Cyber Resilience Act — Regulation (EU) 2024/2847
Does your product fall under the Cyber Resilience Act — and which requirements apply then?
The CRA applies horizontally: it concerns every product with a data connection, whatever the industry. ViaGuardium guides manufacturers of products with digital elements through the self-assessment — scope, product class under Annexes III and IV, a risk class per interface and asset, and the essential requirements of Annex I that are actually relevant. The result is an indication with a chain of reasoning, not a conformity assessment and not legal advice.
Scope
Does the product fall under the CRA?
Product Class
Under Annexes III and IV
Risk Classes 1–5
Per interface and asset
Essential Requirements
From Annex I, with reasoning
Foundations
Reporting obligations under Article 14 apply from 11 September 2026, full application from 11 December 2027. Ask us directly — we review every request personally.
Relevant Requirements Instead of the Whole of Annex I
In practice the third question is usually skipped: the whole of Annex I is worked through because nobody can substantiate why a requirement does not apply. That costs effort where there is no risk — and leaves open where something actually needs doing.
ViaGuardium derives, per interface and per asset, a risk class from 1 to 5 following BSI TR-03183-1, and from that the essential requirements of Annex I with the implementation level expected in each case. Requirements that are not relevant do not disappear from the report — they appear in it with their reasons.
How to read the result. BSI TR-03183-1 is an interpretation aid, not a harmonised standard, and carries no presumption of conformity under Article 27. The guideline itself calls the scoring scheme in its Annex D experimental. The report therefore states its outcome as an indication with a chain of reasoning — not as a finding, and not as a conformity assessment.
Request a DemoFrom the Scope Check to the Requirements — In One Application.
Assembling a CRA self-assessment from spreadsheets, regulation texts and guideline PDFs is laborious and hard to audit. ViaGuardium asks everyday questions instead of specialist vocabulary and documents every answer together with the way it was derived — through to a PDF report in which every rating is traced back to the input it came from.
The chain of reasoning runs through the whole report: the scope check names the criterion that tipped the balance, the product class names the core function it follows from, and every requirement names the risk class that made it relevant.
Scope and Product Class — the Two Questions Everything Else Depends On
Each of the two is a precondition for the next. Only once it is clear that the regulation applies does the product class matter — and only once the product class is known is it clear which conformity assessment route is open at all.
The scope check works through six everyday questions: making the product available on the EU market, a data connection to a device or a network, commercial activity, excluded product categories, the cut-off date of 11 December 2027 and whether the product has been substantially modified since. The outcome is one of three statements — the product is likely to fall under the CRA, it is likely not to, or only the reporting obligations apply. The report names the criterion that tipped the balance in each case.
The product class then follows from the core function of the product, as set out in Annexes III and IV: default product, important product of class I or class II, critical product. With it comes the question of which route is open — self-assessment under Module A, the presumption of conformity from a harmonised standard, Module B+C or H involving a notified body, or a European certification scheme such as EUCC.
- Made available in the EU — placing on the market or making available in the course of a commercial activity
- Data connection — a direct or indirect logical or physical connection to a device or network
- Excluded categories — products already covered by other Union law, such as medical devices, cars, ships or civil aviation
- Cut-off date and substantial modification — a change affecting intended use or conformity brings an existing product back within scope
- Product class — default, important class I or II under Annex III, or critical under Annex IV
Risk Classification — per Interface and per Asset
Exposure differs considerably from one interface to the next. ViaGuardium therefore records every outward connection separately — explicitly including maintenance and diagnostic access — and combines its exposure with the protection needs of the data behind it. That yields a risk class from 1 (very low) to 5 (very high) for each combination, following BSI TR-03183-1.
What the assessment works through:
Seven stages, each building on the answers of the one before:
Scope
Product Class
Product Profile
Interfaces
Protection Needs
Risk Classes
Essential Requirements
Product Profiles for a Quick Start
- Device without a connection to an open network · device on a local network without cloud
- Device with a cloud connection · device with a mobile or direct internet connection
- Software on third-party hardware · software with its own backend
A Report You Can Put in Front of Someone
Substantiated exclusions instead of silent gaps.
The report is designed for the situation in which someone asks a question about it — a customer, an auditor, a notified body. It therefore documents not only which of the essential requirements of Annex I are relevant, but also which are not, and why.
A basis for the technical documentation is not the technical documentation. The report supports what Article 31 requires of you; it does not produce it, and it does not run the procedure under Article 32 on your behalf.
What ViaGuardium Does Differently
Compliance tools tend to hand over a checklist covering the whole of Annex I and leave the reasoning to you. ViaGuardium deliberately takes a different approach.
Generic Compliance Checklists
- The whole of Annex I is worked through, regardless of the product
- No traceable link between an answer and the requirement it triggers
- Requirements that do not apply simply go missing instead of being excluded with reasons
- No differentiation per interface — a service port is treated like a public web interface
- The result is a document that has to be taken on trust
ViaGuardium
- Traceable rather than merely plausible: every rating is traced back to the input it came from
- Substantiated exclusions: requirements that are not relevant appear in the report with their reasons
- Per interface and asset: risk classes 1 to 5 following BSI TR-03183-1, instead of one blanket rating
- Disclosed deviations: matrix and rule set are both calculated, and differences are shown rather than smoothed over
- Honest about its own limits: an indication with a chain of reasoning, stated as such
You remain the manufacturer — we supply the basis
The self-assessment establishes whether the Cyber Resilience Act applies to your product and which requirements follow from that. The obligations under the regulation stay with you — and that is exactly what makes it worth stating clearly where the software stops.
No conformity assessment
The conformity assessment, the EU declaration of conformity and the CE marking are the responsibility of the manufacturer. Where the regulation requires a notified body for important or critical products, that body remains necessary. The self-assessment is the starting point of that route, not a substitute for it.
No presumption of conformity
The requirements are derived via BSI TR-03183-1. That guideline is an interpretation aid, not a harmonised standard, and therefore carries no presumption of conformity under Article 27. Its Annex D — the source of the scoring scheme and the risk matrix — describes its own approach as highly experimental. The report says so rather than hiding it.
Traceable, not just plausible
A checklist is checked for plausibility; a derivation is retraced. ViaGuardium keeps every rating attached to the question it came from, names the risk class that made a requirement relevant, and states the calculation method in the report. That is what makes an assessment reviewable instead of something to be taken on trust.
No legal advice
The report states what the information entered suggests and discloses which criterion tipped the balance. It does not replace a legal assessment of the individual case, nor the technical documentation under Article 31, nor the conformity assessment procedure under Article 32.
Open about what is still unfinished
Where BSI TR-03183-1 does not cover a clause of Annex I, the report says so and names the regulation directly as the source. Where the two calculation routes disagree, both results are shown. An assessment that conceals its gaps is harder to use, not easier.
Software-as-a-Service: Always Up to Date
BSI TR-03183-1 is explicitly a living document, and the regulation is accompanied by guidance and harmonised standards still being developed. Updates to the catalogue and the configuration are applied centrally.
Regulation (EU) 2024/2847
Annex I (essential requirements), Annexes III and IV (product classes), Annex VII (technical documentation)
BSI TR-03183-1 and -2
Cyber resilience requirements for manufacturers and products, plus the SBOM part — as an interpretation aid, without presumption of conformity
GDPR Compliant
German servers, encrypted transmission, access control
Audit Trail
Versioning, reference date and full traceability of every assessment
Who Is ViaGuardium For?
Above all for small and medium-sized manufacturers without a security department of their own
Manufacturers of Products with Digital Elements
Clarify the scope, determine the product class and narrow the implementation effort down to the requirements that are actually relevant
Development and Product Ownership
Anyone building the technical documentation under Annex VII needs a defensible risk assessment and a substantiated selection of requirements first
Importers and Distributors
Anyone making third-country products available in the EU has to be able to judge whether the manufacturer's conformity claims are plausible
Consultancy and Assessment
A traceable starting document in which every rating stays attached to the input it came from
How It Works
Five steps to a documented CRA self-assessment
Clarify the Scope
Six questions on making available in the EU, data connection, exclusions and the cut-off date — including whether the product has been substantially modified since
State the Core Function
The product class under Annexes III and IV follows from it — and with it the conformity assessment routes that are open
Record the Product Profile and the Interfaces
Intended purpose, foreseeable misuse, hardware and software revision, support period — and every outward connection separately, explicitly including maintenance access
Answer the Protection Needs
Which data the product processes, asked in everyday terms. Exposure and protection needs together yield a risk class from 1 to 5 per interface and asset
Review, Release and Generate the PDF Report
Relevant requirements with implementation level, substantiated exclusions and the calculation method — with every rating traced back to its input
Request Access
A CRA assessment shows where a product is open to attack — which is why we do not create accounts automatically. We review every request personally and get back to you. No obligations and no hidden costs.
Why there is no instant access
A CRA assessment sets out in black and white where a product is open to attack and which requirements are still outstanding. That is not something that should be handed out to anyone through an automated self-service form. So nobody is granted access at the click of a button — we look at your request and reply personally.
- Fill in the form — who you are and which product this is about. About two minutes.
- We review it manually — and get back to you, with questions about your use case if needed.
- Access and terms — you receive your credentials and a matching offer.
Already a customer? Login here
Frequently Asked Questions
The requirements are derived via BSI TR-03183-1, which determines a risk class from 1 to 5 per interface and asset. The result is a PDF report in which every rating is traced back to the input it came from. A conformity assessment is deliberately not part of it.
The self-assessment is the starting point of that route, not a substitute for it. It replaces neither the technical documentation under Article 31 nor the procedure under Article 32.
BSI TR-03183-1 is an interpretation aid, not a harmonised standard, and therefore carries no presumption of conformity under Article 27. Its Annex D describes its own scoring scheme as highly experimental — which is why the report states its outcome as an indication rather than a finding.
It determines which conformity assessment route is open: self-assessment under Module A, the presumption of conformity from a harmonised standard, Module B+C or Module H involving a notified body, or a European cybersecurity certification scheme such as EUCC.
ViaGuardium therefore records every outward connection separately — explicitly including maintenance and diagnostic access.
Products placed on the market before that date can still come within scope if they are substantially modified afterwards.
Reporting obligations from 11 September 2026, full application from 11 December 2027.
Establish now whether and how the Cyber Resilience Act affects your product — with an assessment that states where every rating comes from.