What do Part I and Part II of Annex I mean in the CRA? Annex I sets out the CRA’s essential cybersecurity requirements. Part I covers the security properties products should be designed and developed with, while Part II covers vulnerability handling, including how vulnerabilities should be managed during the support period. For industrial computing and networking products, this makes Annex I especially relevant when reviewing product security, lifecycle support, update policy, and supplier readiness.
Does every industrial computer or networking device need third-party assessment under the CRA? No. Many products can follow a self-assessment route, but that is not true for every category. If a product’s core functionality falls into one of the CRA’s important or critical product categories, stricter conformity assessment rules may apply. That makes it especially relevant for some industrial networking, communications, and security-related devices.
Does the CRA apply to components as well as finished products? Yes. The CRA applies to products with digital elements made available on the EU market, including hardware and software components placed separately on the market as well as finished products. That is relevant for industrial projects where systems are built up from separate computing, networking, storage, or communications elements.