EU compliance checker

Six questions. At the end you get the regulations that apply, the conformity assessment route each one puts you on, and what to read next.

This is an educational tool, not advice. It applies simplified logic to the answers you give and cannot see your product. Use the result as a starting point, not as a determination of your legal position. Disclaimer →

Question 1 of 6

Question 1 What is your product?

Pick the closest description. Software includes mobile and desktop applications, firmware and embedded software.

Question 2 Is it placed on the EU market in the course of a commercial activity?

Placing on the market means the first making available in the EU. Selling from outside the EU to EU customers counts. Non-commercial open source is a separate case.

Question 3 Is it excluded by sector-specific legislation?

The Cyber Resilience Act excludes products already covered by certain sector regimes.

Question 4 Does it fall into an Annex III or Annex IV category?

These are the important and critical product categories. Read them functionally — a device that includes a VPN function is caught by the VPN entry whatever you call the product.

Question 5 For machinery only: is it listed in Annex I of the Machinery Regulation?

Part A is six categories where a notified body is always required. Part B is a longer list where self-assessment survives if harmonised standards are applied in full.

Question 6 For machinery only: will you apply harmonised standards in full?

Applying the relevant harmonised standards in full, where they cover all applicable essential health and safety requirements, is what keeps Annex I Part B products in self-assessment.

The logic, written out

Nothing here is hidden in code. This is exactly what the checker does with your answers.

Cyber Resilience Act

How answers map to a Cyber Resilience Act outcome
IfThen
Software, connected hardware, or machinery with software or a connectionPotentially a product with digital elements — continue
Not made available in the EUOut of scope of the CRA
Open source, published outside any commercial activityExcluded as non-commercial open source. Steward duties may apply to a supporting foundation. Detail →
Medical device, motor vehicle, civil aviation, marine, or national security or militaryExcluded by sector legislation
In scope, no Annex III or IV categoryModule A — self-assessment, no notified body
In scope, Annex III Class IModule A only if harmonised standards or a certification scheme are applied in full; otherwise Module B+C or Module H
In scope, Annex III Class IIModule B+C, Module H, or a certification scheme at level substantial. Notified body required
In scope, Annex IV criticalEuropean cybersecurity certification where mandated by delegated act; otherwise the Class II routes
In scope, in any classArticle 14 reporting applies now. Full obligations from 11 December 2027

Machinery Regulation

How answers map to a Machinery Regulation outcome
IfThen
Not machinery or a related productMachinery Regulation does not apply
Machinery, not listed in Annex IInternal checks — self-assessment
Annex I Part B, harmonised standards applied in fullInternal checks — self-assessment
Annex I Part B, standards not applied in fullEU type-examination plus conformity to type, or full quality assurance. Notified body required
Annex I Part ANotified body required regardless of standards
Any machinery in scopeRegulation (EU) 2023/1230 applies from 20 January 2027. No transition period