Reg (EU) 2024/2847Generate dossier — €149
LIVE — Enforcement tracker · Deadline dashboard · Transposition status — Updated weekly from EUR-Lex, Safety Gate, OEIL & 12 official sourcesView regulatory intelligence →

You manufacture WiFi, Bluetooth, and Zigbee modules in Taiwan that end up inside consumer and industrial products sold across the European Union. Under Regulation (EU) 2024/2847, your module is a product with digital elements — it contains firmware, processes data, and establishes network connections. Article 3(1) makes no distinction between a final product and a component placed on the market separately. CRACheck documents it.

Wireless modules sit at the centre of the CRA's supply chain model. Your module contains firmware, implements authentication and encryption protocols, and connects to networks — that places it within Article 2(1). Physical and virtual network interfaces are listed as Important Class I in Annex III (item 10). Routers, modems, and switches are Class I (item 12). If your module functions as a network interface or routing component, it faces the corresponding conformity assessment obligations. CRACheck classifies your module, maps its security features to Annex I, and generates the 8-document dossier. €149 per module family. 15–25 minutes. Browser-side processing.

Generate CRA dossier — €149Free: check your product classification

€149 one-time · 8-document ZIP · 15–25 minutes · Browser-side

Regulation (EU) 2024/2847 · Art. 31 + Annex VII · Annex III Class I · 8 documents · 100% browser-side

Key numbers

Annex III
Network interfaces are Class I (item 10)
Art. 3(1)
Components placed on market separately are in scope
€149
Per module family, one-time payment

How CRACheck works

You enter your product data. CRACheck structures the documentation per Article 31 + Annex VII.

1
Classify your module
CRACheck evaluates whether it qualifies as a network interface (Annex III item 10), router/switch component (item 12), or Default product
2
Enter module specifications
Wireless protocol stack, firmware version, security features (WPA3, BLE pairing, Zigbee trust centre)
3
Document firmware development process
Secure coding, code signing, OTA update capability, regression testing
4
Map Annex I cybersecurity requirements
Authentication, encryption, data minimisation, secure defaults, factory reset
5
Complete vulnerability handling
Module-level PSIRT, CVE coordination with integrator customers, firmware patch distribution
6
Generate the 8-document dossier
Classified and structured for your module's Annex III position
7
Distribute to OEM customers
The dossier supports their own Annex VII technical file as component-level evidence

Common mistakes

RED OVERLAP CONFUSION

"We already comply with the Radio Equipment Directive — the CRA adds nothing"

The RED (Directive 2014/53/EU) and the CRA (Regulation (EU) 2024/2847) are separate legal instruments. The RED's delegated acts on cybersecurity (Article 3(3)(d)(e)(f)) address specific radio equipment risks. The CRA's essential requirements (Annex I) are broader, covering vulnerability handling, secure updates, data protection, and documentation. RED compliance does not satisfy CRA documentation obligations under Art. 31 + Annex VII.

COMPONENT EXEMPTION MYTH

"We sell modules B2B, not to consumers — the CRA does not apply"

Article 2(1) applies to products with digital elements made available on the EU market. "Made available" includes B2B transactions. A module sold to an OEM customer for integration is placed on the market. The CRA does not distinguish between B2C and B2B channels for scope.

INTEGRATOR RESPONSIBILITY

"Our OEM customer is the manufacturer — documentation is their problem"

If you market the module under your own brand and sell it as a separate product to integrators, you are the manufacturer under Article 3(13). Your OEM customer is the manufacturer of the final product, with separate obligations. Both carry documentation duties. Your customer's compliance does not substitute for yours on the module.

What the ZIP contains

8 PDF documents generated from your data. Each cites the specific article of Regulation (EU) 2024/2847 it complies with.

1

Product Classifier

Determines if your module is Default, Important Class I (Annex III item 10 or 12), or another category. Critical for OEM customers who need the component's classification for their conformity assessment.

2

Technical Documentation

Art. 31 + Annex VII dossier for the module: wireless stack architecture, firmware, security protocols, manufacturing quality controls.

3

Risk Assessment

Annex I Part I risk analysis for wireless modules: protocol-level attacks (deauthentication, MITM, replay), firmware injection, key compromise, side-channel leakage.

4

User Information

Annex II integrator documentation: secure integration checklist, antenna requirements, firmware update channel, security defaults, end-of-support date.

5

Declaration of Conformity

Art. 28 + Annex V. Sits alongside your RED Declaration.

6

CVD Policy

Module-level vulnerability disclosure framework: how integrators and researchers report vulnerabilities, acknowledgement timelines, patch distribution.

7

Notification Template

Art. 14 ENISA notification for module vulnerabilities. Includes impact assessment template for downstream products. Art. 14(2): early warning within 24h, notification within 72h, final report within 14 days.

8

Obligations Calendar

Enforcement dates, firmware support period, patch cycle milestones.

Mira antes de comprar — Descargar dossier de muestra (PDF, empresa ficticia) — Estructura real, artículos reales, formato real. Datos ficticios.

Generated from your data, in your browser. No data leaves your device.

What you pay

🧾 EU REGULATORY CONSULTANT FOR WIRELESS MODULES
€8,000–€18,000
4–10 weeks. Requires sharing firmware binaries and RF design. RED and CRA often scoped separately — double cost.
✓ CRACHECK
€149
8 documents. 15–25 min. 100% browser-side — firmware and RF specs stay on your machine. 10 regenerations for firmware updates. Pack 10: €99/module. Pack 30: €79/module.

Two layers

● LAYER 1

Module-level CRA documentation

CRACheck classifies your wireless module against Annex III, maps security features to Annex I, generates 8 PDFs per Art. 31 + Annex VII. This is what your OEM customers need as component-level evidence and what you need as the module manufacturer.

∅ LAYER 2

Implementation and testing

CRACheck does not test your WPA3 implementation, audit BLE pairing security, or validate your firmware signing chain. If your module lacks Annex I Part I security features (secure defaults, encryption, authentication), engineering work is needed before documentation can accurately reflect compliance.

Your OEM customers will request this documentation as their own CRA deadlines approach. Having it ready makes your modules easier to specify.

Enforcement regime

Article 64 of Regulation (EU) 2024/2847.

🔴
Essential requirements + manufacturer obligations (Art. 64(2))
€15,000,000 / 2.5%

Annex I + Art. 13/14.

🟠
Documentation and conformity obligations (Art. 64(3))
€10,000,000 / 2%

Art. 28, 31, 32.

🟡
Misleading information (Art. 64(4))
€5,000,000 / 1%

Misleading information.

Alternatives

CriterionRED/CRA Joint ConsultantModule Manufacturer AssociationManual DocumentationCRACheck
Time per family4–10 weeks2–4 weeks (template)3–6 weeks15–25 minutes
Cost€8,000–€18,000Membership feeStaff time€149
Annex III classificationConsultant-dependentGeneric guidanceSelf-researchBuilt-in Annex III logic
IP exposureFirmware sharedAnonymised dataInternal100% browser-side

Dozens of module variants for EU-market OEMs?

Wireless module OEMs maintain large SKU portfolios. Each family with distinct firmware and functionality requires a separate CRA dossier. Volume pricing: €99/module (pack 10), €79/module (pack 30).

Request Volume Pricing
Modules sharing identical firmware and security architecture may be documented as a single product family.

What CRACheck guarantees and what it does not

CRACheck generates a structured document aligned with Article 31 and Annex VII of Regulation (EU) 2024/2847 based on your module data. The accuracy is your responsibility as manufacturer.

We guarantee the structure follows Art. 31 + Annex VII and legal references are correct. We do not guarantee acceptance by a market surveillance authority or notified body in a specific case.

CRACheck is not legal advice. For CRA-RED interface questions, Annex III classification, or harmonised standard coverage, consult a specialised attorney.

Frequently asked questions

Is a WiFi module a "network interface" under Annex III?
Annex III Class I item 10 lists "physical and virtual network interfaces." A WiFi module that enables a device to connect to a network meets this definition. CRACheck's classifier evaluates your module's primary function against all applicable Annex III categories to determine the correct classification.
Who is the CRA manufacturer — us or the OEM using our module?
Both. Article 3(13) defines the manufacturer as whoever develops or manufactures the product and markets it under their name. If you sell the module under your brand, you are the manufacturer of the module. Your customer is the manufacturer of the final product. Each has independent obligations under Article 13.
Does RED compliance reduce our CRA obligations?
No. The Radio Equipment Directive and the CRA are separate legal instruments with distinct requirements. RED covers radio spectrum, EMC, and specific cybersecurity requirements for radio equipment. The CRA adds broader cybersecurity documentation (Annex VII), vulnerability handling (Art. 14), and essential requirements (Annex I) that RED does not fully address.
Do we need SBOM for a wireless module?
The technical documentation under Annex VII point 2 requires description of the design, development, and production processes. This includes identifying software components and dependencies. CRACheck structures the SBOM information within the Technical Documentation output.
Is this a subscription?
No. One-time payment. 30 days editing, 10 regenerations. PDF yours permanently.
Can I request a refund?
Under Article 16(m) of Directive (EU) 2011/83, licence activation constitutes express consent for immediate digital content generation. Refunds only for reproducible technical failures.
What if the regulation is amended?
Regenerate at no additional cost during licence validity.
⚠️ Important notice: CRACheck is a self-assessment documentation tool, not legal advice and not a third-party audit. The document under Article 31 and Annex VII of Regulation (EU) 2024/2847 is generated from your input data. You are responsible for the accuracy of the data you provide. CRACheck does not replace a qualified professional assessment.

Your module connects thousands of EU products to the network. Document it at the source.

Eight documents. Article 31 + Annex VII fully structured. Regulation (EU) 2024/2847. Your data stays on your device. The ZIP you download is yours forever.

€149 one-time
8-document professional dossier · 15–25 minutes · No subscription · Browser-side
Generate CRA dossier — €149
✓ Last regulatory check: 1 May 2026 · No substantive changes detected · View history