Independent information resource Product security · EU CRA
CRA scope / 03

Does the CRA Apply to Hardware?

Learn when hardware falls within the Cyber Resilience Act, including connected devices, hardware components, embedded software, network connectivity, market availability and product classification.

IN BRIEF

Connected hardware and separately marketed hardware components can fall within CRA scope. Manufacturers should define the complete product boundary, including embedded software and firmware, then assess connectivity, the Union market route, exclusions and product classification.

01 / 08

Hardware Is Expressly Covered by the CRA Definition

Article 3 expressly includes hardware within the definition of a product with digital elements. It defines hardware as a physical electronic information system, or parts of one, capable of processing, storing or transmitting digital data. The CRA is therefore not limited to software or internet applications. Physical products containing processors, digital storage, communications functionality or other electronic information-system capabilities can enter the scope analysis.

02 / 08

Connectivity Is Still Part of the Scope Test

Being electronic hardware does not by itself settle CRA scope. Article 2 generally requires the product's intended purpose or reasonably foreseeable use to include a direct or indirect logical or physical data connection to a device or network. This can include Ethernet, Wi-Fi, Bluetooth, USB data interfaces, industrial networks, device-to-device communication or other relevant data connections. The product does not need to be continuously connected to the public internet.

03 / 08

Connected Consumer Devices Can Be Covered

Many connected consumer devices can meet the definition of a product with digital elements where the other scope conditions are satisfied. Examples can include connected cameras, smart-home products, wearable devices, routers and other digitally connected equipment. The exact result depends on the product and applicable legal rules rather than on its marketing category. Some types of connected products can also interact with other EU product legislation, which needs to be considered separately.

04 / 08

Industrial Hardware Can Also Require CRA Analysis

The CRA is not limited to consumer products. Industrial controllers, network appliances, industrial computers, communications equipment and other hardware used in professional environments can also require CRA analysis. Intended use in a factory or enterprise environment does not by itself remove a hardware product from the CRA. The product boundary, connectivity, Union market route and any sector-specific exclusions or interactions still need to be assessed.

05 / 08

Hardware Components Can Be Products in Their Own Right

Article 3 includes hardware components being placed on the market separately. A component intended for integration into another electronic information system can therefore have its own CRA position when marketed separately. Manufacturers should distinguish a component supplied as its own commercial product from a part that exists only inside a finished product and is never separately placed on the market.

06 / 08

Embedded Software Is Part of the Product-Security Picture

Modern hardware frequently depends on firmware, boot software, device drivers, local applications and other embedded code. CRA scope and cybersecurity analysis should reflect the product as it actually operates rather than treating the physical enclosure as the entire product. The manufacturer needs to understand which software enables product functions, how it is updated and how vulnerabilities in that software affect the security of the hardware product.

07 / 08

Hardware Scope and Hardware Classification Are Different

A conclusion that hardware is within CRA scope does not determine its conformity route. Some categories of hardware with particular core functionality are listed as important or critical products under Annexes III and IV. Other hardware remains within the general product framework. Classification should therefore follow the scope determination rather than replace it.

08 / 08

Build the Hardware Scope Record Around the Marketed Product

A practical hardware scope record should identify the marketed device, processor and digital functions, firmware and embedded software, communications interfaces, remote functions, intended use, expected deployment environment, manufacturer and Union market route. Separately marketed components should be identified as separate products where appropriate. That record can then support classification, cybersecurity risk assessment and conformity work.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.