[{"data":1,"prerenderedAt":10},["ShallowReactive",2],{"article:en:is-your-product-in-scope-of-the-cyber-resilience-act":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"body":9},"en","is-your-product-in-scope-of-the-cyber-resilience-act","Is your product in scope of the Cyber Resilience Act? Where SaaS sits","The most-asked CRA question is not how to report, it is whether the Regulation applies to you at all. Pure software as a service is out and inside NIS2; installed and downloadable software is in; remote processing a product cannot work without is back in. The determination is yours to make and record. Here is the text that decides it.","2026-09-11","\nBefore any of the Cyber Resilience Act's deadlines matter, there is a question that comes first, and every FAQ on the subject shows it is the one people actually ask: does this apply to me? A software company that sells subscriptions to a web application, a firm that ships a device with firmware in it, a developer who publishes a library, a consultancy that builds custom software for one client: each of them has a different answer, and the Regulation, Regulation (EU) 2024\u002F2847, decides it in about three places.\n\nThis article walks through those places. It does not tell you whether your product is in scope, because that determination depends on what you actually place on the market, and it is yours to make and, more to the point, to record.\n\n## The definition: Article 3(1)\n\nThe Regulation applies to a **product with digital elements**, defined in Article 3(1) as \"a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately\".\n\nThree things are in that sentence.\n\n**Software counts on its own.** A product with digital elements does not need to be a physical thing. An application you install, a mobile app, a desktop program, an operating system, a library, a firmware image: each is a software product, and each can be placed on the market on its own.\n\n**Components count on their own.** A library or a module sold or supplied separately is a product in its own right, with its own manufacturer.\n\n**Remote data processing solutions come with the product.** This is the clause that pulls some cloud back into scope, and it is defined in the next paragraph.\n\n## The connection condition: Article 2(1)\n\nArticle 2(1) narrows the definition to products \"whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network\".\n\nThat condition is wide. It is not \"connected to the internet\". A device that is never online but is updated by plugging it into a computer over USB has a physical data connection to a device, and that is enough. A German developer selling firmware for an off-the-shelf handheld described exactly this situation on Hacker News in August 2026: offline, no wireless, no network stack compiled in, updates by reflashing over a cable, and in scope, which they found out by reading the Regulation and the Commission's guidance themselves. Nobody thinks of themselves as a \"manufacturer of a product with digital elements\" until they discover they are one.\n\n## Where SaaS sits: Recital 12 and Article 3(2)\n\nThis is the question most software companies are really asking, and the answer has two halves.\n\n**Pure software as a service is outside the CRA.** Recital 12 says that cloud service models such as software as a service are not products with digital elements, because they are services rather than products placed on the market, and they are covered instead by the NIS2 Directive, Directive (EU) 2022\u002F2555. If what you sell is access to an application that runs on your infrastructure, and nothing is installed or downloaded on the customer's side, the CRA does not reach you. NIS2 may, depending on your size and sector, but that is a different regulation with a different shape.\n\n**Remote processing that a product cannot function without is inside.** Article 3(2) defines **remote data processing** as data processing at a distance \"for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the product with digital elements from performing one of its functions\". Recital 12 makes the same point: cloud components are covered when they are part of the product in this sense.\n\nSo a smart lock with a mobile app and a cloud back end is one product with digital elements, back end included, because without the back end the lock cannot perform its functions. A desktop application that phones home to a licence server is a product whose remote data processing is in scope. A web application with no installed component is a service.\n\nThe line is not \"do you have a cloud\". It is \"is there a product placed on the market, and does the cloud do something that product cannot do without\". Where a product is both, the installed part is in scope and its essential remote processing comes with it. Which parts of the cloud come in, module by module, with the Commission's two tests and its mobile banking example, is [its own article](\u002Farticles\u002Fwhich-parts-of-your-backend-are-inside-the-cra-remote-data-processing).\n\n## What is out, by name: the rest of Article 2\n\nThe Regulation excludes products already covered by sector-specific rules with their own cybersecurity requirements: medical devices under Regulations (EU) 2017\u002F745 and 2017\u002F746, civil aviation under Regulation (EU) 2018\u002F1139, motor vehicle type approval under Regulation (EU) 2019\u002F2144, and marine equipment under Directive 2014\u002F90\u002FEU. It also excludes products developed or modified exclusively for national security or defence purposes, and products designed specifically to process classified information.\n\nSpare parts made available to replace identical components, manufactured to the same specifications, are excluded too.\n\n## Open source: covered, but differently\n\nFree and open-source software that is not monetised is largely outside the manufacturer obligations, and Article 24 creates a separate, lighter regime for **open-source software stewards**: foundations and organisations that support the development of open-source products intended for commercial activities. The reporting duty in Article 14 reaches stewards for the products they steward, which is why the deadlines apply to them as well as to manufacturers. If you make a commercial product out of open-source components, you are the manufacturer of that product, and the components' licence does not change that.\n\n## Placed on the market, and the date question\n\nEvery obligation hangs on the product being **placed on the market**, the first making available of a product on the Union market. Internal tools you build and run for yourself are not placed on the market. Software you supply to one customer is.\n\nThe dates matter for products that are already out there. The Regulation applies in full from 11 December 2027, and under Article 69 products placed on the market before that date are subject to the requirements only if they are substantially modified afterwards. The reporting duty in Article 14 is the exception: it has applied since 11 September 2026, and it reaches products that were already on the market. There is no size threshold and no small-company exemption anywhere in the text; what the Regulation does for small manufacturers is [make size a factor in the fine and let them file simplified documentation](\u002Farticles\u002Fcyber-resilience-act-penalties).\n\n## Default, important, critical\n\nOnce a product is in scope it falls into one of three tiers, and the tier decides how conformity is assessed rather than whether the obligations apply. The default tier is self-assessment. **Important** products are listed in Annex III in two classes: class I includes password managers, VPN products, operating systems, routers and browsers; class II includes hypervisors, firewalls and tamper-resistant microprocessors, and its conformity assessment involves a third party. **Critical** products in Annex IV, such as hardware devices with security boxes, smart meter gateways and smartcards, may be required to obtain a European cybersecurity certificate. If your product is not on either list, it is default, and the reporting duty applies to it exactly as it does to the others.\n\n## The thing to actually do\n\nWrite the determination down. One page: what you place on the market, whether it is software, hardware or both, whether it has remote data processing in the Article 3(2) sense, which exclusion in Article 2 you rely on if you rely on one, and which tier it falls in. Date it and sign it.\n\nIf you would rather start from questions than from a blank page, [the six-question determination on this site](\u002Fcyber-resilience-act\u002Fscope) produces that one page as text, with the article for each step, and stores nothing.\n\nThat document is what you show if a market surveillance authority asks why you did or did not report, and it is what your incident procedure opens with at hour zero, when [the 24-hour clock](\u002Farticles\u002Fcra-final-report-clock-does-not-start-when-you-become-aware) is already running and nobody has time to reread Recital 12. If the answer is \"in scope\", the next question is [which CSIRT is yours](\u002Farticles\u002Fwhich-csirt-do-you-report-to-under-cra-article-14), and that one has a table.\n\nTwo questions this article leaves to the Commission's guidance, which of your builds is a product at all (a browser extension or installed client is, a web app used in a browser is not) and when a software version counts as placed on the market for the December 2027 cutoff, are answered in [the placement article](\u002Farticles\u002Fwhen-is-software-placed-on-the-market-under-the-cra-and-which-of-your-builds-is-a-product).\n\n## Sources\n\n- Regulation (EU) 2024\u002F2847, Article 2(1) to (5), Article 3(1) and (2), Article 14, Article 24, Article 69, Article 71(2), Annexes III and IV, and Recital 12.\n- European Commission, technical FAQ on the CRA, version 1.3 of 1 July 2026, chapter on scope.\n- [\"Ask HN: Is anyone else preparing for the EU Cyber Resilience Act?\"](https:\u002F\u002Fnews.ycombinator.com\u002Fitem?id=49520688), August 2026, for the offline handheld example.\n- The community FAQ at cra.orcwg.org and the FAQ at cyberresilienceact.eu, read on 8 September 2026, for which questions people ask first.\n\nThis is not legal advice, and the scope determination is the one thing on this page we will not make for you. The article references are there so you can read the text and make it yourself.\n",1789383985006]