C84.io
CRA Scope Assessment

Does the Cyber Resilience Act Apply to Your Product?

A targeted assessment that determines whether your products fall under the CRA — and exactly what obligations that triggers.

Assess Your CRA Scope

The CRA Changes the Rules for Every Digital Product.

The EU Cyber Resilience Act introduces mandatory cybersecurity requirements for all products with digital elements — from firmware to SaaS, from IoT devices to developer libraries.

The first question every product team needs to answer: are we in scope? And if so, under which category — default, Class I, or Class II? The answer determines your obligations for vulnerability handling, documentation, incident reporting, and CE marking.

Our CRA Scope Assessment gives you a definitive answer — not an opinion — backed by article-level analysis of the regulation.

What You Get

A clear determination of your CRA obligations, specific to your product portfolio.

Product Classification

Each product mapped to its CRA category — default, Class I, or Class II — with the regulatory rationale documented.

Obligation Matrix

A product-by-product breakdown of required security properties, documentation, and conformity assessment paths.

Vulnerability Handling Gap Review

Assessment of your current vulnerability disclosure and patch management processes against CRA Article 11 requirements.

Timeline & Action Plan

A phased roadmap aligned to CRA transition periods, so your team knows what to deliver and when.

How It Works

Focused on your product portfolio. No generic checklists.

  1. 1

    Product Inventory

    We catalog your products with digital elements — hardware, software, firmware, SaaS — and their intended use cases.

  2. 2

    Regulatory Mapping

    Each product is analyzed against CRA annexes and classification criteria to determine its category and obligations.

  3. 3

    Gap Identification

    We compare your current development, documentation, and vulnerability handling processes to CRA requirements.

  4. 4

    Report & Roadmap

    You receive the Classification Report, Obligation Matrix, and a phased Action Plan — with a live briefing for your product and engineering leads.

Who This Is For

  • Product managers and CTOs building connected or software-defined products
  • IoT and embedded device manufacturers entering or selling in the EU
  • SaaS companies unsure whether their platform qualifies as a "product with digital elements"
  • Open-source maintainers evaluating their obligations under CRA exemptions
  • Legal and compliance teams preparing for CE marking and conformity assessments

Clarify Your CRA Obligations

Don't wait for enforcement to find out if your products are in scope. Get clarity now.

Assess Your CRA Scope