Module 1 of 8 · 35 min
CRA foundations, timeline, and scope
The regulation's purpose and legal architecture, the staged application timeline, Article 2 scope, Article 3 definitions, and the exclusions that hand products to other regimes.
Learning objectives
- State what Regulation (EU) 2024/2847 requires at the highest level and why it is a regulation, not a directive
- Recall the staged application dates: 11 June 2026, 11 September 2026, and 11 December 2027, and what applies at each
- Determine whether a given product is a product with digital elements in scope under Article 2
- Apply the exclusions for medical devices, aviation, motor vehicles, marine equipment, and national security
- Distinguish placing on the market from making available, and identify when open-source software falls in scope
What the CRA is and why it exists
The Cyber Resilience Act, Regulation (EU) 2024/2847, is the EU's horizontal cybersecurity law for products with digital elements. It entered into force on 10 December 2024 and follows the New Legislative Framework: essential requirements in an annex, conformity assessment before market access, an EU Declaration of Conformity, and the CE marking as the visible attestation. Because it is a regulation rather than a directive, it applies directly in every Member State without national transposition, and it applies to any manufacturer, wherever established, whose products are placed on the EU market.
The staged timeline
Application is staged. From 11 June 2026 the provisions on notified bodies apply, so conformity assessment bodies can be notified and start work. From 11 September 2026 the Article 14 reporting obligations apply, putting manufacturers on the 24-hour and 72-hour clocks for actively exploited vulnerabilities and severe incidents. From 11 December 2027 the regulation applies in full, including the Annex I essential requirements and conformity assessment. Products placed on the market before that date are only caught when they are substantially modified afterwards, though Article 14 reporting applies from September 2026 to products placed on the market after that date regardless.
Three dates carry the exam weight: 11 June 2026 (notified bodies), 11 September 2026 (Article 14 reporting), 11 December 2027 (full application).
Article 2 scope
The CRA covers products with digital elements made available on the market whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. That includes software and hardware alike, and their remote data processing solutions where processing is performed remotely by or on behalf of the manufacturer and its absence would prevent a product function. Indirect connectivity counts: a sensor that only reaches a network through a gateway is in scope. Pure services such as SaaS are generally out of scope and left to NIS2, except where they are remote data processing of a product.
Exclusions and boundaries
Products already governed by sector regimes with equivalent cybersecurity coverage are excluded: medical devices under the MDR and IVDR, civil aviation equipment under Regulation (EU) 2018/1139, motor vehicles under the type-approval framework, and marine equipment. Products developed or modified exclusively for national security or defence purposes are excluded, as are spare parts made to replace identical components. Free and open-source software supplied outside a commercial activity is not in scope; monetisation through paid support, hosting, or integration into a commercial product brings it in for whoever monetises it, and open-source software stewards get a tailored light regime.
The definitions that decide cases
Article 3 carries the definitions the exam turns on. A manufacturer develops products or has them developed and markets them under its own name or trademark. Placing on the market is the first making available of a product on the Union market; making available is any supply in the course of a commercial activity. Substantial modification changes a product in a way that affects compliance or intended purpose and can make the modifier a manufacturer. The support period is the time during which vulnerability handling is guaranteed. An actively exploited vulnerability is one for which there is reliable evidence of malicious exploitation, and that definition is the trigger for the strictest reporting clock.
When two answers look right, check the definition. Most scope questions resolve on the precise Article 3 wording, not intuition.
Official sources for this module
Module 1 quiz
10 questions, pass mark 70%, 3 attempts. Starting an attempt consumes it.
Enroll and confirm your email to take the quiz.