Sources
Primary source
The only primary source is the Official Journal text of the Cyber Resilience Act as published on EUR-Lex, which entered into force on 10 December 2024 [1]. Guidance documents and recitals inform how the Facts Table phrases an entry, and are named in the entry's citation where they do.
The Facts Table
CEMarque maintains the Facts Table: each entry has an identifier, a kind, the provision it cites, and a plain-language statement checked against the text. The table is versioned; every page on this site names the version it was written against and cannot be served against an older one.
Facts this site depends on
Every entry below is a CEMarque Facts Table item (v2026.09.4) that at least one CRARequired page cites. The full table, with change history, is published by CEMarque.
- F-001 Regulation (EU) 2024/2847 entered into force on 10 December 2024. Art. 71(1)
- F-002 Article 14 (reporting obligations of manufacturers) applies from 11 September 2026. Art. 71(2)
- F-003 The Regulation applies in full from 11 December 2027. Art. 71(2)
- F-004 Products placed on the market before 11 December 2027 are subject to the Regulation only if substantially modified after that date; Article 14 applies to them regardless. Art. 69(2)–(3)
- F-005 A product with digital elements is a software or hardware product and its remote data processing solutions, including components placed on the market separately, whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Art. 3(1), Art. 2(1)
- F-006 Remote data processing means data processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the product from performing one of its functions. Art. 3(2)
- F-007 The Regulation applies to products made available on the market in the course of a commercial activity; charging a price, charging for support, monetising via advertising or data, or otherwise intending to monetise are commercial activity. Art. 2(1), Art. 3(22), Recitals
- F-008 Cloud services that are not part of a product are outside the Regulation (they fall under NIS2); remote data processing essential to a product is within scope as part of that product. Art. 3(1)–(2), Recitals
- F-009 Free and open-source software not monetised is not considered placed on the market. Open-source software stewards (legal persons that systematically support free and open-source software intended for commercial activities) have a light regime: a documented cybersecurity policy, cooperation with authorities, and Article 14 reporting only where they are involved in development or where an incident affects their own development infrastructure; they do not affix CE marking and are not subject to fines. Art. 3(14), Art. 3(48), Art. 24, Art. 64(10)(b), Recitals 18–19
- F-010 Excluded: medical devices (Regulation (EU) 2017/745) and in vitro diagnostics (2017/746) and motor-vehicle type-approved products (2019/2144) (Art. 2(2)); civil aviation products certified under Regulation (EU) 2018/1139 (Art. 2(3)); marine equipment under Directive 2014/90/EU (Art. 2(4)); spare parts made to identical specifications (Art. 2(6)); products developed or modified exclusively for national security or defence, or designed exclusively to process classified information (Art. 2(7)). Art. 2(2)–(4), (6)–(7)
- F-011 Manufacturer: a natural or legal person who develops or manufactures products with digital elements or has them designed, developed or manufactured, and markets them under their name or trademark, whether for payment, monetisation or free of charge. Art. 3(13)
- F-012 Importers place only compliant products on the market; verify conformity assessment, technical documentation, CE marking and manufacturer identification; indicate their own name and address; report known vulnerabilities to the manufacturer; keep the declaration of conformity; cooperate with authorities. Art. 19
- F-013 Distributors act with due care; verify CE marking, declaration of conformity and manufacturer/importer obligations; do not make non-compliant products available; report vulnerabilities to the manufacturer; cooperate with authorities. Art. 20
- F-014 Substantial modification: a change after placing on the market affecting compliance with essential requirements or resulting in a modification of the intended purpose; a person who substantially modifies a product becomes its manufacturer. Art. 3(30), Art. 22
- F-030 Actively exploited vulnerability (Art. 3(42)): reliable evidence that a malicious actor has exploited it in a system without the system owner's permission. A severe incident having an impact on the security of the product (Art. 14(5)) is one that negatively affects or is capable of negatively affecting the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or that has led or is capable of leading to the introduction or execution of malicious code. Art. 3(42), Art. 3(44), Art. 14(5)
- F-034 A manufacturer may appoint an authorised representative by written mandate; the representative keeps the declaration of conformity and technical documentation at the disposal of authorities and cooperates with them. Non-EU manufacturers: reporting is routed via the representative's Member State. Art. 18, Art. 3(15), Art. 14(7)
- F-101 Made available on the market means supply for distribution or use on the EU market in the course of a commercial activity. Art. 3(22)
- F-102 Monetisation or commercial redistribution by you changes a non-commercial verdict; re-check when that happens. Recitals
- F-103 Cloud services may fall under NIS2 (Directive (EU) 2022/2555) rather than the CRA. NIS2
- F-104 A developer who integrates a component into their own product is the manufacturer of that product and responsible for its conformity, including the integrated component. Art. 13(5), Art. 3(13)
- F-105 For products already on the market, conformity is not required until substantial modification, but customers and distributors may ask for it; Article 14 applies regardless. Art. 69(2)–(3)
- F-106 Marketing a product under your own name or trademark makes you the manufacturer even if someone else developed it. Art. 3(13), Art. 21
- F-107 Where a product depends on your own remote data processing (a backend or API without which it cannot perform one of its functions), that remote processing is part of the product: it is covered by the essential requirements, the technical documentation and market surveillance alongside the client software or device. Art. 3(1)–(2), Annex I, Annex VII