The CRA glossary
The key terms of the Cyber Resilience Act, each with what it means in practice. Where the regulation defines a term itself, the official definition and its place in the text are given.
No term matches this search.
A
-
Actively exploited vulnerability Legal definition
The trigger for the reporting duty: the only vulnerability state that starts a 24-hour clock.
Learn more about Actively exploited vulnerability -
Administrative cooperation group (ADCO) Practical term
The coordination body of the national market surveillance authorities. It orders nothing against a company, but it shapes what those authorities measure against.
Learn more about Administrative cooperation group (ADCO) -
Attack surface Practical term
The sum of all the places where an attacker can interact with a product. Annex I requires keeping it small, measured against the risk.
Learn more about Attack surface -
Authorised representative Legal definition
The mandated representation inside the Union, which takes on specified tasks but expressly not the manufacturer’s core obligations.
Learn more about Authorised representative
C
-
CE marking Legal definition
The manufacturer’s own declaration that product and processes meet the requirements. No authority certifies it: it is a self-declaration that carries liability.
Learn more about CE marking -
Commission guidelines Practical term
The interpretive material the Commission publishes under Article 26. It eases application of the CRA, but replaces no standard and creates no presumption of conformity.
Learn more about Commission guidelines -
Common specifications Practical term
The CRA fallback for when standardisation does not deliver: technical requirements adopted by the Commission with the same effect as a harmonised standard.
Learn more about Common specifications -
Component Legal definition
Software or hardware meant for integration, for as long as it stays integrated. Marketed separately, it becomes a product with the full set of obligations.
Learn more about Component -
Conformity assessment Legal definition
The demonstration that a product meets the essential requirements: self-assessed or with a notified body, depending on the product category.
Learn more about Conformity assessment -
Conformity assessment body Legal definition
The testing and certification organisation that has to satisfy Article 39 before a Member State may designate it as a notified body. The CRA borrows the term itself from accreditation law.
Learn more about Conformity assessment body -
Conformity assessment procedures Practical term
The four routes in Article 32 by which a manufacturer demonstrates conformity, from self-assessment to a quality system audited by a notified body.
Learn more about Conformity assessment procedures -
Consumer Legal definition
The CRA adopts the standard consumer definition but attaches very few rules to it. For a manufacturer’s obligations it is rarely the deciding factor.
Learn more about Consumer -
Coordinated vulnerability disclosure Practical term
The defined process for how vulnerability reports from outside arrive, get handled and eventually become public. For manufacturers it is an obligation, not a nicety.
Learn more about Coordinated vulnerability disclosure -
Critical products with digital elements Practical term
The three product categories in Annex IV, the only ones that can be made subject to mandatory European certification. Until that happens, the Article 32(3) procedures apply.
Learn more about Critical products with digital elements -
CSIRT designated as coordinator Legal definition
The national body that receives a manufacturer’s mandatory notifications. It is not created by the CRA but designated under Article 12(1) of the NIS2 Directive.
Learn more about CSIRT designated as coordinator -
CVE Practical term
The unique identifier for publicly known vulnerabilities. Essential for matching against your bill of materials, but not a statement about risk.
Learn more about CVE -
CVSS Practical term
The widely used scoring system for vulnerability severity, which only becomes meaningful once your own context is factored in.
Learn more about CVSS -
Cyber resilience regulatory sandboxes Practical term
Controlled testing environments before placing on the market that a Member State may set up but need not. They ease the run-up to conformity without replacing it.
Learn more about Cyber resilience regulatory sandboxes -
Cyber threat Legal definition
The yardstick that decides whether a weakness counts as a vulnerability. Cyber threats themselves are only ever reported voluntarily.
Learn more about Cyber threat -
Cybersecurity Legal definition
The purpose of the whole Regulation is the one notion the CRA does not spell out itself. It borrows the wording of the Cybersecurity Act, and what is meant are activities, not a state once achieved.
Learn more about Cybersecurity -
Cybersecurity risk Legal definition
Magnitude and likelihood of an incident together make up the measure that decides which Annex I requirements apply to a product in the first place.
Learn more about Cybersecurity risk -
CycloneDX Practical term
One of the two established exchange formats for software bills of materials. The CRA never names it, yet it satisfies the Annex I requirement.
Learn more about CycloneDX
D
-
Data connection Practical term
Article 2(1) hangs the entire scope of the CRA on a single feature. Four forms of connection are provided for, and one of them is enough.
Learn more about Data connection -
Distributor Legal definition
The lightest role in the supply chain. But only as long as the product’s properties remain untouched.
Learn more about Distributor -
Due diligence for third-party components Practical term
Article 13(5) makes manufacturers answerable for building blocks they did not write themselves. How deep the checking has to go depends on the risk of the individual component.
Learn more about Due diligence for third-party components
E
-
Economic operator Legal definition
The umbrella term the CRA uses whenever it addresses every role that carries obligations at once, from manufacturer and representative to importer and distributor.
Learn more about Economic operator -
Electronic information system Legal definition
The CRA’s base technical term. On its own it creates no manufacturer obligation, yet it carries the definitions of software, hardware and component.
Learn more about Electronic information system -
End-point Legal definition
A device becomes an end-point through its role in a network, not through its form factor. The CRA defines the term but attaches no obligation of its own to it.
Learn more about End-point -
ENISA Practical term
The European Union Agency for Cybersecurity. The CRA does not create it, but makes it the second recipient of every mandatory notification and the operator of the reporting platform.
Learn more about ENISA -
Essential cybersecurity requirements Practical term
Annex I of the CRA: thirteen requirements for the product and eight for the manufacturer’s processes. Without both, a product cannot reach the market.
Learn more about Essential cybersecurity requirements -
EU declaration of conformity Practical term
The manufacturer’s binding statement that a product meets the requirements. Without it there is no CE marking; with it, responsibility is assumed.
Learn more about EU declaration of conformity -
European cybersecurity certification scheme Practical term
The fourth route to conformity: a certificate issued under a scheme of the Cybersecurity Act, which can even become compulsory for critical products.
Learn more about European cybersecurity certification scheme -
European standard Legal definition
The wider category that harmonised standards come from. Adopted by CEN, Cenelec or ETSI, voluntary to apply, and on its own carrying no presumption of conformity.
Learn more about European standard -
European vulnerability database Practical term
The European record of known vulnerabilities run by ENISA. The CRA does not establish it, but draws on it at both ends of the vulnerability process.
Learn more about European vulnerability database -
Exploitable vulnerability Legal definition
The middle of three levels. It sets no reporting clock running, yet it blocks every further shipment for as long as it is known and unfixed.
Learn more about Exploitable vulnerability
F
-
Free and open-source software Legal definition
The definition sits in Article 3(48), but it does not decide the scope. Open-source software is caught only once it is made available on the market in the course of a commercial activity.
Learn more about Free and open-source software
H
-
Hardware Legal definition
The physical counterpart to software. The classification helps decide where identifiers and the CE marking go, and what the technical documentation has to show.
Learn more about Hardware -
Harmonised standard Legal definition
Voluntary to apply, but with a substantial benefit: comply with one and your product is deemed conformant to that extent.
Learn more about Harmonised standard
I
-
Important products with digital elements Practical term
Annex III of the CRA lists 19 categories in class I and four in class II. A product that has their core functionality loses the free choice of how to assess its conformity.
Learn more about Important products with digital elements -
Importer Legal definition
Whoever first brings third-country products onto the Union market carries real verification duties, but not the manufacturer’s development responsibility.
Learn more about Importer -
Incident Legal definition
The second reporting trigger alongside actively exploited vulnerabilities, defined through NIS2 and narrower than everyday usage suggests.
Learn more about Incident -
Incident affecting product security Legal definition
An incident that harms, or could harm, a product’s ability to protect data or functions. It only has to be reported where Article 14(5) makes it severe.
Learn more about Incident affecting product security -
Indirect connection Legal definition
The term that pulls products with no network access of their own into scope, as soon as the system around them can be connected.
Learn more about Indirect connection -
Information and instructions to the user Practical term
The information package Annex II requires with every product, from the vulnerability contact point to the end date of the support period.
Learn more about Information and instructions to the user -
Informing users Practical term
The duty to inform impacted users about actively exploited vulnerabilities and severe incidents. It sits alongside the notification to authorities and is not discharged by it.
Learn more about Informing users -
Intended purpose Legal definition
The use a manufacturer states for a product, and the reference point for scope, risk assessment and the reach of every obligation.
Learn more about Intended purpose -
International standard Legal definition
Pulled in through the European standardisation regulation and limited to three bodies: a usable working basis, but no presumption of conformity.
Learn more about International standard
L
-
Logical connection Legal definition
The kind of connection that needs no cable or plug. For pure software it is the route into the scope of the CRA.
Learn more about Logical connection
M
-
Making available on the market Legal definition
Any supply for distribution or use in the course of a commercial activity, whether paid for or not.
Learn more about Making available on the market -
Manufacturer Legal definition
The role carrying by far the most obligations, and one you take on faster than expected: selling under your own name is enough.
Learn more about Manufacturer -
Market surveillance authority Legal definition
The national body that enforces the CRA: it requests documentation, orders corrective action and imposes the fines.
Learn more about Market surveillance authority -
Micro, small and medium-sized enterprises Legal definition
Not a separate class of obligations but a size classification borrowed from Recommendation 2003/361/EC. It governs simplified documentation, reduced fees and one narrow exemption from fines.
Learn more about Micro, small and medium-sized enterprises -
Module A: internal control Practical term
The conformity assessment procedure a manufacturer runs alone: no notified body, no certificate, but the obligations in points 2, 3 and 4 of Annex VIII, Part I.
Learn more about Module A: internal control -
Module B: EU-type examination Practical term
The part of a conformity assessment procedure in which a notified body examines and certifies the type. On its own it does not open the market.
Learn more about Module B: EU-type examination -
Module C: conformity to type Practical term
The second step after EU-type examination. Here the manufacturer alone ensures that every unit produced matches the type that was examined.
Learn more about Module C: conformity to type -
Module H: full quality assurance Practical term
The one CRA procedure in which a notified body examines no type at all but approves the manufacturer’s quality system and then keeps it under surveillance.
Learn more about Module H: full quality assurance
N
-
Near miss Legal definition
The event that almost became an incident: outside the Article 14 reporting duty, but open to voluntary notification under Article 15.
Learn more about Near miss -
Notified body Legal definition
The independent organisation behind third-party conformity assessment of important and critical products, designated by a Member State and listed by the Commission.
Learn more about Notified body -
Notifying authority Legal definition
The national body behind the notified bodies. It assesses, designates, notifies and monitors the assessment organisations of a Member State.
Learn more about Notifying authority
O
-
Open-source software steward Legal definition
A role of its own for foundations and entities that sustain open-source development without being manufacturers. The list of duties attached to it is much shorter.
Learn more about Open-source software steward
P
-
Penalties and administrative fines Practical term
Three tiers of administrative fine reaching EUR 15 million or 2.5 % of worldwide annual turnover, capped by the CRA and imposed under national law.
Learn more about Penalties and administrative fines -
Personal data Legal definition
A term the CRA borrows from the GDPR. It rarely decides whether an Annex I requirement applies, but it does decide how heavily the risk weighs.
Learn more about Personal data -
Physical connection Legal definition
Electrical, optical and mechanical interfaces, wires and radio waves: the CRA draws the physical connection widely, and radio sits in the same list as the cable.
Learn more about Physical connection -
Placing on the market Legal definition
The first making available on the Union market: the point by which assessment, documentation and marking must all exist.
Learn more about Placing on the market -
Presumption of conformity Practical term
Apply one of the three rulebooks in Article 27 and compliance need not be derived requirement by requirement, but only in so far as the rulebook covers it.
Learn more about Presumption of conformity -
Product with digital elements Legal definition
This term decides whether the CRA applies to a product at all. It reaches considerably further than the wording first suggests.
Learn more about Product with digital elements
R
-
Reasonably foreseeable misuse Legal definition
The use that runs against the intended purpose and still has to be expected. In the Regulation it has exactly one home: the information for users.
Learn more about Reasonably foreseeable misuse -
Reasonably foreseeable use Legal definition
The use that is not necessarily the intended purpose and still has to be expected. It helps decide whether a product is in scope, and it belongs in the risk assessment.
Learn more about Reasonably foreseeable use -
Recall Legal definition
The sharpest corrective measure in the CRA: it aims at the return of products that have already reached the end user, whether driven by the manufacturer itself or ordered by an authority.
Learn more about Recall -
Remote data processing Legal definition
Whether a backend is regulated along with the product turns on this term. It qualifies the common assumption that SaaS is out of scope.
Learn more about Remote data processing -
Reporting obligations Practical term
The most time-critical requirement in the CRA: two triggers, three stages, and a deadline that runs in calendar time.
Learn more about Reporting obligations
S
-
Security update Practical term
The fix the CRA requires without delay, free of charge and, where feasible, separately from functionality updates. It has to stay retrievable for ten years after it is issued.
Learn more about Security update -
Significant cybersecurity risk Legal definition
The threshold at which a risk turns into a procedure: a high likelihood of an incident and severe consequences have to be present together.
Learn more about Significant cybersecurity risk -
Single reporting platform Practical term
The reporting route the CRA runs on, operated by ENISA. One notification, one national end-point, and behind it distribution to every authority concerned.
Learn more about Single reporting platform -
Software Legal definition
Not a thing in its own right under the CRA, but the part of a system that consists of computer code. Obligations attach only once it is a product or a component.
Learn more about Software -
Software Bill of Materials (SBOM) Legal definition
The machine-readable record of every component in a product. Any vulnerability analysis builds on it, and the CRA requires it explicitly.
Learn more about Software Bill of Materials (SBOM) -
SPDX Practical term
The bill of materials format that grew out of licence compliance. The CRA never names it, and it still answers the Annex I duty well.
Learn more about SPDX -
Substantial modification Legal definition
The threshold at which an already marketed product must be reassessed. Crossing it can turn a distributor into a manufacturer.
Learn more about Substantial modification -
Support period Legal definition
The period during which vulnerabilities must be handled. At least five years, measured against how long the product is expected to be used.
Learn more about Support period
T
-
Technical documentation Practical term
The evidence behind the declaration of conformity, which must exist before placing on the market and stay available for at least ten years.
Learn more about Technical documentation -
Transition periods and dates of application Practical term
The CRA has been in force since December 2024 but takes effect in stages: Chapter IV since June 2026, Article 14 from September 2026, everything else from December 2027.
Learn more about Transition periods and dates of application
U
-
Union harmonisation legislation Legal definition
The collective name for the body of EU product law the CRA joins. It governs CE marking, the single declaration of conformity and the reach of notified bodies.
Learn more about Union harmonisation legislation -
Union safeguard procedure Practical term
The escalation stage of CRA enforcement. It settles whether one Member State’s measure against a product applies across the Union or has to be withdrawn.
Learn more about Union safeguard procedure
V
-
VEX Practical term
The machine-readable statement of whether a known vulnerability actually affects your product. It is the answer to the noise from bill-of-materials matching.
Learn more about VEX -
Vulnerability Legal definition
The deliberately broad starting point of all vulnerability handling, and by no means the same thing as a defect.
Learn more about Vulnerability
W
-
Withdrawal Legal definition
The corrective measure that stops the supply line: it catches everything that has not yet reached the end user, from warehouse stock to shelf stock to download offers.
Learn more about Withdrawal
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.