A company that sells software as a service usually reads the Cyber Resilience Act first, finds that a web application "accessed exclusively through a web browser" is not a product with digital elements, and stops. The law that does reach it is the other one. Directive (EU) 2022/2555 lists cloud computing service providers in Annex I, under digital infrastructure, and its recital 33 says what a cloud computing service is in terms that name the business model outright. This article is what that means for a SaaS company, in the order the duties arrive.
The definition names SaaS
Article 6(30) defines a cloud computing service as "a digital service that enables on-demand administration and broad remote access to a scalable and elastic pool of shareable computing resources, including where such resources are distributed across several locations". Recital 33 fills the terms in: computing resources "include resources such as networks, servers or other infrastructure, operating systems, software, storage, applications and services"; "the service models of cloud computing include, inter alia, Infrastructure as a Service (IaaS), Platform as a Service (PaaS), Software as a Service (SaaS) and Network as a Service (NaaS)"; the terms have the meaning of ISO/IEC 17788:2014; "on-demand administration" is the customer's ability to provision without a human on the provider's side, "broad remote access" is access over the network from thin or thick clients, "scalable" and "elastic" describe resources allocated and released with demand, and "shareable" describes resources "provided to multiple users who share a common access to the service, but where the processing is carried out separately for each user".
A multi-tenant application that customers sign up to, use from a browser and scale their own usage of is that definition. The corner cases are the ones where a term fails: a single-tenant deployment provisioned by hand for one customer is not on-demand and not shareable; a product the customer installs and runs is software, not a service, and is the CRA's. The row in Annex I is the one the scope determination asks about first, and it is verbatim there in six languages.
Size decides which kind of entity you are
Being of a listed type is the first condition of Article 2(1); the second is size. The Directive applies to entities that "qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC, or exceed the ceilings for medium-sized enterprises": 50 staff or more, or above EUR 10 million in both turnover and balance sheet, counted for the enterprise together with its partner and linked enterprises. A SaaS company at that size is an important entity under Article 3(2). One that exceeds the medium ceilings, 250 staff or both EUR 50 million turnover and EUR 43 million balance sheet, is an essential entity under Article 3(1)(a), because cloud computing is an Annex I type and Annex I types are essential by size alone. Below the small ceiling the company is outside, unless its member state identifies it under Article 2(2)(b) to (e); its customers will still ask for the supply-chain evidence Article 21(2)(d) makes them collect. The rules, in order, with the seven ways to be essential, are their own article.
One state's law, decided by where the decisions are taken
For a cloud computing service provider, Article 26(1)(b) places jurisdiction with the member state of the main establishment in the Union, and Article 26(2) says that is "the Member State where the decisions related to the cybersecurity risk-management measures are predominantly taken", or, failing that, where the security operations are carried out, or, failing that, where the establishment with the highest number of employees is. Customers in other member states change nothing. A SaaS company established outside the Union that offers the service in it designates a representative in a member state where it offers the service and is under that state's jurisdiction (Article 26(3)); without one, any member state where it provides the service may act against it.
That state's transposing act is the one that names the competent authority, the registration route, the notification form and the fine ceilings. Which act each state has communicated to the Commission, and which states have communicated none, is on the register page, read from the Commission's own records.
The registry
Article 27 makes ENISA keep a registry of, among others, cloud computing service providers, from information the entities submit to their competent authority: the name, the sector and subsector, the address of the main establishment and other establishments in the Union or of the representative, contact details, the member states where the service is provided, and the IP ranges. The deadline in Article 27(2) was 17 January 2025, and changes must be notified within three months. A SaaS company of the size above that has not registered is late, not exempt; the register page names the state's act, and the act names the portal.
The measures are uniform, and they are ISO 27001
For cloud computing service providers, Article 21(2)'s ten measures are not left to the member state. Implementing Regulation (EU) 2024/2690 applies to them directly, its Article 1 naming cloud computing service providers among "the relevant entities", and its Annex sets the technical and methodological requirements of each measure in 13 sections, the same text in every state. The Regulation's recital 3 says where those sections come from: European and international standards, ISO/IEC 27001 among them. The mapping page places each section against the ISO 27001 controls that satisfy it and names the two places it asks for more than an ISMS gives.
Incidents: four thresholds, three clocks
The same Regulation decides when a SaaS company's incident is significant, and it replaces judgment with numbers. Article 3(1) applies to every relevant entity: a direct financial loss above EUR 500 000 or 5 % of annual turnover, whichever is lower; the exfiltration of trade secrets; death or considerable damage to health; a successful, suspectedly malicious and unauthorised access capable of causing severe operational disruption. Article 7 adds four for cloud computing service providers: the service completely unavailable for more than 30 minutes; availability limited for more than 5 % of the service's users in the Union or more than 1 million of them, whichever is smaller, for more than one hour; the integrity, confidentiality or authenticity of stored, transmitted or processed data compromised by a suspectedly malicious action; or compromised with an impact on more than 5 % or more than 1 million of the users in the Union, whichever is smaller. Scheduled maintenance is excluded (Article 3(2)), and users are counted as contracted customers plus the natural and legal persons associated with business customers who use the service (Article 3(3)).
A significant incident starts Article 23's clocks: an early warning within 24 hours of becoming aware, a notification within 72 hours, a final report within one month, to the CSIRT or the competent authority as the state's act provides. The clocks, beside the CRA's, and the thresholds quoted in full are their own article; half an hour of complete unavailability is a notifiable incident with no further judgment, which is a fact worth putting in front of whoever owns your status page.
The line to the CRA
The Cyber Resilience Act reaches products with digital elements. The Commission's guidance on the Regulation, C(2026) 5252 of 27 July 2026, says at paragraph 21 that software "that executes remotely and is merely accessed by the user is not, on that basis alone, a product with digital elements", which is "typically the case for web applications, including progressive web apps, where they are accessed exclusively through a web browser". The service is NIS2's. The exception is a SaaS company that also ships something installed, a desktop client, a mobile app, an agent, an SDK: that is a product, and the cloud behind it is remote data processing under Article 3(2) of the CRA where a function of the product fails without it. Which law reaches which part and which parts of the backend are inside the CRA are the two articles for that company; the incident record is then one record with two forms.
What to do this quarter
Write the determination down, with the articles: the Annex I row, the size class as counted, the state of main establishment, important or essential. The scope tool writes it from five answers. Check the registration against the state's portal and the Article 27 fields, and the date it was made. Map what the ISMS already has against the Regulation's 13 sections, and close the two gaps the mapping names. Put the four Article 7 thresholds and the "became aware" rule into the incident procedure, with who files and where, before the first incident tests it.
Sources
- Directive (EU) 2022/2555 (NIS2), Article 2(1) and (2), Article 3(1) and (2), Article 6(30), Article 21(2), Article 23(4), Article 26(1) to (3), Article 27(1) to (3), Annex I point 8, recital 33.
- Commission Implementing Regulation (EU) 2024/2690, recital 3, Article 1, Article 3, Article 7, Annex.
- Regulation (EU) 2024/2847 (CRA), Article 3(1) and (2), recital 12; Commission guidance C(2026) 5252, paragraphs 20 and 21.
- Commission Recommendation 2003/361/EC, Annex, Articles 2 and 3.
This is not legal advice. The member state's act names the authority, the portal and the form, and may add categories under Article 2(2)(b) to (e).