Testing Services
Industry
EU CRAFDA & MDRPayment & FinanceNewsAbout Us
EN繁中
Contact Us
Regulation (EU) 2024/2847 · CE Marking

EU CYBER RESILIENCE ACT

One-stop service from gap analysis and testing to certification, ensuring your products connect seamlessly with global standards.

Applicability check

Four questions to define if you need CRA.

Step 1

Is the product sold commercially in the EU market?

Step 2

Does the product contain “digital elements”?

Step 3

Does the product exchange data with external devices or networks?

Step 4

Does the product fall under an official exclusion?

CRA self-assessment

How ready are you for the CRA? Find out in three minutes.

This CRA self-assessment helps manufacturers quickly evaluate cybersecurity readiness and identify compliance gaps. Please note: results are for initial reference only and do not constitute legal advice.

0 / 52 0 / 26 answered

Status: —

Answer the questions above to see where you stand.

Get a lab readiness assessment →

Indicative only, not legal advice. The binding text is Regulation (EU) 2024/2847.

Next step

Not sure where to start? Join a CRA training session.

Open
In Person

EU CRA Update

September 18, 2026 · 14:00 · Taipei

CRA's reporting obligation is now in effect. Applus+ Laboratories' Cybersecurity Business Unit Director Jose Ruiz Gualda joins Taipei in person to share first-hand European conformity assessment insights alongside SVS. Sept 18, limited seats.

For: decision-makers · export sales leads · compliance officers
More detail →Register →EU CRA seminar poster — 18 September 2026, Taipei
FAQ

Common CRA Questions

Does the CRA apply to products already on the market?

The essential requirements apply to products placed on the EU market from 11 December 2027 onward. However, a substantial modification to an existing product can make it count as newly placed — and the reporting obligations from 11 September 2026 apply to manufacturers regardless of when the product shipped.

Is my product excluded from the CRA?

Only if another EU law already covers the same risk: medical devices (MDR / IVDR), motor vehicles, certified aviation products, marine equipment, and products built solely for national security or defence. Everything else with digital elements is in scope by default.

Do I need a Notified Body?

Most likely not: roughly 90% of products fall into the default class and may self-assess against the essential requirements — especially when applying harmonized standards such as EN 18031. Important Class I (until harmonized standards apply), Class II and critical products are the exceptions. Classification is step one of any CRA engagement.

How does the CRA differ from the Radio Equipment Directive (RED)?

RED applies to specific radio equipment categories and is already in force; the CRA covers all products with digital elements — a much broader scope. If you've already gone through RED cybersecurity conformity, that evidence isn't wasted — it's the foundation your CRA technical file builds on.

What does the CRA require regarding SBOM — and does that include open-source components?

Your SBOM must be machine-readable — SPDX or CycloneDX, not a hand-compiled document. That format matches the EUVD's API, so you can cross-reference your components against EU Vulnerability Database entries and flag actively exploited ones. Open source supplied outside a commercial activity is exempt; once it ships inside your commercial product, it belongs in your SBOM and your vulnerability handling.