Module 1 of 8 · 35 min
CRA foundations, timeline, and scope
The regulation's purpose and legal architecture, the staged application timeline, Article 2 scope, Article 3 definitions, and the exclusions that hand products to other regimes.
Learning objectives
- State what Regulation (EU) 2024/2847 requires at the highest level and why it is a regulation, not a directive
- Recall the staged application dates: 11 June 2026, 11 September 2026, and 11 December 2027, and what applies at each
- Determine whether a given product is a product with digital elements in scope under Article 2
- Apply the exclusions for medical devices, aviation, motor vehicles, marine equipment, and national security
- Distinguish placing on the market from making available, and identify when open-source software falls in scope
What the CRA is and why it exists
The Cyber Resilience Act, Regulation (EU) 2024/2847, is the EU's horizontal cybersecurity law for products with digital elements. It entered into force on 10 December 2024.
The law follows the New Legislative Framework: essential requirements in Annex I, conformity assessment before market entry, an EU Declaration of Conformity, and CE marking.
As an EU regulation, it applies directly across all Member States without national transposition laws. It covers every manufacturer placing products on the EU market, regardless of where they are established.
The staged timeline
The regulation applies in stages. From 11 June 2026, rules for notified bodies take effect so assessment bodies can register.
From 11 September 2026, Article 14 reporting duties apply. Manufacturers must follow 24-hour and 72-hour reporting clocks for actively exploited vulnerabilities and severe incidents.
From 11 December 2027, the regulation applies in full, including Annex I essential requirements and conformity assessments.
Three dates carry the exam weight: 11 June 2026 (notified bodies), 11 September 2026 (Article 14 reporting), 11 December 2027 (full application).
Article 2 scope
The CRA covers products with digital elements whose intended use includes a direct or indirect logical or physical data connection. This scope includes both software and hardware.
Remote data processing solutions fall in scope when operated by or for the manufacturer, and when absence prevents a product function. Indirect network connectivity also brings devices in scope.
Standalone SaaS services are generally covered under NIS2, unless they function as direct remote data processing for a connected product.
Exclusions and boundaries
Products covered by sector-specific EU cybersecurity laws are excluded: medical devices under MDR/IVDR, civil aviation under Regulation (EU) 2018/1139, motor vehicles, and marine equipment.
Products built exclusively for national defense or national security are exempt. Spare parts replacing identical components are also exempt.
Free and open-source software supplied without commercial activity remains outside scope. Commercial monetization or paid support brings the software into scope.
The definitions that decide cases
Article 3 defines the core legal terms. A manufacturer designs or markets products under its own name or trademark.
Placing on the market is the first supply of a product on the EU market. Making available means any commercial distribution.
Substantial modifications alter products in ways affecting compliance, potentially making the modifier a manufacturer. An actively exploited vulnerability has reliable evidence of malicious exploitation.
When two answers look right, check the definition. Most scope questions resolve on the precise Article 3 wording, not intuition.
Official sources for this module
Module 1 quiz
10 questions, pass mark 70%, 3 attempts. Starting an attempt consumes it.
Enroll and confirm your email to take the quiz.
Apply this to your product
The modules teach the obligations in the abstract. These two tools answer them for a product you actually place on the market, and neither needs an account.