Interactive Tool

EU Cyber Resilience Act Scope Explorer

Determine whether your product is in scope of the EU Cyber Resilience Act, which conformity route applies, and how ISASecure / IEC 62443 certification accelerates your path to compliance.

Dec 2024

CRA entered into force

Sep 11, 2026

Vulnerability & incident reporting obligations apply

Dec 11, 2027

Full application — conformity assessment & CE marking

Explore your CRA conformity path

Click the starting question, then a product category, to see the applicable conformity route and how an ISASecure certification supports it. The CRA applies to any product with digital elements placed on the EU market — including non-EU manufacturers.

Product with digital elements?

The CRA applies to any hardware or software 'product with digital elements' (PDE) made available on the EU market — regardless of where the manufacturer is based. If you sell into the EU, you are in scope.

Conformity route

Determine your product class to find the conformity route.

How ISASecure helps

Perseus helps you classify your product and scope CRA obligations.

Note: This tool is an educational guide, not legal advice. CRA harmonised standards and product classifications are still being finalised; an ISASecure / IEC 62443 certification supports and accelerates CRA readiness but does not by itself constitute a CE marking. Contact Perseus for a formal scoping assessment.

Prepare for the CRA Deadline

The CRA's full obligations apply from December 2027. Perseus combines ISASecure certification authority with IEC 62443 expertise to get your products compliant ahead of the deadline.