Exclusions from scope
Over-scoping costs as much as under-scoping. Many organisations apply the CRA to products that are expressly excluded, while forgetting components that are firmly inside.
Sectoral exclusions — the lex specialis rule
The legislator carved out sectors that already have an equivalent or stricter cybersecurity regime. The exclusion rests on the text that covers the product, not on the company’s line of business.
| Excluded products | Prevailing text | Applicable cybersecurity regime |
|---|---|---|
| Medical devices | Regulation (EU) 2017/745 (MDR) | MDR Annex I requirements, MDCG 2019-16 guidance |
| In vitro diagnostic medical devices | Regulation (EU) 2017/746 (IVDR) | Same, IVD strand |
| Motor vehicles | Regulation (EU) 2019/2144 | UN Regulations R155 (cybersecurity management system) and R156 (software update) |
| Civil aviation | Regulation (EU) 2018/1139 | The “Part-IS” delegated regulation on information security |
| Marine equipment | Directive 2014/90/EU | The marine equipment regime |
Exclusions linked to national security and defence
- Products developed or modified exclusively for national security or defence purposes.
- Products specifically designed to process classified information.
The word “exclusively” is decisive: a dual-use product also sold on the civil market is not excluded in its civil version.
Other exclusions
- Spare parts placed on the market to replace identical components in existing products and manufactured to the same specifications.
- Free and open-source software not supplied in the course of a commercial activity — the full regime is set out in Open source.
- Products intended exclusively for research and prototypes not placed on the market.
- Unfinished products made available for testing or demonstration and not intended for end use.
The false friends
Four traps recur.
1. A component of an excluded product is not excluded. A medical device falls under the MDR, but the communications library you sell into it, placed on the market separately, is a PDE in its own right — with its own CE marking under the CRA.
2. A sectoral exclusion does not exempt from NIS 2. An essential or important entity remains subject to its risk management obligations, including supply chain security, whatever products it manufactures.
3. “You sell a service, not a product” is not an exclusion. See the qualification of remote data processing solutions in Scope.
4. “It is open source” is not an exclusion in itself. What is excluded is supply outside a commercial activity. Free software you embed in a product you sell engages your full responsibility: see Integrating open source.
What to produce
For every product ruled out of scope, a reasoned exclusion sheet: the sectoral text relied on, its exact reference, the justification for its applicability, date and signatory. An undocumented exclusion is indefensible before a market surveillance authority, and the cost of demonstrating it after the fact bears no relation to the cost of a one-page sheet written at the right moment.