← CRA FAQScope and applicability

Which products are outside the scope of the CRA?

Also asked

  • Are medical devices covered by the Cyber Resilience Act?
  • Is marine equipment in scope of the CRA?
  • Do spare parts fall under the CRA?
  • Can the Commission take more products out of CRA scope later?

Article 2 carves out six groups. Medical devices under Regulations 2017/745 and 2017/746, motor vehicles under Regulation 2019/2144, products certified under the aviation Regulation 2018/1139, and marine equipment under Directive 2014/90/EU are excluded outright. So are spare parts manufactured to the same specifications as the identical components they replace, and products developed or modified exclusively for national security or defence, including anything specifically designed to process classified information. Everything else made available on the Union market with a data connection is in scope from 11 December 2027.

Each exclusion exists because another instrument already carries the cybersecurity duty, so an excluded product is regulated elsewhere rather than unregulated.

At a glance

Medical devices and IVDs
Excluded, Article 2(2), points (a) and (b)
Motor vehicles
Excluded, Article 2(2), point (c)
Civil aviation
Excluded where certified under Regulation (EU) 2018/1139, Article 2(3)
Marine equipment
Excluded, Article 2(4)
Spare parts
Excluded where identical and to the same specifications, Article 2(6)
Defence and classified
Excluded, Article 2(7)
Everything else
In scope from 11 December 2027

Last reviewed 7 August 2026

Verified against Regulation (EU) 2024/2847 Articles 2, 3, 32 and 71 as published in OJ L, 20.11.2024, read in full text on EUR-Lex on 7 August 2026, and Commission guidance C(2026) 5252 final of 27 July 2026.

What Article 2 actually removes

The general rule in Article 2(1) is wide. The CRA applies to products with digital elements made available on the market whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network.[1] The exclusions that follow are specific and closed.

Three instruments displace the CRA outright under Article 2(2). Products to which the Medical Device Regulation (EU) 2017/745 applies, products to which the In Vitro Diagnostic Medical Devices Regulation (EU) 2017/746 applies, and products to which the motor vehicle type-approval Regulation (EU) 2019/2144 applies.[1]

Two more sit in their own paragraphs. Article 2(3) removes products certified in accordance with the civil aviation Regulation (EU) 2018/1139, and Article 2(4) removes equipment falling within the scope of the marine equipment Directive 2014/90/EU.[1][4]

Article 2(7) removes products developed or modified exclusively for national security or defence purposes, and products specifically designed to process classified information. Article 2(8) adds that no obligation under the Regulation requires supplying information whose disclosure would run contrary to a Member State's essential national security, public security or defence interests.[1]

CRA referenceArticle 2(1) to (4), (7) and (8)

The two exclusions summaries usually miss

Most published summaries of CRA scope list medical devices, vehicles, aviation and defence, then stop. Two more exclusions carry real commercial weight.

Marine equipment under Directive 2014/90/EU is a full carve-out in Article 2(4), not a partial one. A manufacturer supplying bridge, navigation or safety equipment covered by that Directive is outside the CRA for those products, and inside it for anything else it sells.[1][4]

Spare parts are excluded by Article 2(6), and the wording is narrow enough to matter. The exclusion reaches spare parts made available on the market to replace identical components in products with digital elements, manufactured according to the same specifications as the components they are intended to replace.[1] A replacement part that is improved, redesigned or built to a different specification does not meet that description, so a supplier treating its whole spares catalogue as out of scope is likely to be wrong about part of it.

CRA referenceArticle 2(4) and (6)

Why an exclusion is not an exemption

Every sectoral exclusion in Article 2 exists because another Union instrument already imposes cybersecurity duties on the same product. Medical devices carry cybersecurity, post-market surveillance and incident reporting duties through the MDR and IVDR. Type-approved vehicles carry a cybersecurity management system obligation maintained across the vehicle lifecycle. Certified aviation products are assessed through the EASA framework.

The practical effect is single regulation rather than no regulation. A manufacturer that establishes an exclusion has answered which regime applies, not whether one does. Article 2(5) makes the logic explicit for future cases: the CRA's application to products covered by other Union rules addressing all or some of the Annex I risks may be limited or excluded, but only where that is consistent with the overall regulatory framework and where the sectoral rules achieve the same or a higher level of protection.[1]

Commission guidance C(2026) 5252 works through borderline cases at the edges of these boundaries.[5]

CRA referenceArticle 2(2), (3) and (5)

The boundary can move without the Regulation changing

Article 2(5) empowers the Commission to adopt delegated acts under Article 61 specifying whether a limitation or exclusion is necessary, which products and rules are concerned, and the scope of any limitation.[1] A scope determination made today is therefore a position to re-check rather than a settled fact.

One boundary is worth stating plainly because it is regularly misread as an exclusion. Free and open-source software is not excluded by Article 2. The test sits in the definition of making available on the market, which reaches supply for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge.[2] Software supplied outside a commercial activity falls away on that definition rather than through Article 2, and Article 24 then creates a lighter regime for open-source software stewards.

Even inside Annex III, open source keeps a concession that is easy to miss. Article 32(5) lets manufacturers of products qualifying as free and open-source software that fall under the Annex III categories demonstrate conformity using an Article 32(1) procedure, which keeps internal control available.[3]

CRA referenceArticle 2(5), Article 3, point (22), and Article 32(5)

Sources

Every claim above traces to one of these. Items marked Binding are law in force. Everything else is interpretive and is labelled as such.

  1. [1]

    Publications Office of the European Union · Article 2(1) to (8) · CELEX:32024R2847 · OJ L, 20.11.2024

    spare parts that are made available on the market to replace identical components in products with digital elements

    Accessed 2026-08-07

  2. [2]

    Publications Office of the European Union · Article 3, point (22) · CELEX:32024R2847 · OJ L, 20.11.2024

    the supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity

    Accessed 2026-08-07

  3. [3]

    Publications Office of the European Union · Article 32(5) · CELEX:32024R2847 · OJ L, 20.11.2024

    Accessed 2026-08-07

  4. [4]

    Publications Office of the European Union · Directive as a whole, as applied by CRA Article 2(4) · CELEX:32014L0090

    Accessed 2026-08-07

  5. [5]

    European Commission · C(2026) 5252

    Non-binding. Only the Court of Justice of the European Union can give an authoritative interpretation of the CRA.

    Accessed 2026-08-07

Follow-up questions

Our product is excluded. Do we still have to do anything?+

Under the CRA, no. Under the instrument that displaced it, almost certainly yes. Each exclusion in Article 2 points at a regime that already carries cybersecurity obligations for that product class. Record which regime applies per product line and why, because a company with several lines will frequently be inside the CRA for some and outside for others, and the determination is the thing an authority will ask to see.

We sell the same component into vehicles and into the general market. Which applies?+

Assess the versions separately. The Article 2(2), point (c) exclusion attaches to products to which the vehicle type-approval Regulation applies. A component supplied through channels open to the general public is not covered by that framework merely because an identical part also goes into vehicles, so the general-market version needs its own scope determination.

Does an exclusion cover the software we ship alongside the product?+

Only where that software falls inside the same excluded framework. Software necessary for hardware to perform its intended functions forms a single product with that hardware, so it follows the hardware's position. Separate software supplied for its own purposes is assessed on its own, and may well sit inside the CRA while the hardware sits outside it.

Work out where your product actually lands

Free CRA classification for your product, a vulnerability disclosure portal on your own domain, and Article 14 deadline tracking. Receiving and tracking reports is free for every manufacturer placing products with digital elements on the EU market.