For a connected consumer product, determine CRA applicability first and then identify which consumer-safety risks remain within the GPSR framework. Do not duplicate a risk already fully governed by specific Union harmonisation legislation, but do not assume the GPSR disappears entirely merely because the product is CE marked under another act. Cybersecurity evidence can support safety analysis where hacking, interconnection or software changes create health or safety consequences.
The GPSR Is the EU Consumer-Product Safety Net
Regulation (EU) 2023/988 requires economic operators to place or make available only safe consumer products. Article 2 states that the GPSR applies where there are no specific Union provisions with the same objective, and for products already subject to specific safety requirements it applies only to aspects or risk categories not covered by those rules.
The GPSR Has Applied Since 13 December 2024
The GPSR became applicable on 13 December 2024. It therefore already governs relevant consumer-product safety obligations while the CRA's main product requirements continue toward their 11 December 2027 application date and CRA Article 14 reporting obligations have applied since 11 September 2026.
Cybersecurity Can Be Part of the GPSR Safety Assessment
GPSR Article 6 requires appropriate cybersecurity features to be considered where the nature of the product makes them necessary to protect against external influences, including malicious third parties, and where that influence could affect product safety. A cybersecurity weakness therefore becomes a GPSR issue when it creates a health or safety consequence, not merely because the product has a network connection.
Interconnection Can Create Safety Risk
The GPSR safety assessment considers the effect of the product on other products and the effect that other products may have on it, including interconnection. For connected products, loss or manipulation of an external connection can therefore matter where the consequence is unsafe behaviour.
Software Updates Can Change the Product-Safety Analysis
The GPSR recognises that new technologies and software updates can change product characteristics and safety. A digital modification that has an impact on safety can trigger a new risk assessment and, under Article 13, a person making a substantial modification can be treated as a manufacturer for the affected product.
The CRA Provides a More Specific Cybersecurity Framework
For in-scope products with digital elements, the CRA establishes detailed cybersecurity and vulnerability-handling requirements that go beyond the GPSR's general safety assessment. Product teams should use the CRA for the dedicated cybersecurity conformity work while separately asking whether the same cyber facts create consumer-safety consequences under the GPSR.
GPSR Does Not Simply Vanish for Every Product Subject to Union Harmonisation Law
Article 2 narrows the GPSR where specific Union harmonisation legislation covers the same risks, and certain GPSR chapters do not apply to harmonised products. Other GPSR provisions can remain complementary, including particular consumer-protection, online-marketplace, accident, recall or remedy mechanisms where no specific rule with the same objective applies.
CRA Cybersecurity Evidence Can Support GPSR Safety Work
Threat models, penetration tests, secure-update records, incident analysis and architecture evidence can help a safety team understand whether malicious external influence could create an unsafe condition. Reuse the evidence, but record a separate safety conclusion because the GPSR asks whether the product is safe, while the CRA asks whether cybersecurity requirements are satisfied.
Corrective Actions May Need Coordination
A serious cybersecurity weakness can require CRA remediation and can also create a product-safety problem requiring consumer communication, withdrawal or recall analysis. Product security, safety, legal and market-surveillance teams should coordinate facts and timing so corrective actions remain consistent across the applicable regimes.
Use a Risk-by-Risk Overlap Record
For connected consumer products, map each significant risk to the legal regime that regulates it. Record whether the risk is governed by CRA cybersecurity requirements, another specific Union product law, the GPSR safety net or more than one regime for different purposes. This prevents both duplicate work and accidental gaps.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.