CRA-readiness evidence, reports and controlled follow-up for connected-product teams
PAXECTReadiness
Home / CRA Knowledge Hub / Product suitability
Product suitability / Scanner Box fit

Product suitability: choose the right PAXECT Readiness route

Not every connected product, or product with digital elements, fits the same PAXECT Readiness route. This article helps importers, manufacturers and connected-product teams assess whether their product belongs in the Scanner Box workflow, evidence review / supplier follow-up, staged validation, or specialist review.

First decide the right route

Product suitability should be assessed before a connected product is placed into the PAXECT Readiness Scanner Box workflow or another route. Not every product fits the same route, and the first decision is whether the product context, available access, supplier information and review objective support a standard Scanner Box fit.

A connected product with suitable technical access may fit the Scanner Box route. A product with limited access, missing firmware, supplier-managed software or unclear product cybersecurity evidence may need evidence review / supplier follow-up instead.

Some product categories may need staged validation, while sectors or use cases outside standard scope may need specialist review / outside standard scope before they should be treated as a standard PAXECT Readiness route.

Where the route decision fits in the workflow

Product suitability is the first workflow decision because it determines how a connected product, or a product with digital elements, should enter PAXECT Readiness. Importers, manufacturers and connected-product teams need to understand whether the product has enough available technical access for a Scanner Box fit, whether product cybersecurity evidence needs to be reviewed first, or whether the product should be routed to staged validation or specialist review.

The route decision affects what evidence should be collected and how that evidence is handled later. If the Scanner Box route is appropriate, technical evidence can be collected or reviewed in a structured way. If direct access is limited, supplier evidence, firmware information, support-period context, update information or vulnerability-handling context may need evidence review and supplier follow-up before a technical route is chosen. If the product category is still being validated, staged validation keeps the review controlled instead of presenting the product as standard scope. If the sector, product risk or use case sits outside standard scope, specialist review / outside standard scope is the more responsible route.

Scanner Box technical evidence Readiness Report Evidence Dossier Supplier Requests Remediation Guidance customer-approved remediation / Managed Remediation validation audit and proof context

This matters for connected-product CRA-readiness because later records depend on the starting route. A Readiness Report should reflect the route used to collect or review evidence. An Evidence Dossier should keep product context, supplier information and review status connected. Supplier Requests should follow from the evidence gaps that were actually identified. Remediation Guidance, customer-approved remediation / Managed Remediation, validation and audit and proof context should remain tied to the product-fit decision rather than becoming disconnected follow-up work.

This section gives the workflow context for the product suitability decision. For the full process, readers can continue with How it works, Reports & Evidence, Remediation Guidance, the CRA Knowledge Hub or the related evidence-to-follow-up article.

Four product suitability routes

This article uses four product suitability routes to determine whether a connected product or product with digital elements belongs in the PAXECT Readiness Scanner Box workflow, an evidence review / supplier follow-up route, staged validation, or specialist review. The route depends on product context, available access, supplier evidence, product cybersecurity evidence and product risk, so importers, manufacturers and connected-product teams do not have to force every product into the same workflow.

Route 1

Scanner Box fit

Best fit when: technical evidence can be collected or reviewed safely for a connected product or product with digital elements. Product context, file access, firmware, software, app evidence or network-facing evidence supports a standard PAXECT Readiness route.

Next step: enter the Scanner Box workflow while keeping product cybersecurity evidence connected to later review, reporting and validation.

Route 2

Evidence review / supplier follow-up

Best fit when: direct technical access is limited or supplier-held evidence is needed first. Firmware may be unavailable, documentation may be incomplete, cloud behaviour may be supplier-managed, or vulnerability-handling context may need clarification.

Next step: review available evidence, identify missing product cybersecurity evidence and prepare supplier follow-up before choosing a Scanner Box route.

Route 3

Staged validation

Best fit when: the product category may be relevant to connected-product CRA-readiness but should not yet be treated as standard Scanner Box scope. The category, access method or evidence type still needs validation.

Next step: keep the product on a controlled validation path instead of overstating support or forcing it into the wrong workflow.

Route 4

Specialist review / outside standard scope

Best fit when: the product, sector or use case needs a different assurance path before it should be handled as standard PAXECT Readiness scope. Product risk, sector requirements, safety impact or operational context may make specialist review more appropriate.

Next step: treat the product as outside standard scope and use specialist review to decide whether product cybersecurity evidence can still be structured appropriately.

Scanner Box fit

Scanner Box fit is possible when technical evidence for a connected product, or product with digital elements, can be collected or reviewed in a controlled way. The route depends on the product context, available access, evidence availability and whether the review can be handled safely within the PAXECT Readiness workflow.

Typical fit indicators may include firmware, embedded software, network-facing evidence, app or APK evidence, software inventory, supplier-managed software components, update information, support-period evidence and other technical data suitable for structured CRA-readiness review.

Scanner Box fit does not mean that every connected product qualifies. If access is missing, supplier evidence is incomplete, or the product category is not yet validated, the product should move to evidence review / supplier follow-up or staged validation instead of being forced into the Scanner Box route.

When the route is appropriate, Scanner Box evidence can support Readiness Reports, Evidence Dossier creation, Supplier Requests, Remediation Guidance, customer-approved remediation workflows, validation, audit trail and proof context.

Evidence review / supplier follow-up

Some connected products may not be suitable for direct Scanner Box evidence collection. That does not mean the product should be ignored; it may still need structured evidence review, supplier follow-up and product cybersecurity evidence for CRA-readiness work.

Evidence review / supplier follow-up is useful when direct device access is limited, firmware is unavailable, supplier documentation is the main evidence source, or the product with digital elements depends on supplier-managed software, cloud behaviour, software components or external update processes.

This route helps importers, manufacturers and connected-product teams structure available supplier evidence, identify missing information, prepare supplier questions and define the next review or remediation step. Typical evidence gaps may involve vulnerability handling, support-period evidence, update evidence, component context or unclear supplier responsibilities.

This route supports CRA-readiness work without claiming CRA compliance or certification. If the missing evidence is resolved later, the product may move toward Scanner Box review or another suitable route; if not, it should remain in evidence review, staged validation or specialist review.

Staged validation

Staged validation is used when a product category, access method, evidence type or review path is relevant to PAXECT Readiness but is not yet a standard Scanner Box route. It gives importers, manufacturers and connected-product teams a controlled validation path before a product is treated as standard scope.

Android APK/app evidence may be available where enabled and validated as an expanded evidence route. Physical Android device setups and other product-specific evidence paths may still require staged validation before they should be handled as standard Scanner Box scope.

Wireless-only evidence paths such as BLE, embedded or RTOS-style environments, Windows EXE/MSI software-package evidence and iOS app-package evidence should be treated as future or expanded review paths unless they have been enabled and validated for that product route.

Staged validation prevents overstating support while keeping the product on a reviewable path. Depending on the result, the product may later move toward Scanner Box review, evidence review / supplier follow-up or specialist review.

Specialist review / outside standard scope

Some products, sectors or use cases should not be handled as standard Scanner Box scope. Specialist review / outside standard scope is the product suitability route for a connected product or product with digital elements when sector rules, safety impact, operational risk, certification duties or assurance requirements sit outside the normal PAXECT Readiness route.

Outside-standard-scope signals may include regulated sectors or safety-sensitive products such as medical devices, automotive systems, aviation, defence, payment systems, high-risk OT/ICS, critical infrastructure or safety-critical machinery. These examples are signals for sector-specific assessment, not claims that those domains are standard supported routes.

PAXECT may help structure available product cybersecurity evidence where appropriate for CRA-readiness discussions, but it does not certify the product, approve sector suitability, replace legal review, replace formal conformity assessment or act as a notified body or sector specialist. Responsibility for sector-specific certification, safety assurance, legal assessment and market placement decisions remains with the relevant manufacturer, importer, distributor or specialist adviser.

Official CRA context: see the European Commission’s Cyber Resilience Act summary and the EUR-Lex text of Regulation (EU) 2024/2847. These sources provide official regulatory context; PAXECT does not replace legal review, formal conformity assessment, sector-specific certification, notified body work, safety assurance or specialist security assessment.

Which route fits your product?

Product suitability depends on the product type, available access, supplier information and the review objective.

A connected product may fit the Scanner Box route, evidence review / supplier follow-up, staged validation or specialist review / outside standard scope.

Request an early readiness review to identify the right starting route.

FAQ

Does every connected product fit the Scanner Box workflow?

No. Product suitability depends on the product type, available access, supplier information and the review objective. Some products fit Scanner Box review, while others need evidence review / supplier follow-up, staged validation or specialist review.

Can PAXECT still help if the product cannot be scanned directly?

Yes. If direct technical access is limited, the product may still fit an evidence review / supplier follow-up route. This helps structure available supplier evidence, identify missing information and prepare the next review step.

When is staged validation the right route?

Staged validation is used when a product category, access method or evidence type is relevant but not yet standard Scanner Box scope. It keeps the product on a controlled validation path instead of forcing it into the wrong workflow.

What happens if the product is outside standard scope?

The product may need specialist review before it is handled as a standard route. This can apply when sector rules, safety impact, operational risk or assurance requirements require a separate assessment path.

Check which route fits your connected product.

Request an early product-fit review to see whether your product fits the Scanner Box route, evidence review / supplier follow-up, staged validation or specialist review / outside standard scope.