Form cover
Page 1 of 2

CRA Product Scope & Applicability Form

This form helps identify whether your product is likely in scope of the EU Cyber Resilience Act (CRA), and which obligations may apply.
This is not a legal determination and does not replace legal or conformity assessment advice.

SECTION-1

Where is your company legally established?

Where is your company legally established?
A
B

Do you make your product available in the EU market?

Do you make your product available in the EU market?
A
B
C

Your role for this product

Your role for this product
A
B
C
D
E

SECTION-2

Product Name

Product type

Product type
A
B
C
D
E

Is this product intended to be used by:

Is this product intended to be used by:
A
B
C

Section-3

Does your product have any of the following?

Does your product have any of the following?
A
B
C
D
E

Does your product include third-party or open-source software components?

Does your product include third-party or open-source software components?
A
B
C
D

Do you maintain a software bill of materials (SBOM)?

Do you maintain a software bill of materials (SBOM)?
A
B
C
D

Can you update the product after release?

Can you update the product after release?
A
B
C
D

Section-5

Vulnerability Reporting

Vulnerability Reporting
A
B
C

Security patches

Security patches
A
B
C

Third-party monitoring

Third-party monitoring
A
B
C

Section-6

Does your product perform any of the following functions?

Does your product perform any of the following functions?
A
B
C
D
E
F
G
H
I
J
K
L

Section-7

Uses AI?

Uses AI?
A
B
C

AI Security Relevant?

AI Security Relevant?
A
B
C

Section-8

Support period

Support period
A
B
C
D

Lifecycle Status

Lifecycle Status
A
B
C
D

Section-9

Email