必填项已用 * 标注

滚动至顶部