Risk-class calculator
Before you configure the flow, the first question is a different one: is my product in scope of the Cyber Resilience Act? And in which class? The calculator answers indicatively in four steps, and shows the minimum obligations and the technical file you will need. It is a free public tool at https://cranotify.eu/en/classe-rischio.
Indicative result, not legal advice. The definitive classification is the manufacturer's responsibility and depends on the product's «core functionality». The calculator does not decide for you and uses no artificial intelligence: it is a deterministic decision tree over a map written and verified against the official sources.
The four steps
The classes and what they entail
«Core functionality» matters more than the name
An «important» or «critical» category applies by the product's core functionality, not by an ancillary feature. Integrating a component that would itself be an important product (for example an operating system inside a smartphone) does not make the whole product «important»: what counts is the core functionality of the product as a whole. For borderline cases, record the choice and verify it with an expert.
What it is based on
The category → class map is anchored to the primary sources: Commission Implementing Regulation (EU) 2025/2392, which sets out the technical descriptions of the categories of important and critical products, read together with Annex III (class I and II) and Annex IV of Reg. (EU) 2024/2847. The scope logic follows the Commission guidance on the application of the CRA. Every entry in the map cites its reference point.
Getting the summary
From the result you can have the class summary and the obligations checklist emailed to you (optional, with consent). The result stays visible on screen without leaving any data.
The calculator answers «am I in scope of the CRA?». The triage inside the application answers a different, later question: «does this event trigger the Art. 14 reporting obligation?». Two complementary axes.