CRASPACE
Scanning · scope · class · risk
CRASPACE
30 min with a CRA specialist - your classification confirmed against real specs, your open questions closed. Free, no obligation.Rulebook v0.5.1Full compliance 11 Dec 2027
Annex III, Class I, point 19

Is a fitness tracker or smartwatch covered by the CRA?

Yes, if it monitors health and is not a medical device, or if it is intended for children. Annex III Class I point 19 covers personal wearables with a health monitoring purpose to which the medical device regulations do not apply, and personal wearables intended for use by and for children.

ClassImportant - Class I
What that class requiresSelf-assessment only if harmonised standards applied; else notified body

The category, quoted in full:

Personal wearable products to be worn or placed on a human body that have a health monitoring (such as tracking) purpose and to which Regulation (EU) 2017/745 or (EU) 2017/746 do not apply, or personal wearable products that are intended for the use by and for children

Annex III, Class I, point 19, Regulation (EU) 2024/2847

The medical device carve-out points the other way from the rest of the annex: if Regulation (EU) 2017/745 or 2017/746 applies, the product is outside this category rather than more heavily regulated by it.

Frequently confused with:

A worked example:

Connected medical deviceA CRA verdict worth as much as an in-scope one: a device regulated under MDR/IVDR is carved out by Art 2 - with the boundary conditions that decide it.

Obligations that apply to every product in scope, whatever its class:

  • Essential requirements (Annex I) - secure by design & default
  • Machine-readable SBOM
  • Coordinated vulnerability disclosure policy
  • Security updates across support period (~5 yrs)
  • Technical documentation (Annex VII)
  • Conformity assessment (route depends on class)
  • CE marking + EU Declaration of Conformity
  • 24h / 72h reporting to ENISA + CSIRT (from Sep 2026)

What a manufacturer is assessed against:

  1. Cybersecurity risk assessment Art 13(2)
  2. Secure-by-design essential requirements Annex I Pt I
  3. Vulnerability-handling process Annex I Pt II
  4. Software bill of materials (SBOM) Annex I Pt II §1
  5. Coordinated vulnerability disclosure policy Art 13 · Annex I Pt II
  6. Security updates & support period Art 13(8)
  7. Technical documentation (Annex VII) Annex VII
  8. Conformity assessment & EU Declaration of Conformity Art 28 · Annex V
  9. CE marking Art 30
  10. Vulnerability & incident reporting readiness Art 14 (from 11 Sep 2026)
  11. Economic-operator & market-surveillance obligations Art 13/19–24 · Annex II

The dates that matter:

  • 11 September 2026 - reporting obligations for actively exploited vulnerabilities and severe incidents apply.
  • 11 December 2027 - full compliance applies.
  • Market-surveillance authorities can order corrective action, withdrawal or recall, and fines reach €15 million or 2.5% of global annual turnover.

Check your own products against this

The same rulebook that produced this page runs the free check. It reads your products, classifies each one against Annex III and IV, and gives you an indicative verdict with the reasoning and citation for every product.

All categories