30 min with a CRA specialist - your classification confirmed against real specs, your open questions closed. Free, no obligation.Rulebook v0.5.1Full compliance 11 Dec 2027
Worked example · Consumer hardware
In scope, Default class - the outcome ~90% of products get
A mid-size domestic appliance manufacturer
Worked example - a product archetype run through the CRASPACE rulebook. Not a client engagement, and not a conformity assessment.
Companion mobile appMobile application · app, API, cloud
Why it lands there
The oven is a product with digital elements: it contains software and connects to a network. That alone puts it in scope - the CRA is not a security-products regulation, it is a connected-products regulation.
It matches no descriptor in Annex III or Annex IV. It is not a router, not a security device, not a smart lock. So it lands in Default, the residual class.
The companion app is assessed as its own product with digital elements, not as an accessory to the oven. It also lands in Default.
Default is the *conformity route*, not an exemption. Every Annex I essential requirement still applies in full, and the manufacturer self-declares against them.
What follows from it
✓Annex I essential requirements - secure by default, no known exploitable vulnerabilities at release, minimised attack surface
✓A machine-readable SBOM covering the firmware and the app
✓A coordinated vulnerability disclosure policy, published and reachable
✓Free security updates across the declared support period, with the support end date communicated to buyers
✓The Annex VII technical file, plus CE marking and an EU Declaration of Conformity
The trap on this one
The common mistake here is reading "Default" as "nothing to do". Default decides *who assesses conformity* - you, rather than a notified body. It does not reduce the Annex I requirements by a single line.
The questions this leaves open
A public-evidence scan cannot answer these. They are what a consultation is for, and they are deliberately questions rather than instructions.
What is the declared support period for the oven, and is it stated where a buyer sees it before purchase?
Does the SBOM cover the third-party cloud SDKs inside the companion app, or only the firmware?
Is there a published route for a researcher to report a vulnerability, and a named owner for what arrives on it?
The realistic next step
Device testing against EN 18031 and EN 303 645 produces most of the evidence a Default-class Annex I self-declaration rests on - secure defaults, update integrity, no exposed interfaces. That is the cheapest evidence to obtain and the first thing an authority asks for.
This is an archetype. Yours is not. Run the check against your own company and get the same reasoning applied to the products you actually ship, each with a source you can open.