CRASPACE refers to these throughout your report. This page is a quick, non-legal guide to what each one means. The authoritative text is the official Regulation (EU) 2024/2847 and its implementing regulation 2025/2392.
Everyday products with digital elements (memory chips, most mobile apps, smart speakers, connected toys without special functions). Self-assessment against the essential requirements - no notified body.
Security-adjacent products: password managers, VPNs, network management, browsers, antivirus/EDR, SOHO routers. Self-assessment if you apply harmonised standards; otherwise a notified body.
Higher-impact security products: firewalls, hypervisors, industrial intrusion-detection systems, tamper-resistant microprocessors. A notified body assessment is mandatory.
The highest-risk category: smart cards / secure elements, smart-meter gateways, hardware security modules. Notified body and potentially a mandatory EU cybersecurity certificate.
What every in-scope product must satisfy. Two parts: product properties - secure by design and by default, shipped free of known exploitable vulnerabilities, minimal attack surface, protection of data - and vulnerability-handling processes - an SBOM, coordinated disclosure, and security updates across the support period (typically ~5 years).
The list that defines Important Class I and Class II products (above). Being on this list raises the conformity route above simple self-assessment. See the list →
The narrowest, highest-assurance list - products where a security failure has the broadest blast radius. Always requires a notified body; may require an EU cybersecurity certificate at assurance level ‘substantial’ or higher.
The dossier you must compile and keep: product description, design/development/production details, the cybersecurity risk assessment, the vulnerability-handling processes, applied standards, and the EU Declaration of Conformity. It's the evidence behind your CE mark.
The regulation applies across the EU; the transition period begins.
Actively exploited vulnerabilities & severe incidents must be reported to ENISA and your national CSIRT within 24h / 72h.
All essential requirements apply. CE marking & an EU Declaration of Conformity are required to sell.
Up to €15 million or 2.5% of global annual turnover, whichever is higher - plus withdrawal or recall.
This guide is indicative and simplified - not legal advice or a conformity assessment.