CRA knowledge base
Questions & answers on the Cyber Resilience Act
Made understandable based on the European Commission’s official FAQ – sorted by topic. Search the terms or pick a topic block.
Topic blocks
Scope
When does a connected product fall under the CRA – and what is excluded?
9 questions View all questions →Interplay with other EU law
Relationship to machinery, medical, radio, product-safety, GDPR and data law.
17 questions View all questions →Important & critical products
Which products count as “important” or “critical” – and what follows?
4 questions View all questions →Manufacturer obligations
Risk assessment, vulnerabilities, security updates, components and support period.
28 questions View all questions →Reporting obligations
Reporting actively exploited vulnerabilities and severe incidents to ENISA/CSIRT.
4 questions View all questions →Conformity assessment & CE
Modules A/B+C/H, technical documentation, CE marking, declaration of conformity, notified bodies.
10 questions View all questions →Transition period
What applies from when – and how are existing products and distributors affected?
5 questions View all questions → Summarised and translated from the European Commission’s “FAQs on the Cyber Resilience Act” (v1.2, 16 January 2026), licensed under CC BY 4.0. Simplified by Lehner & Szecsey – the original text prevails. Official EU FAQ (original text).