CRA compliance documentation, generated from one product state
The Cyber Resilience Act (EU 2024/2847) requires manufacturers of digital products to keep Annex VII technical documentation, an EU Declaration of Conformity, a risk assessment and an SBOM. This site explains what the requirements mean for each product type and class.
Product types
Smart home gateway / hub
Central hub connecting smart home devices, running firmware and relaying control commands.
IoT sensor
Network-connected sensing device (temperature, motion, air quality) reporting to a gateway or cloud.
Smart wearable
Wearable device (watch, tracker) collecting personal data and syncing to a companion app.
Network router
Home or office router carrying all connected traffic to the internet.
IP camera / video surveillance device
Network camera streaming and storing video, accessible remotely.
Industrial controller / automation device
Programmable controller for industrial automation, running on plant networks.
Importance classes
All other products (default class)
Products with digital elements that do not fall under the important or critical classes. Self-assessment under Module A is the typical route.
Important class I (Annex III)
Important products listed in Annex III, class I: Module A is available ONLY when the manufacturer fully applied harmonised standards / common specifications / an ECS scheme of at least substantial level (Art. 32(2)); otherwise EU-type examination (B+C) or full quality assurance (H).
Important class II (Annex III)
Important products in Annex III class II: third-party conformity assessment (EU-type examination, Module B+C) is generally required, with a notified body.
Critical class (Annex IV)
Critical products in Annex IV (e.g. smart meter gateways, secure elements): the strictest assessment routes with a notified body.
Compliance checklist by email
Get the Annex I checklist for your product type when it is ready.