Regulation (EU) 2024/2847 - CRA
7 minutes


Structured Assessment Logic (SAL) – Your Roadmap for Compliance
SAL Type V(b) – Specific Public Interest Framework – NLF-based Comprehensive Non-Safety Public Interest Framework with non-structural (partial) classification logic
Mapping of CRA (EU) 2024/2847
To implement the requirements of CRA (EU) 2024/2847 in a transparent and structured way, the regulatory assessment process can be represented using a Structured Assessment Logic (SAL). This logic ensures that all technical and regulatory requirements are systematically evaluated and that compliance is supported by documented evidence.
The SAL comprises the following steps:
Product qualification – Is the product actually within the scope of the CRA?
Classification and selection of the conformity assessment procedure - B+C, H, European cybersecurity certification schemes
Risk Assessment – Identification of the applicable essential cybersecurity requirements (Annex I, Part I) – Which essential cybersecurity requirements apply to the product?
The assessment of the cybersecurity risks associated with a product is required not only to evaluate and mitigate hazards, but also to identify which of the essential cybersecurity requirements related to the product properties (set out in Part I of Annex I) are relevant for the type of product concerned.
Means of compliance assessment – Standards, specifications and certification schemes – Which standards, specifications or schemes cover the requirements, and where are there gaps?
Design and process capability for vulnerability handling (Annex I, Part II)
Does the product architecture and the manufacturer's processes enable the effective notification, distribution, verification, download and installation of security updates, thereby ensuring that the vulnerability handling obligations can be fulfilled throughout the support period?
Technical documentation – Which records demonstrate compliance?
Information obligations
EU Declaration of Conformity & CE marking – Official confirmation of compliance, ready for the EU market.
Note: SAL is not an end in itself. It provides a repeatable methodology that translates regulatory principles into a clear, structured assessment logic.
This diagram illustrates the SAL workflow visually:
Product qualification
↓
Classification │ Conformity assessment procedure
↓
Risk Assessment – Identification of the applicable essential cybersecurity requirements
↓
Conformity assessment procedure
↓
Means of compliance assessment – Standards, specifications and certification schemes
↓
Design and process capability for vulnerability handling
↓
Technical documentation
↓
Information obligations
↓
CE marking & Declaration of Conformity
Interfaces to Related Legislation
CRA compliance requires consideration of overlaps with adjacent regulatory frameworks, in particular the Machinery Regulation (EU) 2023/1230 and the Radio Equipment Directive 2014/53/EU, including Commission Delegated Regulation (EU) 2022/30.
Relevant interface considerations are addressed in FAQs on the CRA implementation (Sections 2.4 and 2.6).
A coordinated assessment is necessary to avoid regulatory gaps or duplication. The SAL therefore operates as a cross-legislative compliance framework rather than a standalone assessment tool.
Overview: Regulation (EU) 2024/2847
Number: (EU) 2024/2847
Title: Regulation on horizontal cybersecurity requirements for products with digital elements
Publication: OJ L, 2024/2847, 20.11.2024
Purpose: Establishes a framework for the making available on the EU market of products with digital elements to ensure the cybersecurity of such products
Public interest: Cybersecurity
Guidance: Guidelines on CRA (EU) 2024/2847: FAQs on the CRA implementation and Draft Commission guidance on the Cyber Resilience Act
Product qualification
The CRA (EU) 2024/2847 applies to products with digital elements made available on the market, the intended purpose or reasonably foreseeable use of which includes a direct or indirect logical or physical data connection to a device or network.
A product with digital elements is hardware or software placed on the EU market whose intended or reasonably foreseeable use involves a direct or indirect data connection to another device or network.
Note: This overview is limited to physical products (hardware). Although standalone software is also covered by the CRA, it is not addressed in this SAL.
Physical product |
|
↓ |
|
Can the product process,store or transmit digital data? | No → Not a PDE |
|
|
Yes ↓ |
|
Does the intended purpose or reasonably foreseeable use include a direct or indirect logical or physical data connection to another device or network? | No → Not a PDE |
Yes ↓ |
|
Product withDigital Elements(PDE) |
|
Relevant types of connectivity under the CRA:
Type of Connectivity | Description | Example |
Logical Connectivity | Data exchange through software interfaces, protocols, or communication services | REST API, MQTT communication, TCP/IP connection, OPC UA, CAN over IP |
Physical Connectivity | Data exchange through wired, wireless, electrical, optical, or mechanical interfaces | Ethernet, USB, Bluetooth, RS-485, CAN bus, Zigbee |
Indirect Connectivity | Connection to another device or network through an intermediary system | Sensor → Gateway → Internet |
Note: The concept of indirect connectivity is often overlooked in practice. A direct internet connection is not required. Connectivity through an intermediary device (for example a gateway, PLC or industrial controller) may already bring the product within the scope of the CRA.
Typical Physical Products that Qualify as PDEs
Smart home devices
Wi-Fi cameras
Smart thermostats
Smartwatches
Fitness trackers
Routers
Network printers
Industrial control systems, inter alia
PLCs Remote
I/O modules
Industrial gateways
Drives
HMIs
IoT sensors
Connected household appliances
Classification │ Selection of the conformity assessment procedure
For the purpose of conformity assessment, the CRA distinguishes four categories of Products with Digital Elements, each determining the applicable conformity assessment procedure.
Important Products – Class I constitute the only category in which the availability and full application of relevant harmonised standards, common specifications or European cybersecurity certification schemes determines whether the manufacturer may use Module A (Internal Production Control) or must involve a notified body (Modules B+C or H).
Available conformity assessment modules / routes:
Categories of products | Default products | Important Class I | Important Class II | Critical products | |
Product not listed in Annex III or IV | Product listed in Annex III Class I | Product listed in Annex III Class III | Product listed in Annex IV
| ||
| Are relevant harmonised standards, common specifications or European cybersecurity certification schemes covering the essential cybersecurity requirements fully applied?
|
|
| ||
| Yes ↆ | No ↆ |
|
| |
Conformity assessment procedures | A, B+C, H | A, B+C, H | B+C, H | B+C, H, or a European cybersecurity certification scheme pursuant to Art. 32(3) | European cybersecurity certification scheme under Art. 8(1); if the conditions of Art. 8(1) are not met: B+C, H, or a European cybersecurity certification scheme pursuant to Art. 32(3) |
Note: Unlike other product categories, the conformity assessment route for Important Products – Class I depends not only on the product classification but also on the extent to which the applicable essential cybersecurity requirements are covered by harmonised standards, common specifications or European cybersecurity certification schemes.
Risk Assessment – Identification of the applicable essential cybersecurity requirements (Annex I, Part I)
As with other risk-based Union harmonisation legislation based on the New Legislative Framework (NLF), the manufacturer must perform a cybersecurity risk assessment in order to determine which essential cybersecurity requirements set out in Annex I, Part I apply to the product. The risk assessment therefore serves not only to identify and evaluate cybersecurity risks, but also to establish the scope of the applicable essential requirements.
Under the traditional NLF approach, manufacturers generally identify the essential requirements that are applicable to the product on the basis of the risk assessment. Requirements that are clearly irrelevant or incompatible with the nature of the product may simply be disregarded without any specific justification being included in the risk assessment or other technical documentation.
The Cyber Resilience Act adopts a different approach. Pursuant to Article 13(4), where the manufacturer concludes that one or more essential cybersecurity requirements set out in Annex I, Part I are not applicable, the cybersecurity risk assessment must include a clear and documented justification for each such requirement. According to Recital 55, this may be the case where an essential cybersecurity requirement is incompatible with the nature of the product. The FAQs on the CRA implementation (Section 4.1.3) further clarify that a justification may also be provided where no cybersecurity risks exist that require mitigation in relation to the essential cybersecurity requirement concerned.
Consequently, the cybersecurity risk assessment under the CRA performs a dual function:
it identifies and evaluates the cybersecurity risks associated with the product; and
it determines and documents which essential cybersecurity requirements of Annex I, Part I are applicable and, where appropriate, provides a reasoned justification for requirements considered not applicable.
Practical note: Particular attention should be paid to the "catch-all" requirement in Annex I, Part I, point (1). Even where individual essential cybersecurity requirements are considered inapplicable, the general obligation to design, develop and produce products with an appropriate level of cybersecurity remains applicable and must be taken into account throughout the assessment. This overarching function of Annex I, Part I, point (1) is also emphasised in the Draft Commission guidance on the Cyber Resilience Act (paras. 149 et seq.). (149 sq.).
Means of Compliance – Harmonised standards, common specifications and cybersecurity certification schemes
Identify recognised technical means that enable a presumption of conformity and determine where alternative compliance evidence is required.
Technical specifications facilitating compliance
Use provides a presumption of conformity
Developed by recognised European standardisation organisations or established as common specifications via Commission implementing acts
Design and process capability for vulnerability handling (Annex I, Part II)
This step ensures that the product design and the supporting organisational processes enable the manufacturer to fulfil the vulnerability handling obligations during the entire support period as required under Article 13(8) and Annex I, Part II of the Cyber Resilience Act.
The focus is not limited to post-market activities but extends to the design phase, requiring that products with digital elements are developed in a way that allows the effective implementation of vulnerability remediation measures throughout their lifecycle.
Depending on the nature and severity of the risk, vulnerability remediation measures may take different forms, including immediate security patches, advisories providing temporary workarounds to be followed by subsequent software updates, updates to user documentation, or configuration guidance to disable affected features.
Manufacturers should therefore ensure, both at the level of product design and organisational processes, that products with digital elements include technical functionalities enabling the notification, distribution, download, and installation of security updates. In particular, for consumer products, updates should be capable of being deployed automatically, while still allowing users to provide final approval for the download and installation where appropriate.
This design obligation reflects the approach outlined in the FAQs on the CRA implementation (Section 4.3) and Draft Commission guidance on the Cyber Resilience Act (paras. 114 et seq.), which emphasise the need for built-in update mechanisms and appropriate user control, as well as the Draft Commission Guidance on the Cyber Resilience Act, which further elaborates on the technical and organisational expectations for vulnerability handling capabilities throughout the support period.
Technical documentation
The technical documentation shall contain all elements required under Annex VII of the Cyber Resilience Act and serve as the primary evidence of conformity with the applicable requirements.
Information obligations
Manufacturers shall ensure that products with digital elements are accompanied by the information and instructions for use required under Annex II of the Cyber Resilience Act.
CE Marking
Mandatory before placing the product on the EU market
Must be visible, legible, and permanent
Notified Body number required if involved
Conclusion
With SAL, the mapping as a roadmap, and consideration of interfaces to related legislation, it becomes clear how CRA (EU) 2024/2847 is systematically applied. The final workflow logically follows from scope through requirements, standards, and assessment procedures to CE marking – providing a clear orientation for manufacturers, assessors, and all stakeholders seeking regulatory clarity.
You might also be interested in these articles:
© 2026 by Dr. Matthias K Bauer


