30 min with a CRA specialist - your classification confirmed against real specs, your open questions closed. Free, no obligation.Rulebook v0.5.1Full compliance 11 Dec 2027
Annex III, Class I, point 15
Is an FPGA or ASIC covered by the CRA?
Only with security-related functionalities. Annex III Class I point 15 covers application specific integrated circuits and field-programmable gate arrays with security-related functionalities. A general-purpose FPGA or ASIC without them is not in the category.
ClassImportant - Class I
What that class requiresSelf-assessment only if harmonised standards applied; else notified body
The category, quoted in full:
Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalities
This is one of the few categories where the same physical part is in or out depending on what it does. An FPGA loaded with a cryptographic bitstream and the same FPGA doing video conversion are different answers.
Points 13 and 14 cover microprocessors and microcontrollers with the same qualifier. The distinction is architectural, not regulatory - the class and the route are identical.
Obligations that apply to every product in scope, whatever its class:
Essential requirements (Annex I) - secure by design & default
Economic-operator & market-surveillance obligations Art 13/19–24 · Annex II
The dates that matter:
11 September 2026 - reporting obligations for actively exploited vulnerabilities and severe incidents apply.
11 December 2027 - full compliance applies.
Market-surveillance authorities can order corrective action, withdrawal or recall, and fines reach €15 million or 2.5% of global annual turnover.
Check your own products against this
The same rulebook that produced this page runs the free check. It reads your products, classifies each one against Annex III and IV, and gives you an indicative verdict with the reasoning and citation for every product.