Cyber Resilience Act

End-point

Legal definition Art. 3(11) CRA

“any device that is connected to a network and serves as an entry point to that network”
Regulation (EU) 2024/2847, Art. 3(11) CRA

An end-point is, under Article 3, point (11), of the Cyber Resilience Act (CRA), any device that is connected to a network and serves as an entry point to that network. The definition has two elements that must coincide: the connection to a network, and the role of providing a way into that same network.

The second element is the narrower one. A device sitting on a network is not thereby an end-point; it has to open the route into that network. The CRA defines neither “device” nor “network”, so the question turns on function rather than on form factor. A laptop can be an end-point, and so can a router, a gateway or a server. The wording “any device” excludes no class of device from the outset.

Where the term appears in the Regulation

Outside the definition itself, the end-point in this sense appears exactly once in the enacting terms of the CRA: in Article 7(2), point (a), as “end-point security”. It is absent from Annex I and from Article 2, and no manufacturer obligation attaches to being an end-point. The definition is a building block for other provisions, not a legal consequence in itself.

End-point security as a classification criterion

Article 7(2) sets out two criteria, at least one of which is met by each product category listed in Annex III. Point (a) describes products that primarily perform functions critical to the cybersecurity of other products, networks or services, and lists securing authentication and access, intrusion prevention and detection, end-point security or network protection.

That criterion classifies nothing by itself. Under Article 7(1) an important product is one having the core functionality of a category set out in Annex III, and no category there is called end-point security. The closest are class I, point 4, software that searches for, removes or quarantines malicious software, and class II, point 2, firewalls, intrusion detection and prevention systems. What follows from the classification is covered by the pages on important products and critical products.

The criterion does most of its work looking forward. Article 7(3) empowers the Commission to amend Annex III by delegated act and points to these same criteria when assessing whether an amendment is needed. Where a category is newly added or moved from class I to class II, those acts provide, where appropriate, for a transitional period of at least 12 months before the conformity assessment procedures in Article 32(2) and (3) start applying, unless a shorter period is justified on imperative grounds of urgency. The technical descriptions of the categories in Annexes III and IV come from an implementing act under Article 7(4), which the Commission is to adopt by 11 December 2025.

Not to be confused with the notification end-point

The same word carries an entirely different meaning elsewhere in the CRA. Under Article 16(1) the architecture of the Single reporting platform must allow Member States and ENISA to put in place their own electronic notification end-points. Article 14(7) determines which of those end-points a manufacturer files through, and under Article 16(5) ENISA provides specifications for the secure operation of the platform that also cover the security arrangements for those end-points.

What is meant there is a reporting interface at a CSIRT designated as coordinator or at ENISA, not a device. The definition in Article 3, point (11), describes something else and does not fit it. Reading the reporting provisions, the term should therefore be kept apart from the legal definition.

Relationship to the scope

Article 2(1) makes the CRA applicable on the basis of a direct or indirect, logical or physical data connection to a device or network. The word end-point does not occur there. The definition therefore does not state the entry test; it describes one possible far end of the connection. The scope test itself is explained by the Data connection.

Why that role matters is set out in recital 9, which does not use the word end-point. Under certain conditions, any product with digital elements integrated in or connected to a larger electronic information system can serve as an attack vector for malicious actors. Even hardware and software considered less critical can facilitate the initial compromise of a device or network and open the way to privileged access or lateral movement between systems. That is precisely the role an end-point plays.

What it changes in practice

Even without a legal consequence of its own, acting as an entry point shapes the requirements. Annex I, Part I, point 2 applies, by its opening sentence, on the basis of the cybersecurity risk assessment under Article 13(2) and only where applicable. For a device through which a network is entered, four letters are regularly in play:

  • Point (d): protection from unauthorised access by appropriate control mechanisms, including at least authentication, identity or access management systems, and reporting on possible unauthorised access
  • Point (i): minimising the negative impact of the product itself or of connected devices on the availability of services provided by other devices or networks
  • Point (j): limiting attack surfaces, expressly including external interfaces
  • Point (k): reducing the impact of an incident through appropriate exploitation mitigation mechanisms and techniques

Article 13(3) requires the risk assessment to state whether and, if so, in what manner the requirements in Annex I, Part I, point 2 apply to the product and how they are implemented. Where a manufacturer treats one of the Essential cybersecurity requirements as inapplicable, Article 13(4) calls for a clear justification in the technical documentation. For a product that serves as the way into a network, that justification is hard to sustain for the four letters above.

Recital 55 shows the route out where a requirement genuinely does not fit but risks remain: the manufacturer should address them by other means, for instance by limiting the intended purpose to trusted environments or by informing users about the risks. Such a limitation does not stay internal. Under Annex II, point 4, the intended purpose including the security environment provided by the manufacturer belongs in the information supplied to the user.

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.