Cyber Resilience Act decision examples
CRA scope and roles
Draw the product boundary, check commercial supply and identify who is responsible. Compare worked examples and the evidence behind each CRA assessment.
Does the CRA apply to this offering?
Open a situation to compare the relevant facts, worked results and evidence to retain.
Does the CRA cover a cloud service used by a connected device?
The relationship to the product matters. A remote service needed for a product’s function needs a different assessment from a standalone browser application.
View facts and examplesWhen does commercial open-source software enter CRA scope?
An open-source licence alone does not decide scope. Document commercial activity, product responsibility and any distinct open-source-steward role.
View facts and examplesDoes an identical replacement component need a CRA scope assessment?
The identical-spare-part boundary depends on the replacement and the original having the same specifications. A redesigned component needs its own assessment.
View facts and examplesIs an open-source contributor the CRA manufacturer?
Contribution to a project and responsibility for supplying a finished product are different roles. Record which activity the organisation actually performs.
View facts and examplesHow to use these examples
The situations are hypothetical and use explicitly recorded assumptions. They explain a decision path, not a conclusion about your own product. Reporting obligations for manufacturers apply from 11 September 2026; broader product requirements apply from 11 December 2027.
Product-readiness examples support preparation for those broader requirements. A readiness result does not declare conformity. Primary sources and the assessment version are provided on each situation page.