1. What does your company actually make?
Software customers install, download, or self-hostDesktop app, on-prem/self-hosted platform, mobile app, developer SDK/library, firmware
A physical device with embedded softwareIoT device, industrial equipment, wearable, connected appliance
A cloud service accessed only through a browserNo installable app, not tied to any physical device we or a partner makes
None of the abovePure hardware with no software at all, or a non-digital product
1b. Is your cloud service required for a physical connected product to work?
YesE.g. we (or a partner) make a connected device, and our cloud backend is necessary for it to function
NoOur service stands alone — nothing physical depends on it
2. Does this product reach customers in the EU?
YesSold directly to EU customers, through a distributor, an app store, or bundled into someone else's EU-sold product — regardless of where your company is registered
NoStrictly non-EU sales only, for now
3. Who actually develops it and whose name is on it?
We develop it (or have it developed) and sell it under our own name/brandThis makes you the "manufacturer" under the Act — full obligations, including reporting
We only resell someone else's finished product, unmodified, under their original brandingYou're a "distributor" — the primary reporting duty sits with the original manufacturer, but you must still verify they're compliant before selling it
4. Is your product already regulated by one of these sector-specific EU rules?
YesMedical devices (MDR/IVDR), in-vehicle automotive systems under type-approval, civil aviation equipment, or marine equipment cybersecurity rules
No, none of these apply to us
5. Is this free/open-source software with no commercial activity behind it?
Yes — purely non-commercialVolunteer/community-maintained, not monetized, no company selling support around it
No — it's a commercial productSold, monetized, or developed as part of a business, even if source-available
In scope

Yes — the CRA applies to you.

Based on your answers, you're a manufacturer of a product with digital elements placing it on the EU market — which means Article 14 vulnerability and incident reporting obligations apply to you from 11 September 2026.

The reporting deadlines are the same for every company, regardless of size — a common misconception is that small companies get 72 hours and large companies get 24 hours. That's not how it works. Every manufacturer follows the same cascade:

24h
Early warning to ENISA once you learn of an actively exploited vulnerability
72h
Fuller notification with more detail
14 days
Final report after a fix becomes available

What company size does change: microenterprises get simplified technical documentation requirements, and the conformity assessment route depends on your product's risk class (default/important/critical) — not on your headcount.

Book a call with CRA Alert
← Start over
Likely out of scope

Based on your answers, the CRA probably doesn't apply — yet.

Worth re-checking this if anything changes: you start selling into the EU, you add an installable component, or the product's role changes.

← Start over
Partial obligations

You have some duties, but not the full reporting obligation.

As a distributor reselling someone else's unmodified, already-branded product, the primary Article 14 reporting duty sits with the original manufacturer — not you. But you're still required to verify the manufacturer has met their CRA obligations before making the product available, and to act if you become aware it doesn't comply.

← Start over