Remote data processing test ยท Regulation (EU) 2024/2847

Are APIs and backends in scope of the EU CRA?

Verified against the Official Journal text on

Depends on the remote data processing test (Art. 3(2), Recital 11)

It depends on two functional tests. An API or backend is in scope of the CRA as a remote data processing solution when it is developed by you, or under your responsibility, and a function of your product with digital elements would not work without it. The recitals give the example directly: a mobile app that needs an API or database provided by a service the manufacturer developed pulls that service into scope. A purely third-party backend outside your responsibility, or a standalone cloud service that no product with digital elements depends on, is different, and cloud service models themselves sit under the NIS2 Directive instead.

Basis: Art. 3(1), Art. 3(2), Recital 11, Recital 12

Judgment call: Both "under the responsibility of the manufacturer" and "would prevent one of its functions" are functional tests with no bright line. If either is close for you, treat it as a point to verify and document your reasoning.

What "remote data processing" means Art. 3(1), Art. 3(2), Recital 11

A product with digital elements is a software or hardware product plus its remote data processing solutions. Remote data processing is defined as data processing at a distance where the software is developed by the manufacturer, or under the manufacturer's responsibility, and the absence of which would prevent the product from performing one of its functions.

The point of that definition is to secure a product in its entirety, whether data is processed on the user's device or remotely. So an API or backend is not automatically outside the CRA just because it runs in the cloud; the question is what it is attached to and who is responsible for it.

The two tests, both judgment calls Art. 3(2), Recital 11

First test: is the backend developed by you, or under your responsibility? A service you build, run, or commission is yours. A genuinely independent third-party service that you merely call is not, even if your product would break without it. That distinction is doing a lot of work and deserves careful thought.

Second test: would a function of the product fail without the backend? Processing or storage at a distance is in scope only in so far as it is necessary for the product to perform its functions. A backend that only powers analytics or an unrelated internal system is a weaker case than one your product cannot function without.

Judgment call: Neither test has a bright-line rule in the CRA text. The recitals illustrate the paradigm case (a mobile app needing the manufacturer's API) but leave the edges to interpretation.

When a backend stays out of scope Recital 12, Art. 3(2)

The recitals are explicit that websites which do not support the functionality of a product with digital elements, and cloud services designed and developed outside the responsibility of a product's manufacturer, do not fall within scope. Directive (EU) 2022/2555 (NIS2) applies to cloud computing services and to service models such as SaaS, PaaS, and IaaS.

So a standalone API product that no product with digital elements depends on, or a backend you consume from a genuinely separate provider, is not pulled in by this route. Map each backend to the product it serves before deciding.

What in-scope status means for a backend Art. 13, Art. 14, Art. 71(2)

Where a backend is in scope, it is treated as part of the product, so the manufacturer obligations cover it together with the software or hardware it serves. In practice that means the essential requirements, vulnerability handling, technical documentation, and reporting all extend to the backend, on the same timeline as the product. Reporting duties start 11 September 2026 and the full obligations apply from 11 December 2027.

What you must do

  • Where the backend is in scope, design, develop, and produce it (with the product) in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities across the product and its in-scope backend during the support period, including a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
If your backend is in scope with a product, reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply to the product and its in-scope backend: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

We sell an API product on its own. Is it in scope of the CRA?

A standalone cloud service that no product with digital elements depends on is not pulled in as a remote data processing solution, and cloud service models sit under NIS2. If an installable product of yours needs the API to function, that changes the picture. (Recital 12, Art. 3(2))

Our mobile app calls our own backend API. Does the backend fall under the CRA?

Very likely yes. The recitals give this exact example: a mobile app that needs an API or database from a service the manufacturer developed pulls that service into scope as a remote data processing solution, together with the app. (Art. 3(2), Recital 11)

What about a third-party backend we do not control?

A cloud service designed and developed outside the responsibility of your product's manufacturer does not fall within scope through this route. The test is responsibility, not merely whether your product depends on the service. (Recital 12, Art. 3(2))

Work out whether your backend is in scope

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes, including the remote data processing question that decides whether your backend comes in with the product.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.