Cyber Resilience Act decision examples
CRA checks for real product decisions
Explore Cyber Resilience Act scope, classification, support, product changes and reporting with worked examples and evidence checklists.
Start with the decision in front of you
Explore product scope, conformity preparation and reporting through specific situations. Each example shows its assumptions and the result of the published assessment.
Scope and roles
Draw the product boundary, check commercial supply and identify who is responsible.
4 worked situationsClassification
Connect the product’s core function to its class and conformity-assessment route.
4 worked situationsEssential requirements
Find gaps in product-security controls and the evidence needed for review.
2 worked situationsImporters and distributors
Check the product, its documentation and the escalation path before supply.
2 worked situationsSupport and maintenance
Record expected use, dependency support and ongoing vulnerability handling.
3 worked situationsProduct modifications
Review changes to intended purpose, cybersecurity and manufacturer responsibilities.
4 worked situationsExploited vulnerabilities
Separate a known weakness from active exploitation and prepare the reporting sequence.
3 worked situationsSevere incidents
Assess security impact and preserve the evidence for each notification stage.
2 worked situationsHow to use these examples
The situations are hypothetical and use explicitly recorded assumptions. They explain a decision path, not a conclusion about your own product. Reporting obligations for manufacturers apply from 11 September 2026; broader product requirements apply from 11 December 2027.
Product-readiness examples support preparation for those broader requirements. A readiness result does not declare conformity. Primary sources and the assessment version are provided on each situation page.