Interactive Tool
EU Cyber Resilience Act Scope Explorer
Determine whether your product is in scope of the EU Cyber Resilience Act, which conformity route applies, and how ISASecure / IEC 62443 certification accelerates your path to compliance.
Dec 2024
CRA entered into force
Sep 11, 2026
Vulnerability & incident reporting obligations apply
Dec 11, 2027
Full application — conformity assessment & CE marking
Explore your CRA conformity path
Click the starting question, then a product category, to see the applicable conformity route and how an ISASecure certification supports it. The CRA applies to any product with digital elements placed on the EU market — including non-EU manufacturers.
Product with digital elements?
The CRA applies to any hardware or software 'product with digital elements' (PDE) made available on the EU market — regardless of where the manufacturer is based. If you sell into the EU, you are in scope.
Conformity route
Determine your product class to find the conformity route.
How ISASecure helps
Perseus helps you classify your product and scope CRA obligations.
Note: This tool is an educational guide, not legal advice. CRA harmonised standards and product classifications are still being finalised; an ISASecure / IEC 62443 certification supports and accelerates CRA readiness but does not by itself constitute a CE marking. Contact Perseus for a formal scoping assessment.
Prepare for the CRA Deadline
The CRA's full obligations apply from December 2027. Perseus combines ISASecure certification authority with IEC 62443 expertise to get your products compliant ahead of the deadline.