CRASPACE
Scanning · scope · class · risk
CRASPACE
30 min with a CRA specialist - your classification confirmed against real specs, your open questions closed. Free, no obligation.Rulebook v0.5.1Full compliance 11 Dec 2027
Worked example · Consumer hardware

In scope, Default class - the outcome ~90% of products get

A mid-size domestic appliance manufacturer

Worked example - a product archetype run through the CRASPACE rulebook. Not a client engagement, and not a conformity assessment.

The verdict

CRA scope
In scope
Class
Default
Basis
Not listed in Annex III or IV
Conformity route
Self-assessment (Module A)

The products assessed

  • Wi-Fi connected ovenHome appliance · Wi-Fi, companion app, cloud
  • Companion mobile appMobile application · app, API, cloud

Why it lands there

  1. The oven is a product with digital elements: it contains software and connects to a network. That alone puts it in scope - the CRA is not a security-products regulation, it is a connected-products regulation.
  2. It matches no descriptor in Annex III or Annex IV. It is not a router, not a security device, not a smart lock. So it lands in Default, the residual class.
  3. The companion app is assessed as its own product with digital elements, not as an accessory to the oven. It also lands in Default.
  4. Default is the *conformity route*, not an exemption. Every Annex I essential requirement still applies in full, and the manufacturer self-declares against them.

What follows from it

  • Annex I essential requirements - secure by default, no known exploitable vulnerabilities at release, minimised attack surface
  • A machine-readable SBOM covering the firmware and the app
  • A coordinated vulnerability disclosure policy, published and reachable
  • Free security updates across the declared support period, with the support end date communicated to buyers
  • The Annex VII technical file, plus CE marking and an EU Declaration of Conformity

The trap on this one

The common mistake here is reading "Default" as "nothing to do". Default decides *who assesses conformity* - you, rather than a notified body. It does not reduce the Annex I requirements by a single line.

The questions this leaves open

A public-evidence scan cannot answer these. They are what a consultation is for, and they are deliberately questions rather than instructions.

  • What is the declared support period for the oven, and is it stated where a buyer sees it before purchase?
  • Does the SBOM cover the third-party cloud SDKs inside the companion app, or only the firmware?
  • Is there a published route for a researcher to report a vulnerability, and a named owner for what arrives on it?

The realistic next step

Device testing against EN 18031 and EN 303 645 produces most of the evidence a Default-class Annex I self-declaration rests on - secure defaults, update integrity, no exposed interfaces. That is the cheapest evidence to obtain and the first thing an authority asks for.

This is an archetype. Yours is not. Run the check against your own company and get the same reasoning applied to the products you actually ship, each with a source you can open.