CRA Doc - Cyber Resilience Act documentation Home

CRA compliance documentation, generated from one product state

The Cyber Resilience Act (EU 2024/2847) requires manufacturers of digital products to keep Annex VII technical documentation, an EU Declaration of Conformity, a risk assessment and an SBOM. This site explains what the requirements mean for each product type and class.

Product types

Smart home gateway / hub

Central hub connecting smart home devices, running firmware and relaying control commands.

IoT sensor

Network-connected sensing device (temperature, motion, air quality) reporting to a gateway or cloud.

Smart wearable

Wearable device (watch, tracker) collecting personal data and syncing to a companion app.

Network router

Home or office router carrying all connected traffic to the internet.

IP camera / video surveillance device

Network camera streaming and storing video, accessible remotely.

Industrial controller / automation device

Programmable controller for industrial automation, running on plant networks.

Importance classes

All other products (default class)

Products with digital elements that do not fall under the important or critical classes. Self-assessment under Module A is the typical route.

Important class I (Annex III)

Important products listed in Annex III, class I: Module A is available ONLY when the manufacturer fully applied harmonised standards / common specifications / an ECS scheme of at least substantial level (Art. 32(2)); otherwise EU-type examination (B+C) or full quality assurance (H).

Important class II (Annex III)

Important products in Annex III class II: third-party conformity assessment (EU-type examination, Module B+C) is generally required, with a notified body.

Critical class (Annex IV)

Critical products in Annex IV (e.g. smart meter gateways, secure elements): the strictest assessment routes with a notified body.

Compliance checklist by email

Get the Annex I checklist for your product type when it is ready.