CRAnotify Documentation

Risk-class calculator

Before you configure the flow, the first question is a different one: is my product in scope of the Cyber Resilience Act? And in which class? The calculator answers indicatively in four steps, and shows the minimum obligations and the technical file you will need. It is a free public tool at https://cranotify.eu/en/classe-rischio.

Indicative result, not legal advice. The definitive classification is the manufacturer's responsibility and depends on the product's «core functionality». The calculator does not decide for you and uses no artificial intelligence: it is a deterministic decision tree over a map written and verified against the official sources.

The four steps

1 · ScopeA product with digital elements, placed on the EU market in a commercial activity? It handles the known exclusions (medical devices, aviation, motor vehicles, non-commercial FOSS, pure services, identical spare parts).
2 · NatureWhat kind of product it is: application software, operating system, firmware, connected hardware, microcontroller.
3 · Criticality categoryWhether the product has the core functionality of an «important» or «critical» category in Annex III/IV.
4 · ResultThe indicative class, the minimum obligations, the conformity-assessment route and the suggested technical file (Annex VII).

The classes and what they entail

Out of scopeNo CRA obligations while the condition (an exclusion, or no digital elements) stays true. Keep the rationale on record anyway.
DefaultThe most common category: essential requirements (Annex I), vulnerability handling, Art. 14 reporting, technical documentation, EU declaration of conformity and CE marking. Conformity by self-assessment (internal control).
Important · Class ILike default, applying the relevant harmonised standards under self-assessment, or a type examination.
Important · Class IIA third-party assessment (notified body) is typically required: plan time and budget.
CriticalA European cybersecurity certification (e.g. the EUCC scheme) may be required. This is the most demanding route.

«Core functionality» matters more than the name

An «important» or «critical» category applies by the product's core functionality, not by an ancillary feature. Integrating a component that would itself be an important product (for example an operating system inside a smartphone) does not make the whole product «important»: what counts is the core functionality of the product as a whole. For borderline cases, record the choice and verify it with an expert.

What it is based on

The category → class map is anchored to the primary sources: Commission Implementing Regulation (EU) 2025/2392, which sets out the technical descriptions of the categories of important and critical products, read together with Annex III (class I and II) and Annex IV of Reg. (EU) 2024/2847. The scope logic follows the Commission guidance on the application of the CRA. Every entry in the map cites its reference point.

Getting the summary

From the result you can have the class summary and the obligations checklist emailed to you (optional, with consent). The result stays visible on screen without leaving any data.

The calculator answers «am I in scope of the CRA?». The triage inside the application answers a different, later question: «does this event trigger the Art. 14 reporting obligation?». Two complementary axes.

Didn’t find the answer?

Support replies within one working day. Quote your organisation code and, if the request concerns a case, its number.

Documentation updated on 5 August 2026 · Legal notice · Privacy · support@cranotify.eu