CRASPACE
Scanning · scope · class · risk
CRASPACE
30 min with a CRA specialist - your classification confirmed against real specs, your open questions closed. Free, no obligation.Rulebook v0.5.1Full compliance 11 Dec 2027
Methodology v0.3.0 · rulebook 0.5.1

How CRASPACE decides

Every verdict is produced by a deterministic, versioned rulebook rather than by a model. This page is that rulebook: the scoping flow, the four classes, the conformity route each one carries, and the eleven checkpoints a manufacturer is assessed against - each with the Article or Annex it rests on.

Status: draft, pending specialist validation. This methodology is published at version 0.3.0 so that it can be read, cited and disagreed with. It has not been validated by a named regulatory specialist, and it is not legal advice or a conformity assessment. Where it is wrong, it is wrong in public and in a versioned document.

Why a rulebook and not a model

Product discovery uses AI: it reads a company's own site to find out what that company sells. Classification does not. The verdict comes from descriptors matched against Annex III and Annex IV, so the same inputs always produce the same output, every verdict carries the methodology version that produced it, and a cached report is regenerated when that version changes.

The practical test of that separation: a page on this site cannot state a class the tool would not give, because both read the same file.

The scoping flow

Six steps, in order. Steps 1 and 4 are decided by the engine. Steps 0, 2, 3 and 6 depend on facts that are not in a product description - who manufactures it, whether a sectoral regime already governs it - so they are recorded as reasoning and sensitivities rather than auto-decided. A hypothesis is labelled as one.

  1. 0Manufacturer testArt 3(13)
  2. 1Automotive carve-outArt 2(2)(c) · Reg 2019/2144 / UN R155-R156
  3. 2Other sectoral carve-outs (marine / medical / aviation / defence)Art 2(4),(7)
  4. 3Identical spare partArt 2(6)
  5. 4Classification (core-functionality test)Impl. Reg 2025/2392 · Annex III/IV
  6. 5Conformity routeArt 32
  7. 6Parallel-regime checkMachinery / NIS2 / RED / GDPR / PLD

The four classes

Annex III lists 19 Class I and 4 Class II categories; Annex IV lists 3 critical ones. Everything else with digital elements is Default. 24 pages cover those 26 categories one by one.

ClassAnnexConformity route
CriticalAnnex IVArt 32(3) procedures (as Class II) - plus an EU cybersecurity certificate at assurance ≥ substantial IF the Commission adopts a delegated act under Art 8(1) for the category
Important - Class IIAnnex III, Part IIThird-party (notified body) assessment mandatory
Important - Class IAnnex III, Part ISelf-assessment only if harmonised standards applied; else notified body
Defaultn/aSelf-assessment (Module A)

The eleven checkpoints

What a manufacturer is assessed against, each with its basis in the regulation. A checkpoint with public evidence is met, with partial evidence is partial, and with none is unknown - not failed. Absence of public evidence is not evidence of a gap, and a maturity score built from silence would be a number we invented.

  1. Cybersecurity risk assessment Art 13(2)
  2. Secure-by-design essential requirements Annex I Pt I
  3. Vulnerability-handling process Annex I Pt II
  4. Software bill of materials (SBOM) Annex I Pt II §1
  5. Coordinated vulnerability disclosure policy Art 13 · Annex I Pt II
  6. Security updates & support period Art 13(8)
  7. Technical documentation (Annex VII) Annex VII
  8. Conformity assessment & EU Declaration of Conformity Art 28 · Annex V
  9. CE marking Art 30
  10. Vulnerability & incident reporting readiness Art 14 (from 11 Sep 2026)
  11. Economic-operator & market-surveillance obligations Art 13/19–24 · Annex II

Where none of the eleven is evidenced, the report shows 0 of 11 · NOT SCORED rather than a score. That is deliberate and is not a defect to fix.

Obligations, whatever the class

Class decides the conformity route. It does not decide whether these apply.

  • Essential requirements (Annex I) - secure by design & default
  • Machine-readable SBOM
  • Coordinated vulnerability disclosure policy
  • Security updates across support period (~5 yrs)
  • Technical documentation (Annex VII)
  • Conformity assessment (route depends on class)
  • CE marking + EU Declaration of Conformity
  • 24h / 72h reporting to ENISA + CSIRT (from Sep 2026)

What this stops short of

The assessment identifies; it does not prescribe. It gives scope, classification per product, a readiness checklist and the open questions that would change the answer. It deliberately does not produce a remediation roadmap - that depends on your architecture, your suppliers and your release process, none of which is visible from outside.

On the boundary of what we can do: CRASPACE is not a notified body and does not issue CRA certificates. Where a product is Critical under Annex IV, the honest next step is guidance plus a hand-off to an accredited certification body, and that is what the tool says.

Sources

Key dates: reporting obligations from 11 September 2026, full compliance from 11 December 2027. Market-surveillance authorities can order corrective action, withdrawal or recall, and fines reach €15 million or 2.5% of global annual turnover.

Run it against your own products

The check applies exactly this methodology and shows the reasoning and the citation for every product it classifies.

Category by category