EU CRA FAQs
Technical Frequently Asked Questions and statutory interpretations on Regulation (EU) 2024/2847 (Cyber Resilience Act). Comprehensive reference of 76 statutory questions across scopes, definitions, economic operator obligations, and CE marking.
Scope & Definitions
Scope criteria, definitions of products with digital elements (PDE), data connections, and exclusions.
Interplay with other EU Legislation
Interplay with NIS2, EU AI Act, Machinery Regulation, Product Liability, Medical Devices, and GPSR.
Classification of Products with Digital Elements
Classification criteria determining Default, Important (Class I / Class II), and Critical products.
Manufacturer Obligations & Risk Assessments
Essential cybersecurity requirements (Annex I), risk assessment, secure-by-default, and support periods.
Reporting Obligations for Active Exploits & Severe Incidents
Mandatory 24-hour reporting of actively exploited vulnerabilities and severe incidents to ENISA and CSIRTs.
Conformity Assessment, Modules & Technical Documentation
Conformity assessment routes: Module A (internal control), Module B+C, Module H, and Notified Bodies.
Transition Period & Application Timelines
Application deadlines (11 Sep 2026 for reporting, 11 Dec 2027 for full application) and pre-existing stock rules.
This Site Uses No Cookies
Eigenia does not set cookies. The only thing stored in your browser is one preference, saved in local storage, noting that you have seen this notice.