[Free tools](/free-tools)/[European Union](/free-tools/eu)/CRA product class checker

🇪🇺Free tool · EU

# Which Cyber Resilience Act class is your product?

Pick what your product is and see its CRA class, whether you can self-assess, and the dates that matter — taken from Annexes III and IV of the Regulation.

Does the product contain software or firmware and can it connect to a device or network (directly or indirectly, wired or wireless)?

YesNo

CheckFree · no sign-up · result you can share

## How this works

The Cyber Resilience Act sets cybersecurity requirements for almost every product with software and a data connection sold in the EU. Most products are 'default' and can self-assess. Products whose core function appears in Annex III are 'important' (Class I or Class II), and Annex IV lists 'critical' products — each step up narrows the conformity routes available.

Classification follows the product's core functionality, not every component it contains: a smart speaker with a microcontroller isn't classified as a microcontroller. If your product's main purpose matches a listed category, that class applies to the whole product.

## Questions

### When does the CRA apply?

It entered into force on 10 December 2024. Vulnerability and incident reporting applies from 11 September 2026, and all remaining obligations from 11 December 2027.

### Does the reporting obligation cover products already on the market?

Yes. From 11 September 2026, reporting applies to all products with digital elements made available on the market, including those placed before that date.

### Can I self-assess an important Class I product?

Only if you apply harmonised standards, common specifications or a European cybersecurity certificate in full. Otherwise a notified body is needed.

### Does the CRA apply to medical devices?

No. Devices under the MDR or IVDR are excluded, as are type-approved vehicles, certified civil aviation products and marine equipment.

## Related guides

*   [CE Conformity Assessment Modules Explained: A, B, D, G, H — Which Applies?](/guides/ce-conformity-assessment-modules)
*   [EU Cyber Resilience Act Vulnerability Reporting: The 24-Hour and 72-Hour Deadlines Explained](/guides/eu-cra-vulnerability-reporting-obligations)
*   [EU Cyber Resilience Act: Cybersecurity Requirements for Connected Hardware Products](/guides/eu-cyber-resilience-act)

Regulatory information based on your answers and the sources listed, not legal advice. Krono is not a notified body, test lab or law firm; you remain responsible for your product's compliance.