EU Cyber Resilience Act
Cybersecurity obligations for products with digital elements placed on the EU market. CRA scope, role, Annex III/IV classification, conformity route and timing are evaluated by the pinned CEMarque canonical engine.
beta · ruleset cemarque-r25-429f565 · reviewed 2026-09-10
429f565 · rules 2026.09.1 · facts 2026.09.4. Conformoo pins this version and does not maintain a second CRA decision tree.Deterministic decisions
EU availability, commercial activity, connectivity, delivery form, remote processing, exclusions and economic-operator role.
Class is derived from matched Annex items. There is no declared
cra.category input.Timing is produced by the canonical engine only after its scope gates.
Authoritative sources
Regulation (EU) 2024/2847 — Cyber Resilience Act
https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng
primary_binding_law · reviewed 2026-09-10
Obligation library
Canonical CRA obligation set
The applicable obligation set is instantiated from the CEMarque verdict's cited fact IDs rather than from an independent Conformoo CRA rule table.
Generated artifacts
CRA Applicability Report
report · template v1.0.0
CRA Cybersecurity Risk Assessment Starter
worksheet · template v1.0.0
CRA Article 14 Reporting Runbook
runbook · template v1.0.0
CRA Technical Documentation Package Index
checklist · template v1.0.0
Vulnerability Disclosure Policy Starter
policy · template v1.0.0