Three questions. You get the dates that apply to your product and the legal basis for each one.
No email, no sign-up, nothing stored. The dates come from the regulations themselves — the same engine behind our full CRA assessment.
Step 1 of 4
Is your product covered by a medical device certificate under the EU MDR or IVDR?
Regulation (EU) 2017/745 or 2017/746.
Result
The CRA does not apply to that device.
Cyber Resilience Act, Article 2(2): products with digital elements covered by Regulation (EU) 2017/745 or (EU) 2017/746 are excluded from the scope of this Regulation.
Your cybersecurity obligations for the device itself run through the MDR/IVDR route and MDCG 2019-16, not through the CRA. That is the answer most tools get wrong.
Where the CRA still reaches you: anything you ship that is not inside that certificate. A companion or dashboard app that is not itself a regulated device. A wellness or dual-use product line. An accessory sold separately and outside the scope of the certificate. Each of those is a product with digital elements in its own right, and the CRA dates apply to it.