In scope, default category ยท Regulation (EU) 2024/2847

Is a browser extension in scope of the EU CRA?

Verified against the Official Journal text on

In scope, default category (usually) (Art. 3(1), Art. 2(1))

Yes. A browser extension is software the user installs, so it is a product with digital elements, and distributing it to EU users in the course of business is making it available on the market. Most extensions are default-category products and can self-assess. An extension is very likely not itself a "standalone or embedded browser" under the listed important category, but an extension whose core functionality matches another listed category (for example a password manager or a VPN) would be an important product, with a stricter conformity route. Where the extension relies on a backend you develop, that backend can come into scope with it.

Basis: Art. 3(1), Art. 2(1), Annex III Class I (2)

Judgment call: Whether an extension is a "browser" or "has the core functionality of" any listed category is a classification judgment; the technical descriptions in Implementing Regulation (EU) 2025/2392 control.

An extension is installable software Art. 3(1), Art. 2(1), Art. 3(22)

The CRA reaches products with digital elements made available on the market, which includes software the user downloads or installs. A browser extension is exactly that: code installed into the browser, almost always with a data connection. Publishing it to an extension store where EU users can obtain it is supply on the Union market.

Making available on the market covers supply in the course of a commercial activity, paid or free. A free extension that supports a commercial product is in scope just as a paid one is, so "we do not charge for it" is not the deciding factor.

Is an extension a "browser" under Annex III? Annex III Class I (2), Art. 7(1), Art. 7(4)

Annex III lists "standalone and embedded browsers" as an important product category in Class I. An extension adds functionality to a browser rather than being one, so it is very likely not itself caught by that item. That is a reasoned reading, not a certainty: the technical descriptions in Implementing Regulation (EU) 2025/2392 control what falls inside each category.

The safer approach is to look at the extension's own core functionality against the whole of Annex III, rather than assuming the browser item settles the question. Record the reasoning for whichever way you land.

Judgment call: Whether an extension counts as a browser, or as any listed category, is not spelled out in the CRA text itself. The implementing act's technical descriptions decide it.

When an extension is an important product Art. 7(1), Art. 32(2), Annex III

The category that bites is core functionality, not packaging. An extension whose core function matches a listed important category (a password manager, an identity or access management tool, a VPN, or anti-malware) is an important product, and its conformity route narrows accordingly. A general utility extension usually stays in the default category.

If your extension's whole reason to exist is one of those security functions, treat it as flagged and resolve the classification against the implementing act before choosing a conformity route.

Backend, obligations, and dates Art. 3(2), Art. 13, Art. 71(2)

Where the extension needs a backend you develop, or that is developed under your responsibility, and the extension cannot perform a function without it, that backend is in scope as a remote data processing solution. As manufacturer you meet the essential requirements, handle vulnerabilities, document, assess conformity, and CE mark. Reporting starts 11 September 2026; full obligations from 11 December 2027.

What you must do

  • Design, develop, and produce the extension in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities during the support period, including a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Draw up technical documentation, carry out conformity assessment, and affix the CE marking. (Art. 13(12), Art. 32)
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

Our extension is free on the store. Is it in scope of the CRA?

Very likely yes. Making available on the market covers supply in the course of a commercial activity whether paid or free, so a free extension tied to your commercial product is in scope just as a paid one would be. (Art. 3(22), Recital 15)

Is a browser extension an important product because Annex III lists browsers?

Probably not on that basis. An extension adds to a browser rather than being one, so the browser item very likely does not catch it. But an extension whose core functionality is a listed category, such as a password manager, would be important. (Annex III Class I (2), Art. 7(1))

The extension talks to our own server. Does that pull the server in?

It can. Where the extension cannot perform a function without a backend you develop or are responsible for, that backend is in scope as a remote data processing solution, together with the extension. (Art. 3(2), Recital 11)

See where your extension lands

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes, including the core-functionality question that decides whether your extension is a default or an important product.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.