CRASPACE
Scanning · scope · class · risk
CRASPACE
30 min with a CRA specialist - your classification confirmed against real specs, your open questions closed. Free, no obligation.Rulebook v0.5.1Full compliance 11 Dec 2027
Frequently asked questions

Your questions about the EU Cyber Resilience Act

The questions we are asked most, answered plainly. If yours is about a specific product, the free check will answer it faster than any general answer can - and a specialist will pick up anything it cannot, within 1 business day.

Both. A “product with digital elements” is any hardware or software placed on the EU market that can connect to a device or network, or that contains software - from firmware and mobile apps to operating systems and browser components. There is no hardware exemption: a pure-software vendor can be in scope, and if the product is a security product such as a password manager or a VPN it classifies as Important rather than Default. Services consumed purely remotely are treated differently from software you place on the market, and that boundary usually runs through a portfolio rather than around a company.
If you place products on the EU market, yes. Non-EU manufacturers are fully in scope and generally need an EU-based responsible person - an authorised representative or the importer - to hold the documentation and deal with market-surveillance authorities. Selling through an EU distributor does not move the manufacturer's obligations onto them; it adds obligations for the distributor.
No. Roughly 90% of products are Default class and are self-assessed under Module A. Important Class I products (Annex III Part I - routers, password managers, VPNs, operating systems, antivirus) can also be self-assessed, but only where the relevant harmonised standards are applied; otherwise a notified body is required. Important Class II products (Annex III Part II - firewalls, hypervisors, industrial intrusion-detection systems) require a notified body with no self-assessment alternative. Critical products (Annex IV - smart cards and secure elements, smart-meter gateways, hardware security modules) require a notified body and potentially a mandatory EU cybersecurity certificate.
The regulation entered into force on 10 December 2024. From 11 September 2026 the reporting obligations apply: actively exploited vulnerabilities and severe incidents must be reported to ENISA and your national CSIRT within 24 hours, with a follow-up within 72 hours. From 11 December 2027 all essential requirements apply in full, and products with digital elements need CE marking and an EU Declaration of Conformity. The reporting date is the one most programmes underestimate, because it needs a working process rather than a finished product.
Up to €15 million or 2.5% of global annual turnover, whichever is higher. Separately from fines, national market-surveillance authorities can order corrective action, require a product to be withdrawn, or order a recall across the EU. Enforcement sits with those national authorities, so exposure is per-market rather than a single EU-level process.
Use the free check on the CRASPACE home page. Enter your company name - and optionally your website - and the tool searches public sources, reads your product pages, classifies each product it finds against Annex III and Annex IV using a versioned rulebook, and gives you a scope verdict with a confidence indicator. It takes about two minutes and needs no account. You can correct or add products afterwards and the verdict recomputes live.
Run a cybersecurity risk assessment across the product lifecycle, build security in by design and by default to meet the Annex I essential requirements, stand up a vulnerability-handling process and publish a machine-readable SBOM, ship free security updates across the declared support period and tell users when it ends, compile the Annex VII technical documentation, run the conformity assessment for your product's class, and affix the CE mark with an EU Declaration of Conformity. Reporting of actively exploited vulnerabilities begins 11 September 2026.
Yes, where an equivalent sectoral regime already applies. Medical devices under MDR/IVDR, motor vehicles under Reg 2019/2144 and UN R155/R156, certified civil aviation under Reg 2018/1139, and marine equipment under Directive 2014/90/EU are outside CRA scope. The carve-out attaches to the product, not the company: a medical device manufacturer's waiting-room display, staff app or network appliance is fully in scope, and that is usually the product with no assigned owner.
No, and it is important that it is not read as one. CRASPACE produces an indicative scoping hypothesis from public information, with a confidence indicator, so you can prioritise. It is not legal advice, not a conformity assessment, and not a determination of compliance. Confirm any classification against your actual product specifications and sales channels, and take qualified advice before relying on it.
The verdict is set by a deterministic, versioned rulebook - the same inputs always produce the same result - and the AI layer only retrieves and structures public text. Products are extracted from pages actually fetched from your own site, never recalled from a model's memory, and each one carries a citation you can open. Where public evidence cannot support a number, the report returns nothing for it and says so rather than printing a figure built from silence.

Still not sure whether the CRA applies to you? The check reads your own product pages and classifies what it finds - about two minutes, no account.