Independent information resource Product security · EU CRA
CRA and overlapping EU regulation / 09

When Sector-Specific Cybersecurity Rules Affect CRA Applicability

How sector-specific EU cybersecurity rules can affect Cyber Resilience Act applicability, including express exclusions, Article 2(5) delegated limitations, same-or-higher protection tests and product-specific scope analysis.

IN BRIEF

Use a structured legal decision. First check the express exclusions in Article 2 for MDR, IVDR, covered motor vehicles, specified aviation-certified products and marine equipment. If none applies, check whether a Commission delegated act under Article 2(5) has limited or excluded CRA application for the exact product and sectoral rule. If neither route applies, another cybersecurity law may still operate alongside the CRA even where technical evidence overlaps.

01 / 10

Do Not Treat Every Sectoral Cybersecurity Rule as a CRA Exclusion

The CRA was designed as a horizontal product-cybersecurity framework. Another Union law can impose cybersecurity requirements without automatically displacing it. The legal question is whether Article 2 itself excludes the product or whether a valid limitation or exclusion has been adopted under Article 2(5).

02 / 10

Start With the Express Article 2 Exclusions

Article 2 expressly excludes products with digital elements to which the Medical Device Regulation, the In Vitro Diagnostic Medical Devices Regulation and Regulation (EU) 2019/2144 on motor-vehicle type approval apply. It also excludes specified products certified under Regulation (EU) 2018/1139 and equipment within Directive 2014/90/EU on marine equipment. These exclusions apply by operation of the CRA itself.

03 / 10

Article 2(5) Creates a Separate Limitation Mechanism

For products covered by other Union rules addressing all or some of the cybersecurity risks in Annex I, Article 2(5) allows CRA application to be limited or excluded only where the statutory conditions are met and the Commission adopts a delegated act under Article 61 specifying the products, rules and scope of the limitation where relevant.

04 / 10

The Sectoral Rules Must Provide the Same or a Higher Level of Protection

Article 2(5) is not satisfied merely because another law mentions cybersecurity. The sectoral rules must achieve the same or a higher level of protection as the CRA for the risks concerned. The analysis should therefore compare the actual product-security requirements, lifecycle obligations and covered risks rather than relying on the title of the sectoral legislation.

05 / 10

A Limitation Can Be Partial Rather Than All or Nothing

Article 2(5) permits the CRA to be limited as well as excluded. A future delegated act can therefore define which products, rules or parts of CRA application are affected. Compliance systems should be able to record partial applicability rather than forcing every sectoral product into a binary CRA yes-or-no status.

06 / 10

Check the Exact Product Boundary

Sectoral legislation often applies only to particular products, configurations, intended purposes or type-approval categories. An exclusion that applies to a regulated medical device or vehicle does not automatically extend to unrelated software, development tools, cloud services, aftermarket products or supplier systems sold by the same company.

07 / 10

Entity-Level Cybersecurity Rules Do Not Automatically Decide CRA Product Scope

Some EU cybersecurity laws regulate organisations, services or sectors rather than product conformity. Being subject to an entity-level cybersecurity regime does not by itself answer whether a product with digital elements falls under the CRA. Keep the regulated entity and the regulated product as separate objects in the applicability matrix.

08 / 10

Shared Controls Can Still Reduce Duplicate Work

Even when both CRA and a sector-specific regime apply, common security architecture, secure-development controls, vulnerability processes, test evidence and supplier records may support both. Reuse evidence where it genuinely answers both requirements, but preserve separate legal mappings and conclusions.

09 / 10

Monitor Delegated Acts and Sectoral Amendments

Article 2(5) makes applicability capable of changing as the Commission adopts delegated measures or sector-specific legislation evolves. A product classified as fully CRA-covered today may need reassessment if a future delegated act limits CRA application for that sector. Regulatory monitoring should therefore be tied to affected product records.

10 / 10

Record the Legal Basis for Every Limitation or Exclusion

A defensible applicability record should cite the specific Article 2 paragraph or delegated act, identify the product and sectoral legislation, describe whether the CRA is fully excluded or only limited, and state which obligations remain. Avoid undocumented labels such as sector regulated or equivalent cybersecurity.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.