Scope, Classification & Penalties¶
Draft — needs compliance review before external use
Written as a technical explainer, not legal advice. Verify against the official text of Regulation (EU) 2024/2847 and current guidance before relying on this for a compliance or risk decision.
Who's in scope¶
The CRA's product definition is broad. It applies to a "product with digital elements" — any hardware or software product, plus any remote data processing solution the product depends on to perform its function — that has a direct or indirect logical or physical connection to a device or network. If your device connects to anything, or a network connects to it, it's very likely in scope. That includes the firmware and software used to build, configure, and update the device, and it extends to any cloud/backend service the device can't function without.
There are limited exemptions: spare parts, products exclusively for national defense, and categories already covered by their own sector-specific regulation (certain medical devices, for example, fall under separate EU rules that take precedence). Products given away for free are still in scope if provided in the course of a commercial activity — giving away hardware while selling the associated service doesn't exempt you.
Who carries the obligations¶
The CRA assigns different obligations to different roles in the supply chain:
| Role | What they're responsible for |
|---|---|
| Manufacturer | The full obligation set — security by design, conformity assessment, technical documentation, monitoring, vulnerability handling, and the Article 13/14 reporting duties. This is almost certainly you, if you're reading LAAVAT's docs. |
| Importer | Verifying the product's technical documentation is complete and that the manufacturer completed the required conformity assessment before bringing it into the EU market. |
| Distributor | Verifying the CE mark and CRA conformity are present before making the product available. |
| Open-source software steward | A lighter obligation set — documentation on secure use and vulnerability handling, and a way to report vulnerabilities — reflecting that most OSS is provided without a direct commercial relationship. |
This section, and LAAVAT's platform generally, is written for manufacturers — the role carrying essential-requirements compliance and the reporting deadlines.
Product risk classes¶
Not every connected product carries the same risk, and the CRA doesn't treat them identically. Classification depends on the product's function and context of use, not just its category — the same type of device can land in a different class depending on where and how it's deployed.
| Class | What it means | Assessment route | Example |
|---|---|---|---|
| General | Lower-risk product | Self-assessment | A residential smart thermostat |
| Important — Class I | Moderate risk | Self-assessment if a harmonised (EN) standard covers it; third-party assessment otherwise | A consumer Wi-Fi router; a smart lock tied to a remote alarm system |
| Important — Class II | Direct cybersecurity impact | Third-party assessment required | A smart lock controlling access to a commercial building; a retail point-of-sale terminal |
| Critical | Core to essential services or critical infrastructure | Third-party assessment required; EU cybersecurity certification may apply | Industrial control systems in energy, water, or transport; access control in hospitals or airports |
Harmonised (EN) standards that determine self-assessment eligibility are still being developed by CEN, CENELEC, and ETSI as of this writing — worth tracking if your product's classification depends on one.
Penalties¶
Non-compliance carries real financial exposure, structured in three tiers under Article 64:
| Tier | Applies to | Maximum penalty |
|---|---|---|
| Highest | Non-compliance with Annex I essential requirements, or the manufacturer obligations in Articles 13–14 (this covers most of what this documentation section is about) | €15,000,000 or 2.5% of worldwide annual turnover for the preceding financial year, whichever is higher |
| Middle | Other CRA obligations — importer/distributor duties, conformity assessment, documentation | €10,000,000 or 2% of turnover, whichever is higher |
| Lowest | Supplying incorrect, incomplete, or misleading information to a notified body or market surveillance authority | €5,000,000 or 1% of turnover, whichever is higher |
In every tier, whichever figure is larger applies — for a company with meaningful global revenue, the percentage-of-turnover figure can exceed the fixed euro amount by a wide margin. Beyond fines, market surveillance authorities can order corrective action, product withdrawal, or an outright market ban — for many manufacturers, losing EU market access is the more damaging consequence.