CRA knowledge base
Interplay with other EU law
Relationship to machinery, medical, radio, product-safety, GDPR and data law.
All questions in this topic
Are products under the EASA aviation Regulation (EU) 2018/1139 also covered by the CRA?
No, where the EASA Basic Regulation applies: aeronautical products and equipment (incl. software) fall under their own regime and are exempt from the CRA accordingly.
Source: European Commission · FAQ 2.1 Official EU FAQ (original text)
Are products under the Marine Equipment Directive (EU) 2014/90 also covered by the CRA?
Both govern making products available on the market – the Directive specifically for marine equipment. Which act applies depends on the product; double regulation is to be avoided.
Source: European Commission · FAQ 2.2 Official EU FAQ (original text)
What is the interplay between the CRA and the Product Liability Directive?
They complement each other without overlap: the CRA sets product security requirements, while the Product Liability Directive governs compensation for damage caused by defective products.
Source: European Commission · FAQ 2.3 Official EU FAQ (original text)
What is the interplay between the CRA and the Machinery Regulation?
A product can be both machinery and a product with digital elements. In that case the cybersecurity requirements of both acts must be met.
Source: European Commission · FAQ 2.4 Official EU FAQ (original text)
Must a product comply with both CRA and Machinery Regulation cybersecurity requirements?
Yes. If it is both machinery and a product with digital elements, the cybersecurity requirements of both regulations apply cumulatively.
Source: European Commission · FAQ 2.4.2 Official EU FAQ (original text)
Must conformity be assessed via both the CRA and the Machinery Regulation procedures?
Both provide conformity assessment procedures. A product falling under both must go through the relevant procedures of each; some steps can be combined.
Source: European Commission · FAQ 2.4.3 Official EU FAQ (original text)
What is the interplay between the CRA and the General Product Safety Regulation?
Both govern making products available but have different focuses. The CRA covers cybersecurity; the GPSR addresses other safety risks.
Source: European Commission · FAQ 2.5 Official EU FAQ (original text)
Does a product need to comply with both the CRA and the GPSR?
Possibly: if a product poses safety risks beyond cybersecurity (CRA), those other risks may additionally be governed by the GPSR or other EU law.
Source: European Commission · FAQ 2.5.2 Official EU FAQ (original text)
What is the interplay between the CRA and the Radio Equipment Directive?
The CRA takes over the cybersecurity requirements previously applied via the RED Delegated Regulation (EU) 2022/30 and supersedes them for the radio equipment concerned.
Source: European Commission · FAQ 2.6 Official EU FAQ (original text)
What is the interplay between the CRA and the European Health Data Space Regulation?
Both set requirements for placing products on the market. The CRA provides the baseline cybersecurity requirements; the EHDS Regulation adds specific requirements for EHR systems.
Source: European Commission · FAQ 2.7 Official EU FAQ (original text)
Must a product comply with both the CRA and the EHDS Regulation?
Yes. If a product is both a product with digital elements (CRA) and an EHR system (EHDS), the requirements of both acts apply.
Source: European Commission · FAQ 2.7.2 Official EU FAQ (original text)
Must conformity be assessed via both the CRA and the EHDS procedures?
Both provide conformity assessments – the CRA for products with digital elements, the EHDS Regulation for the harmonised software components of EHR systems.
Source: European Commission · FAQ 2.7.3 Official EU FAQ (original text)
Must the manufacturer draw up separate EU declarations of conformity per legal act?
No. Under Art. 39(2) EHDS Regulation a single EU declaration of conformity covering all applicable acts (incl. the CRA) is sufficient.
Source: European Commission · FAQ 2.7.4 Official EU FAQ (original text)
What is the interplay between the CRA and the GDPR?
Different in nature, no legal overlap: the CRA obliges economic operators on product cybersecurity, the GDPR governs the processing of personal data. Secure products do, however, support data protection.
Source: European Commission · FAQ 2.8 Official EU FAQ (original text)
What is the interplay between the CRA and the Data Act?
Different in nature: the CRA governs the secure making available of products, the Data Act governs (among other things) access to product and related-service data.
Source: European Commission · FAQ 2.9 Official EU FAQ (original text)
How do CRA requirements take account of the Data Act’s data-access obligations?
Cybersecurity (CRA) and data access (Data Act) are to be implemented together: make data available while preserving the CRA’s security requirements – the two are compatible.
Source: European Commission · FAQ 2.9.2 Official EU FAQ (original text)
Must manufacturers redesign products to comply with the Data Act and the CRA?
The Data Act imposes no strict redesign obligation. Manufacturers remain free to design products as they see fit, as long as the data-availability obligations are met.
Source: European Commission · FAQ 2.9.3 Official EU FAQ (original text)
Topic blocks
- Scope
- Important & critical products
- Manufacturer obligations
- Reporting obligations
- Conformity assessment & CE
- Transition period