Does the CRA apply to you?

Ten questions you can answer without looking anything up. You'll see whether the Cyber Resilience Act plausibly reaches your products and why — each answer tied to the article it rests on (CRA Article 2 (opens the primary source in a new tab), CRA Article 3 (opens the primary source in a new tab)) — so the conversation you have with counsel is an hour, not a discovery project.

A structured self-assessment, not legal advice. Computed on this page — your answers are never sent or stored, and there is no email gate.

Your product

Do organisations or people in the EU use software you make?
How does your software reach them?

Tick everything that applies — most companies are more than one.

Do you charge for it, directly or indirectly?

Timing and category

Will any version of this product still be on the EU market after 11 September 2026?
Which best describes your product?

Your Article 14 posture

These four don’t change the scope verdict — they tell you what it means for you.

If a package you depend on were compromised tonight, how would you find out?
If a regulator asked when you first became aware of an exploited vulnerability, could you prove the date?
How often do you actually update dependencies?
Who in your organisation would own a 24-hour ENISA deadline?

Computed on this page. Your answers are not sent or stored.