CRASPACE
Scanning · scope · class · risk
CRASPACE
30 min with a CRA specialist - your classification confirmed against real specs, your open questions closed. Free, no obligation.Rulebook v0.5.1Full compliance 11 Dec 2027
Worked example · Medical technology

Out of scope - carved out by Art 2, with conditions

A medical device manufacturer with a connected patient monitor

Worked example - a product archetype run through the CRASPACE rulebook. Not a client engagement, and not a conformity assessment.

The verdict

CRA scope
Out of scope
Class
Out of scope (sectoral)
Basis
Art 2 carve-out
Conformity route
Governed by its own sectoral regime

Descriptor matched: Medical device - governed by MDR / IVDR (Reg 2017/745, 2017/746)

The products assessed

  • Connected patient monitor (MDR Class IIa)Medical device · Wi-Fi, cloud, firmware

Why it lands there

  1. The CRA carves out products already governed by an equivalent sectoral cybersecurity regime. Devices under the Medical Device Regulation and the In-Vitro Diagnostic Regulation are the clearest example - MDR Annex I already imposes cybersecurity requirements.
  2. The carve-out attaches to the product, not the company. A medical device maker that also sells a general-purpose connected accessory, a companion consumer app outside the MDR conformity boundary, or a clinic-network appliance is in scope for those products.
  3. "Out of scope" here is not a compliance conclusion - it is a *routing* conclusion. The equivalent obligations still exist; they arrive under MDR instead.
  4. This example is included deliberately. A scoping tool that only ever finds work for its partner is not a scoping tool. Roughly the most valuable answer this engine gives is the one that says the regulation does not apply to a given product.

What follows from it

  • MDR / IVDR cybersecurity requirements, via the existing notified body route for the device class
  • For any product outside the MDR conformity boundary - an accessory, a consumer app, an IT appliance - the CRA applies normally and needs its own assessment
  • A documented product-by-product boundary, so the carve-out claim is evidenced rather than assumed portfolio-wide

The trap on this one

The mistake is applying the carve-out at company level. A single non-MDR connected product - a waiting-room display, a staff app, a network appliance - is fully in CRA scope, and it is usually the product nobody assigned an owner to.

The questions this leaves open

A public-evidence scan cannot answer these. They are what a consultation is for, and they are deliberately questions rather than instructions.

  • Which products in the portfolio are inside the MDR conformity boundary, and which merely sit next to one?
  • Is the companion app a regulated part of the device, or a separate consumer product?
  • Does any product ship to non-clinical buyers, where the MDR framing would not hold?

The realistic next step

The useful next step is a portfolio boundary review rather than any testing engagement: establishing which products the carve-out genuinely covers, in writing, before an authority asks.

This is an archetype. Yours is not. Run the check against your own company and get the same reasoning applied to the products you actually ship, each with a source you can open.