Skip to content

Scope, Classification & Penalties

Draft — needs compliance review before external use

Written as a technical explainer, not legal advice. Verify against the official text of Regulation (EU) 2024/2847 and current guidance before relying on this for a compliance or risk decision.

Who's in scope

The CRA's product definition is broad. It applies to a "product with digital elements" — any hardware or software product, plus any remote data processing solution the product depends on to perform its function — that has a direct or indirect logical or physical connection to a device or network. If your device connects to anything, or a network connects to it, it's very likely in scope. That includes the firmware and software used to build, configure, and update the device, and it extends to any cloud/backend service the device can't function without.

There are limited exemptions: spare parts, products exclusively for national defense, and categories already covered by their own sector-specific regulation (certain medical devices, for example, fall under separate EU rules that take precedence). Products given away for free are still in scope if provided in the course of a commercial activity — giving away hardware while selling the associated service doesn't exempt you.

Who carries the obligations

The CRA assigns different obligations to different roles in the supply chain:

Role What they're responsible for
Manufacturer The full obligation set — security by design, conformity assessment, technical documentation, monitoring, vulnerability handling, and the Article 13/14 reporting duties. This is almost certainly you, if you're reading LAAVAT's docs.
Importer Verifying the product's technical documentation is complete and that the manufacturer completed the required conformity assessment before bringing it into the EU market.
Distributor Verifying the CE mark and CRA conformity are present before making the product available.
Open-source software steward A lighter obligation set — documentation on secure use and vulnerability handling, and a way to report vulnerabilities — reflecting that most OSS is provided without a direct commercial relationship.

This section, and LAAVAT's platform generally, is written for manufacturers — the role carrying essential-requirements compliance and the reporting deadlines.

Product risk classes

Not every connected product carries the same risk, and the CRA doesn't treat them identically. Classification depends on the product's function and context of use, not just its category — the same type of device can land in a different class depending on where and how it's deployed.

Class What it means Assessment route Example
General Lower-risk product Self-assessment A residential smart thermostat
Important — Class I Moderate risk Self-assessment if a harmonised (EN) standard covers it; third-party assessment otherwise A consumer Wi-Fi router; a smart lock tied to a remote alarm system
Important — Class II Direct cybersecurity impact Third-party assessment required A smart lock controlling access to a commercial building; a retail point-of-sale terminal
Critical Core to essential services or critical infrastructure Third-party assessment required; EU cybersecurity certification may apply Industrial control systems in energy, water, or transport; access control in hospitals or airports

Harmonised (EN) standards that determine self-assessment eligibility are still being developed by CEN, CENELEC, and ETSI as of this writing — worth tracking if your product's classification depends on one.

Penalties

Non-compliance carries real financial exposure, structured in three tiers under Article 64:

Tier Applies to Maximum penalty
Highest Non-compliance with Annex I essential requirements, or the manufacturer obligations in Articles 13–14 (this covers most of what this documentation section is about) €15,000,000 or 2.5% of worldwide annual turnover for the preceding financial year, whichever is higher
Middle Other CRA obligations — importer/distributor duties, conformity assessment, documentation €10,000,000 or 2% of turnover, whichever is higher
Lowest Supplying incorrect, incomplete, or misleading information to a notified body or market surveillance authority €5,000,000 or 1% of turnover, whichever is higher

In every tier, whichever figure is larger applies — for a company with meaningful global revenue, the percentage-of-turnover figure can exceed the fixed euro amount by a wide margin. Beyond fines, market surveillance authorities can order corrective action, product withdrawal, or an outright market ban — for many manufacturers, losing EU market access is the more damaging consequence.