| CRA Self-Assessment

Cyber Resilience Act — Regulation (EU) 2024/2847

Does your product fall under the Cyber Resilience Act — and which requirements apply then?

The CRA applies horizontally: it concerns every product with a data connection, whatever the industry. ViaGuardium guides manufacturers of products with digital elements through the self-assessment — scope, product class under Annexes III and IV, a risk class per interface and asset, and the essential requirements of Annex I that are actually relevant. The result is an indication with a chain of reasoning, not a conformity assessment and not legal advice.

Scope

Does the product fall under the CRA?

Product Class

Under Annexes III and IV

Risk Classes 1–5

Per interface and asset

Essential Requirements

From Annex I, with reasoning

Foundations

Reporting obligations under Article 14 apply from 11 September 2026, full application from 11 December 2027. Ask us directly — we review every request personally.

Core

Relevant Requirements Instead of the Whole of Annex I

In practice the third question is usually skipped: the whole of Annex I is worked through because nobody can substantiate why a requirement does not apply. That costs effort where there is no risk — and leaves open where something actually needs doing.

ViaGuardium derives, per interface and per asset, a risk class from 1 to 5 following BSI TR-03183-1, and from that the essential requirements of Annex I with the implementation level expected in each case. Requirements that are not relevant do not disappear from the report — they appear in it with their reasons.

How to read the result. BSI TR-03183-1 is an interpretation aid, not a harmonised standard, and carries no presumption of conformity under Article 27. The guideline itself calls the scoring scheme in its Annex D experimental. The report therefore states its outcome as an indication with a chain of reasoning — not as a finding, and not as a conformity assessment.

Request a Demo

From the Scope Check to the Requirements — In One Application.

Assembling a CRA self-assessment from spreadsheets, regulation texts and guideline PDFs is laborious and hard to audit. ViaGuardium asks everyday questions instead of specialist vocabulary and documents every answer together with the way it was derived — through to a PDF report in which every rating is traced back to the input it came from.

Scope
Articles 2 and 3
Product Class
Annexes III and IV
Interfaces
Exposure per connection
Risk Classes
1 to 5, per asset
PDF Report
Requirements and exclusions

The chain of reasoning runs through the whole report: the scope check names the criterion that tipped the balance, the product class names the core function it follows from, and every requirement names the risk class that made it relevant.

Scope and Product Class — the Two Questions Everything Else Depends On

Each of the two is a precondition for the next. Only once it is clear that the regulation applies does the product class matter — and only once the product class is known is it clear which conformity assessment route is open at all.

The scope check works through six everyday questions: making the product available on the EU market, a data connection to a device or a network, commercial activity, excluded product categories, the cut-off date of 11 December 2027 and whether the product has been substantially modified since. The outcome is one of three statements — the product is likely to fall under the CRA, it is likely not to, or only the reporting obligations apply. The report names the criterion that tipped the balance in each case.

The product class then follows from the core function of the product, as set out in Annexes III and IV: default product, important product of class I or class II, critical product. With it comes the question of which route is open — self-assessment under Module A, the presumption of conformity from a harmonised standard, Module B+C or H involving a notified body, or a European certification scheme such as EUCC.

  • Made available in the EU — placing on the market or making available in the course of a commercial activity
  • Data connection — a direct or indirect logical or physical connection to a device or network
  • Excluded categories — products already covered by other Union law, such as medical devices, cars, ships or civil aviation
  • Cut-off date and substantial modification — a change affecting intended use or conformity brings an existing product back within scope
  • Product class — default, important class I or II under Annex III, or critical under Annex IV

Risk Classification — per Interface and per Asset

Exposure differs considerably from one interface to the next. ViaGuardium therefore records every outward connection separately — explicitly including maintenance and diagnostic access — and combines its exposure with the protection needs of the data behind it. That yields a risk class from 1 (very low) to 5 (very high) for each combination, following BSI TR-03183-1.

Interface restriction — what the interface communicates over: internal to the device, in immediate proximity, a dedicated closed network, a shared home or company network, the internet or a mobile network
Access restriction — how accessible the interface is physically or logically. A service port behind a sealed enclosure is not a web interface on the internet
User capability — what skills an attacker has to bring to reach the interface at all
Protection needs of the assets — personal data, particularly sensitive data, technical identifiers, operational and business data, telemetry, and the product functions themselves
Two routes, disclosed deviations — the assessment is calculated both as a matrix and as a rule set. Where the two disagree, the report says so instead of feigning agreement

What the assessment works through:

Seven stages, each building on the answers of the one before:

Scope

Product Class

Product Profile

Interfaces

Protection Needs

Risk Classes

Essential Requirements

Product Profiles for a Quick Start

  • Device without a connection to an open network · device on a local network without cloud
  • Device with a cloud connection · device with a mobile or direct internet connection
  • Software on third-party hardware · software with its own backend

A Report You Can Put in Front of Someone

Substantiated exclusions instead of silent gaps.

The report is designed for the situation in which someone asks a question about it — a customer, an auditor, a notified body. It therefore documents not only which of the essential requirements of Annex I are relevant, but also which are not, and why.

Annex I Part I and Part II — product properties on the one hand, vulnerability handling and SBOM on the other, each with the implementation level expected and the associated measure
Substantiated exclusions — a requirement that is simply missing from a report is not excluded with reasons, it is unanswered
Disclosed gaps — where BSI TR-03183-1 does not cover a clause of Annex I, the report says so and names the regulation directly as the source
Methodology in the report — how the calculation was done, which acceptance criteria apply and how deviations between the two routes are handled
PDF export — versioned and with a reference date, usable as a basis for the technical documentation under Annex VII

A basis for the technical documentation is not the technical documentation. The report supports what Article 31 requires of you; it does not produce it, and it does not run the procedure under Article 32 on your behalf.

What ViaGuardium Does Differently

Compliance tools tend to hand over a checklist covering the whole of Annex I and leave the reasoning to you. ViaGuardium deliberately takes a different approach.

Generic Compliance Checklists

  • The whole of Annex I is worked through, regardless of the product
  • No traceable link between an answer and the requirement it triggers
  • Requirements that do not apply simply go missing instead of being excluded with reasons
  • No differentiation per interface — a service port is treated like a public web interface
  • The result is a document that has to be taken on trust

ViaGuardium

  • Traceable rather than merely plausible: every rating is traced back to the input it came from
  • Substantiated exclusions: requirements that are not relevant appear in the report with their reasons
  • Per interface and asset: risk classes 1 to 5 following BSI TR-03183-1, instead of one blanket rating
  • Disclosed deviations: matrix and rule set are both calculated, and differences are shown rather than smoothed over
  • Honest about its own limits: an indication with a chain of reasoning, stated as such
Living document: BSI TR-03183-1 continues to be revised. With the update subscription an existing assessment is recalculated monthly against the current version of the catalogue and configuration.

You remain the manufacturer — we supply the basis

The self-assessment establishes whether the Cyber Resilience Act applies to your product and which requirements follow from that. The obligations under the regulation stay with you — and that is exactly what makes it worth stating clearly where the software stops.

No conformity assessment

The conformity assessment, the EU declaration of conformity and the CE marking are the responsibility of the manufacturer. Where the regulation requires a notified body for important or critical products, that body remains necessary. The self-assessment is the starting point of that route, not a substitute for it.

No presumption of conformity

The requirements are derived via BSI TR-03183-1. That guideline is an interpretation aid, not a harmonised standard, and therefore carries no presumption of conformity under Article 27. Its Annex D — the source of the scoring scheme and the risk matrix — describes its own approach as highly experimental. The report says so rather than hiding it.

1

Traceable, not just plausible

A checklist is checked for plausibility; a derivation is retraced. ViaGuardium keeps every rating attached to the question it came from, names the risk class that made a requirement relevant, and states the calculation method in the report. That is what makes an assessment reviewable instead of something to be taken on trust.

2

No legal advice

The report states what the information entered suggests and discloses which criterion tipped the balance. It does not replace a legal assessment of the individual case, nor the technical documentation under Article 31, nor the conformity assessment procedure under Article 32.

3

Open about what is still unfinished

Where BSI TR-03183-1 does not cover a clause of Annex I, the report says so and names the regulation directly as the source. Where the two calculation routes disagree, both results are shown. An assessment that conceals its gaps is harder to use, not easier.

Software-as-a-Service: Always Up to Date

BSI TR-03183-1 is explicitly a living document, and the regulation is accompanied by guidance and harmonised standards still being developed. Updates to the catalogue and the configuration are applied centrally.

Regulation (EU) 2024/2847

Annex I (essential requirements), Annexes III and IV (product classes), Annex VII (technical documentation)

BSI TR-03183-1 and -2

Cyber resilience requirements for manufacturers and products, plus the SBOM part — as an interpretation aid, without presumption of conformity

GDPR Compliant

German servers, encrypted transmission, access control

Audit Trail

Versioning, reference date and full traceability of every assessment

Who Is ViaGuardium For?

Above all for small and medium-sized manufacturers without a security department of their own

Manufacturers of Products with Digital Elements

Clarify the scope, determine the product class and narrow the implementation effort down to the requirements that are actually relevant

Development and Product Ownership

Anyone building the technical documentation under Annex VII needs a defensible risk assessment and a substantiated selection of requirements first

Importers and Distributors

Anyone making third-country products available in the EU has to be able to judge whether the manufacturer's conformity claims are plausible

Consultancy and Assessment

A traceable starting document in which every rating stays attached to the input it came from

How It Works

Five steps to a documented CRA self-assessment

1

Clarify the Scope

Six questions on making available in the EU, data connection, exclusions and the cut-off date — including whether the product has been substantially modified since

2

State the Core Function

The product class under Annexes III and IV follows from it — and with it the conformity assessment routes that are open

3

Record the Product Profile and the Interfaces

Intended purpose, foreseeable misuse, hardware and software revision, support period — and every outward connection separately, explicitly including maintenance access

4

Answer the Protection Needs

Which data the product processes, asked in everyday terms. Exposure and protection needs together yield a risk class from 1 to 5 per interface and asset

5

Review, Release and Generate the PDF Report

Relevant requirements with implementation level, substantiated exclusions and the calculation method — with every rating traced back to its input

Request Access

A CRA assessment shows where a product is open to attack — which is why we do not create accounts automatically. We review every request personally and get back to you. No obligations and no hidden costs.

Why there is no instant access

A CRA assessment sets out in black and white where a product is open to attack and which requirements are still outstanding. That is not something that should be handed out to anyone through an automated self-service form. So nobody is granted access at the click of a button — we look at your request and reply personally.

  1. Fill in the form — who you are and which product this is about. About two minutes.
  2. We review it manually — and get back to you, with questions about your use case if needed.
  3. Access and terms — you receive your credentials and a matching offer.
Helps us assess your case — optional
A single product is already enough for a meaningful report — a rough estimate is fine.
Optional

Already a customer? Login here

Frequently Asked Questions

What does ViaGuardium actually do?
ViaGuardium guides you through a self-assessment under the Cyber Resilience Act. It works through four questions in order: does the product fall within the scope of Regulation (EU) 2024/2847, which product class does it belong to under Annexes III and IV, which conformity assessment route is open to it, and which essential requirements of Annex I are relevant at which depth.

The requirements are derived via BSI TR-03183-1, which determines a risk class from 1 to 5 per interface and asset. The result is a PDF report in which every rating is traced back to the input it came from. A conformity assessment is deliberately not part of it.
Does ViaGuardium replace the conformity assessment?
No. The conformity assessment, the EU declaration of conformity and the CE marking remain the responsibility of the manufacturer. For important and critical products a notified body may additionally be required.

The self-assessment is the starting point of that route, not a substitute for it. It replaces neither the technical documentation under Article 31 nor the procedure under Article 32.
Is the report legal advice?
No. The report states what the information entered suggests and discloses which criterion tipped the balance. It does not replace a legal assessment of the individual case.
Where do the requirements come from?
From Annex I to Regulation (EU) 2024/2847, spelled out following BSI TR-03183-1. Where the guideline does not cover a clause of Annex I, the report says so and names the regulation directly as the source.

BSI TR-03183-1 is an interpretation aid, not a harmonised standard, and therefore carries no presumption of conformity under Article 27. Its Annex D describes its own scoring scheme as highly experimental — which is why the report states its outcome as an indication rather than a finding.
Why does the report also state what does not apply?
Because substantiating the exclusions is required in review just as much as meeting the remaining requirements. A requirement that is simply missing from a report is not excluded with reasons — it is unanswered. ViaGuardium therefore lists the requirements that are not relevant together with the reason why.
Which product classes does the CRA distinguish?
Default products, important products of class I and class II under Annex III, and critical products under Annex IV. The classification follows the core function of the product.

It determines which conformity assessment route is open: self-assessment under Module A, the presumption of conformity from a harmonised standard, Module B+C or Module H involving a notified body, or a European cybersecurity certification scheme such as EUCC.
Why is every interface recorded individually?
Because exposure differs considerably from one interface to the next. A service port that can only be reached after opening the enclosure carries a different risk from a web interface exposed to the internet. Without that separation the assessment comes out either too strict or too generous.

ViaGuardium therefore records every outward connection separately — explicitly including maintenance and diagnostic access.
What does the support period mean?
The period during which the manufacturer has to handle vulnerabilities effectively and provide security updates. It follows the expected lifetime of the product and is generally at least five years. It has to be stated to users.
What counts as a substantial modification?
A change that affects the intended use or the conformity with the essential requirements. It is the reason why a product placed on the market before the cut-off date can still come within scope. A pure security update is not a substantial modification.
Does the CRA also apply to software on its own?
Yes. Products with digital elements cover software as well as hardware, including the associated remote data processing solutions.
What happens when BSI TR-03183-1 changes?
The guideline is explicitly a living document and continues to be revised. With the update subscription an existing assessment is recalculated monthly against the current version of the catalogue and configuration — so you can see where a revision changes the picture for your product, and where it does not.
Which deadlines apply under the Cyber Resilience Act?
The reporting obligations under Article 14 apply from 11 September 2026, and the regulation applies in full from 11 December 2027.

Products placed on the market before that date can still come within scope if they are substantially modified afterwards.
How do I get access to the software?
Through a request via the contact form above. There is deliberately no automated instant access: a CRA assessment shows where a product is open to attack and which requirements are still outstanding, so we review every request personally, agree the scope with you and create the account afterwards.

Reporting obligations from 11 September 2026, full application from 11 December 2027.

Establish now whether and how the Cyber Resilience Act affects your product — with an assessment that states where every rating comes from.