Cyber Resilience Act (CRA)
Table of Contents
Chapter I – GENERAL PROVISIONS
Chapter II – OBLIGATIONS OF ECONOMIC OPERATORS AND PROVISIONS IN RELATION TO FREE AND OPEN-SOURCE SOFTWARE
Chapter III – CONFORMITY OF THE PRODUCT WITH DIGITAL ELEMENTS
Chapter IV – NOTIFICATION OF CONFORMITY ASSESSMENT BODIES
Chapter V – MARKET SURVEILLANCE AND ENFORCEMENT
Chapter VI – DELEGATED POWERS AND COMMITTEE PROCEDURE
Chapter VII – CONFIDENTIALITY AND PENALTIES
Chapter VIII – TRANSITIONAL AND FINAL PROVISIONS
Recitals (130)
Annexes
Annex III
IMPORTANT PRODUCTS WITH DIGITAL ELEMENTS
Class I
1. Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers
2. Standalone and embedded browsers
3. Password managers
4. Software that searches for, removes, or quarantines malicious software
5. Products with digital elements with the function of virtual private network (VPN)
6. Network management systems
7. Security information and event management (SIEM) systems
8. Boot managers
9. Public key infrastructure and digital certificate issuance software
10. Physical and virtual network interfaces
11. Operating systems
12. Routers, modems intended for the connection to the internet, and switches
13. Microprocessors with security-related functionalities
14. Microcontrollers with security-related functionalities
15. Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalities
16. Smart home general purpose virtual assistants
17. Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems
18. Internet connected toys covered by Toy Safety Directive of the European Parliament and of the Council () that have social interactive features (e.g. speaking or filming) or that have location tracking features
19. Personal wearable products to be worn or placed on a human body that have a health monitoring (such as tracking) purpose and to which Medical Devices Regulation (MDR) or (EU) No 2017/746 do not apply, or personal wearable products that are intended for the use by and for children
Class II
1. Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments
2. Firewalls, intrusion detection and prevention systems
3. Tamper-resistant microprocessors
4. Tamper-resistant microcontrollers