Free CRA tool

Classify your product under the CRA in 2 minutes

Describe your product or pick a category to see its EU Cyber Resilience Act class, the Article 32 conformity assessment route, and the applicable vertical standard being drafted. Free tool with no signup and no data stored.

Platform coverage: CVD Portal provides an end-to-end self-assessment compliance path for Default-class products (Module A). For Important and Critical products, which require category-specific vertical standards and a third-party notified body, our platform helps you build the technical file and risk assessment evidence for your assessment body.

Decision diagram from CRA product class to conformity assessment route. A product with digital elements is classified against Annex III and Annex IV, which yields four lanes. Default, not listed in Annex III or Annex IV, routes to Module A internal control with no notified body. Important Class I, Annex III Class I with 19 categories, routes to Module A only with full standards coverage, otherwise B plus C or H, so a notified body is conditional. Important Class II, Annex III Class II with 4 categories, routes to Module B plus C, Module H, or a certification scheme, and always needs a notified body. Critical, Annex IV with 3 categories, routes to a mandated certification scheme, otherwise the Class II routes, and always needs a notified body.
Module A self-assessment is open to default-class products. Important products (Annex III) and critical products (Annex IV) need a notified body or a European cybersecurity certification scheme and must comply with specific vertical standards, because no CRA harmonised standard is cited in the Official Journal yet. For those, CVD Portal prepares the technical file and the Annex I evidence the assessment body asks for, and does not replace it.

Step 1 of 2

How does it reach users?

This decides whether the CRA applies at all. A web app used only in a browser is not a product with digital elements.

Frequently asked questions

What is the difference between horizontal and vertical standards?

Horizontal standards (such as CEN/CENELEC EN 40000) apply across all products with digital elements. They define core cybersecurity principles, risk management, and vulnerability handling processes. Vertical standards (such as the ETSI EN 304 6xx series and CENELEC prEN 50765/50770) specify detailed technical requirements for specific product categories like firewalls, routers, password managers, and microcontrollers. Our classifier identifies the applicable vertical standard for your product.

Which products can use CVD Portal for complete CRA self-assessment?

CVD Portal provides the complete automated compliance path (Module A internal control) for Default-class products, which represent the vast majority of products with digital elements. For Important (Class I/II) and Critical products, the CRA requires third-party conformity assessment by a Notified Body or an EU cybersecurity certification scheme (EUCC). For those products, CVD Portal prepares the Annex I risk assessment and technical documentation file for your Notified Body, but does not perform laboratory testing or issue certificates.

Is your product in scope at all?

Is a web application covered by the CRA?

Generally no. Commission guidance C(2026) 5252 confirms that software which executes remotely and is merely accessed by the user is not, on that basis alone, a product with digital elements. A web application reached exclusively through a browser therefore falls outside the CRA, and so does a website that only presents information to visitors. For software to be in scope it must be provided to a user, obtained by that user, and operated on or as part of an electronic information system on the user’s side.

What if we also ship a desktop or mobile app?

Then that app is in scope. A client users download and install executes on their device, which makes it a product with digital elements even where it is built with web technologies. A browser extension is in scope on the same reasoning. Where the client relies on data processing at a distance to perform one of its functions, and that software was designed and developed by you or under your responsibility, the processing forms part of the product as a remote data processing solution.

Is hardware plus its companion app one product or two?

One. Software necessary to operate, configure, control or use hardware in accordance with its intended purpose is part of the same product, even when it arrives through a separate channel such as an app store or a download link after the hardware was placed on the market. Printer drivers and companion apps for wearables both fall on this side of the line, and the combination is classified on the core functionality of the product as a whole.

What applies if the CRA does not?

Falling outside the CRA does not mean falling outside EU cybersecurity law. Directive (EU) 2022/2555 covers cloud computing service providers, with requirements specified by Implementing Regulation (EU) 2024/2690. Regulation (EU) 2022/2554 covers financial entities and their ICT service providers. The GDPR continues to apply to any processing of personal data. Your customers may also ask for evidence regardless, because manufacturers must risk-assess their external dependencies and exercise Article 13(5) due diligence on integrated components.

Does free and open-source software count?

Only where it is supplied in the course of a commercial activity. Charging a price, monetising other services through the software, or requiring personal data processing as a condition of use all count. Selling optional professional services around freely downloadable software does not, and donations generally do not unless access or updates are conditioned on donating. Where the software is published but not placed on the market, the publisher may still be an open-source software steward under Article 24, with a narrower set of obligations.