CRA exclusions are specific and should be tested against the exact legal conditions. A product should not be labelled outside scope merely because it belongs to a regulated sector, is used by government, is a spare part or is security sensitive. The applicable Union legislation, certification status, product purpose and factual conditions matter.
Article 2 Contains Specific CRA Exclusions
The Cyber Resilience Act is deliberately broad, but Article 2 identifies several products that are outside its scope or can be excluded under defined conditions. A reliable exclusion assessment should begin with the exact legal category rather than with an assumption that a heavily regulated sector is automatically exempt. Some exclusions depend on another Union legal act applying to the product, some depend on certification, and others depend on how the product was designed or manufactured.
Medical Devices Covered by Regulation (EU) 2017/745 Are Excluded
Article 2(2) excludes products with digital elements to which Regulation (EU) 2017/745 applies. That Regulation governs medical devices. The CRA recitals explain that the medical-device framework already contains requirements addressing cybersecurity risks and takes a lifecycle approach. The correct question is therefore whether the particular product with digital elements is subject to the Medical Devices Regulation, not merely whether it is used somewhere in healthcare.
In Vitro Diagnostic Medical Devices Are Also Excluded
Products with digital elements to which Regulation (EU) 2017/746 applies are also excluded under Article 2(2). This covers the Union framework for in vitro diagnostic medical devices. Software used in a laboratory or health context is not automatically excluded simply because of its environment. Teams need to establish whether the product itself falls under Regulation (EU) 2017/746.
Certain Motor-Vehicle Products Are Outside CRA Scope
Article 2(2) excludes products with digital elements to which Regulation (EU) 2019/2144 applies. That legislation establishes type-approval requirements for motor vehicles, trailers and relevant systems, components and separate technical units, including cybersecurity and software-update requirements. The exclusion therefore turns on the applicability of that Regulation rather than on every product merely being sold to the automotive industry.
Certified Civil-Aviation Products Have a Separate Exclusion
Article 2(3) states that the CRA does not apply to products with digital elements certified in accordance with Regulation (EU) 2018/1139. That Union aviation framework includes information-security and airworthiness controls. The CRA wording is tied to certification under the aviation Regulation, so suppliers should confirm the certification position of the particular product rather than assuming every piece of software used by an aviation business is excluded.
Marine Equipment Within Directive 2014/90/EU Is Excluded
Article 2(4) removes equipment falling within the scope of Directive 2014/90/EU on marine equipment from the CRA. As with the other sectoral exclusions, the question is whether the particular equipment falls within the identified Union legal regime. Ordinary software used by a shipping company or port operator does not become excluded merely because its customer operates in the maritime sector.
Identical Replacement Spare Parts Have a Conditional Exclusion
Article 2(6) excludes spare parts made available on the market to replace identical components in products with digital elements where those spare parts are manufactured according to the same specifications as the components they replace. This is narrower than a general spare-parts exemption. A redesigned, upgraded or functionally different replacement component should not automatically be treated as excluded under this provision.
National-Security and Defence Products Have a Purpose-Based Exclusion
Article 2(7) excludes products with digital elements developed or modified exclusively for national-security or defence purposes, as well as products specifically designed to process classified information. The words exclusively and specifically matter. A general commercial product purchased by a defence ministry does not become excluded merely because of the identity of the buyer. The design or modification purpose of the product needs to satisfy the statutory condition.
Other Sectoral Rules Can Lead to Future Limitations or Exclusions
Article 2(5) allows the Commission to adopt delegated acts limiting or excluding CRA application for products covered by other Union rules where those rules address all or some of the Annex I cybersecurity risks, the limitation fits the overall regulatory framework and the sectoral rules provide the same or a higher level of protection. Teams relying on sectoral law should therefore distinguish an exclusion that exists in Article 2 today from a possible limitation or exclusion that would require the relevant delegated act.
Open Source Is Not an Article 2 Product-Category Exclusion
Free and open-source software should not be placed in the same list as the Article 2 sectoral exclusions. The CRA instead contains specific rules about commercial activity, monetisation, contributors and open-source software stewards. A scope assessment should therefore analyse those provisions directly rather than writing open source into a generic excluded-products checklist.
An Exclusion Should Be Documented With Its Legal Basis
For any product treated as outside CRA scope, record the exact Article 2 provision relied upon, the other Union legislation or certification where relevant, the facts showing that the condition is satisfied and the product version to which the conclusion applies. Add a review trigger for changes in product purpose, certification, specifications or sectoral legislation. An exclusion supported by a short legal-and-product record is more defensible than a spreadsheet cell that simply says exempt.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.