Cyber Resilience Act
Is my product in scope of the CRA?
A qualifying walk through the definitions that decide it: product with digital elements, manufacturer, remote data processing, commercial activity and the sector exclusions. This page helps you ask the right questions; it does not make the legal determination for you.
Direct answer. The Cyber Resilience Act applies to products with digital elements — software or hardware products and their remote data processing solutions — that are made available on the EU market in the course of a commercial activity and can be connected, directly or indirectly, to a device or network (Article 2(1) and Article 3(1)). If your organisation markets such a product under its own name or brand, it is generally the manufacturer and carries the full set of obligations. Products already covered by certain sector regimes, products for national security or defence, and non-commercial open-source supply are excluded or treated differently.
Three questions settle most cases: Is it a product with digital elements? Are you the manufacturer of it? Does an exclusion apply? The sections below take each in turn, followed by the SaaS boundary that causes the most confusion.
Question 1
Is it a product with digital elements?
Article 3(1) defines a product with digital elements as a software or hardware product and its remote data processing solutions, including software or hardware components placed on the market separately. The product must be capable of a direct or indirect logical or physical data connection to a device or network — a condition that almost every modern software product and every connected device meets.
The definition is deliberately broad. It covers desktop, mobile and server software; firmware; operating systems; libraries and components sold separately; consumer devices; industrial controllers; and hardware with embedded software. It does not depend on the product being consumer-facing, on its price, or on whether it stores personal data.
| Example | Generally | Why |
|---|---|---|
| Desktop or mobile application sold or licensed to EU users | In scope | Software product, commercial activity, network connection. |
| Connected device with firmware and a companion app | In scope | Hardware with software; the app and any backend it depends on are part of the product or its remote data processing. |
| Cloud service used on its own, no shipped product | Generally out of scope of the CRA | Not a product with digital elements; cloud computing services are addressed by NIS2 where its thresholds are met. |
| Backend without which a shipped product cannot perform a function | In scope as remote data processing | Article 3(2): designed by the manufacturer, and the product depends on it. |
| Open-source library published outside any commercial activity | Out of scope | No commercial activity; steward provisions may apply to organisations that support it systematically. |
| Software inside a medical device under the MDR | Excluded from the CRA | Sector regime with its own cybersecurity requirements (Article 2(2)). |
Orientation only. Each row summarises how the definitions are commonly read; the Official Journal text and your legal advisers govern the answer for a specific product.
Question 2
Are you the manufacturer?
Obligations follow the economic operator role. The manufacturer carries most of them; importers, distributors and authorised representatives have narrower duties; open-source software stewards have a light-touch regime. The role is decided by whose name is on the product and who placed it on the market, not by who wrote the code.
| Role | Who | Main obligations |
|---|---|---|
| Manufacturer | Develops or has developed a product with digital elements and markets it under its own name or trademark, for payment, monetisation or free of charge (Article 3(13)). | Essential requirements, vulnerability handling for the support period, technical documentation, conformity assessment and CE marking, Article 14 reporting. |
| Authorised representative | A natural or legal person established in the EU with a written mandate from a manufacturer outside the EU (Article 3(14)). | Tasks specified in the mandate: keeping documentation available, cooperating with authorities (Article 20). |
| Importer | Established in the EU and places on the market a product bearing the name of a person outside the EU (Article 3(15)). | Verify conformity assessment and documentation, keep the declaration, inform the manufacturer and authorities of vulnerabilities (Article 19). |
| Distributor | Makes a product available on the market without being the manufacturer or importer (Article 3(16)). | Act with due care: verify CE marking and documentation, do not supply non-conforming products, inform on vulnerabilities (Article 20). |
| Open-source software steward | A legal person that systematically supports the development of specific free and open-source products intended for commercial activities (Article 3(14) and Article 24). | A light-touch regime: cybersecurity policy, cooperation with authorities, reporting of actively exploited vulnerabilities and severe incidents to the extent involved. |
Question 3
Does an exclusion or a sector regime apply?
Article 2 excludes products already covered by sector rules with their own cybersecurity requirements: medical devices and in-vitro diagnostics, civil aviation, motor vehicles under type approval and marine equipment. Products developed or modified exclusively for national security or defence purposes and products designed for the processing of classified information are also excluded. Spare parts made available to replace identical components and manufactured to the original specifications are outside scope.
If any of your products sits in one of these regimes, the answer is usually not “the CRA does not apply to us” but “this product line is handled under its sector regime; the rest of the portfolio is under the CRA”. Record the reasoning per product, not per company.
The SaaS boundary
Does the CRA apply to SaaS?
Short answer: a cloud service consumed on its own is generally not a product with digital elements, and cloud computing services are addressed by the NIS2 Directive where its thresholds are met. The CRA nevertheless reaches into the cloud through remote data processing: Article 3(2) defines it as data processing at a distance for which the software is designed and developed by the manufacturer, or under its responsibility, and the absence of which would prevent the product with digital elements from performing one of its functions.
In practice: a smart lock whose app and backend are required to lock and unlock, a desktop application whose licensing or sync server is needed for core features, or a device whose firmware updates and telemetry run through the manufacturer’s cloud, all bring that backend into scope as part of the product. A web application with no shipped client that customers use entirely in the browser generally does not become a CRA product because of its backend alone.
Two consequences follow. First, the vulnerability-handling requirements of Annex I Part II and the Article 14 reporting duties cover vulnerabilities in the remote data processing component as much as in the shipped binary. Second, the SBOM and the technical documentation should describe that component. Do not assume every SaaS offering is regulated, and do not assume a product’s backend is out of scope because it lives in the cloud; settle the boundary product by product and write the reasoning down.
The questions the assessment asks
What the preliminary scope assessment looks at.
- Question 1
Does your organisation develop products (software, hardware or both) that are made available in the EU?
Includes apps, desktop software, firmware, devices and components sold or licensed to EU customers.
- Question 2
Do those products contain software or connect to a network or other devices?
The CRA covers products with digital elements: software products and hardware with software, including remote data processing that the product depends on.
- Question 3
Under whose name or brand are the products placed on the market?
The manufacturer is the party that develops or has developed a product and markets it under its own name or trademark.
- Question 4
Are the products supplied in the course of a commercial activity?
Sold, licensed, bundled with paid services or otherwise monetised. Purely non-commercial open-source development is treated differently.
- Question 5
Do you substantially modify third-party products and place them on the market under your name?
A substantial modification can make you the manufacturer of the modified product.
- Question 6
Are any of your products already covered by one of these sector regimes?
Products covered by certain sector rules are excluded from the CRA or treated specially.
The outcome is one of four preliminary results — likely manufacturer, potential manufacturer, requires expert review, likely outside scope — each with the reasons behind it. It is a starting point for the conversation with your advisers and is stored in your Vellaci workspace with the reasoning, the reviewer and the date.
FAQ
Scope questions, answered carefully.
- Does the CRA apply to my software product?
- Generally yes if it is software placed on the EU market in the course of a commercial activity and it can be connected, directly or indirectly, to a device or network — that is the definition of a product with digital elements in Article 3(1). Exclusions exist for products covered by sector regimes (medical devices, civil aviation, motor vehicles, marine equipment), for products developed exclusively for national security or defence, and for non-commercial open-source supply. Whether a specific product is in scope is a determination for your organisation and its legal advisers; the official text governs.
- Does the CRA apply to SaaS?
- Not as such. A cloud service consumed on its own is not a product with digital elements; cloud computing services fall under the NIS2 Directive where they qualify as essential or important entities. The CRA does, however, cover remote data processing: data processing at a distance for which the software is designed and developed by the manufacturer and without which the product could not perform one of its functions (Article 3(2)). A device or application that depends on your backend to work brings that backend into the product's scope. Pure SaaS with no shipped product is generally outside the CRA, but the boundary depends on how the product is designed, so treat it as a question to settle explicitly, not assume.
- We build for another company's brand. Are we the manufacturer?
- The manufacturer is the party that markets the product under its own name or trademark, including products developed for it by others. The brand owner is therefore typically the manufacturer, and your obligations towards it are contractual. Substantially modifying a product and placing it on the market under your own name makes you the manufacturer of the modified product.
- Does the CRA apply to products already on the market?
- Article 14 reporting obligations have applied since 11 September 2026 to every manufacturer of products with digital elements on the EU market, regardless of when the product was placed there. The essential requirements, conformity assessment and CE marking apply from 11 December 2027 to products placed on the market from that date, and to earlier products only if they are substantially modified afterwards.
- Is open-source software in scope?
- Free and open-source software developed or supplied outside a commercial activity is out of scope. A commercial product built on open source is in scope for its manufacturer. Legal persons that systematically support open-source projects intended for commercial use may be open-source software stewards with a light-touch regime under Article 24.
- Can Vellaci tell us whether we are in scope?
- Vellaci records a preliminary scope assessment with the reasoning behind it, and the free assessment on this site gives you a preliminary outcome in eight minutes. Neither is a legal determination. What Vellaci adds is that the decision, the person who made it and the reasoning are recorded and revisable, which is what an auditor or authority will later ask for.
Last reviewed 2026-09-13 · Operational guidance, not legal advice. Article references are to Regulation (EU) 2024/2847 as published in the Official Journal.
Continue with the important and critical product categories, the CRA overview for manufacturers or the pages for software manufacturers, connected and IoT products, industrial and embedded products and network and security products.
Read next
- Guide
CRA product classification: default, important (Class I / II) and critical
How Annex III and Annex IV categories work, the core-functionality test, what changes for conformity assessment under Article 32, edge cases, and how to document a classification decision that will survive scrutiny.
- Guide
Open source and the CRA: stewards, commercial manufacturers and upstream duties
When open-source software is in scope of the Cyber Resilience Act, what the light-touch regime for open-source software stewards in Article 24 requires, and what commercial manufacturers who integrate open source must do under Article 13.
- Guide
CRA vs NIS2: products versus organisations, and how the reporting duties fit together
The Cyber Resilience Act regulates products with digital elements; NIS2 regulates essential and important entities. Many manufacturers face both. How scope, obligations and the 24-hour / 72-hour / one-month reporting steps compare, and how to run one runbook for both.
Get a preliminary answer in eight minutes.
Scope, gaps by area and a recommended next step — before any sales conversation.