In scope, default category ยท Regulation (EU) 2024/2847

Are CMS plugins and themes in scope of the EU CRA?

Verified against the Official Journal text on

In scope when supplied commercially (Art. 3(1), Art. 3(22))

Usually yes. A plugin, extension, or theme that contains code is installable software, so it is a product with digital elements, and supplying it to EU users in the course of business is making it available on the market, whether paid or free. Most plugins are default-category products that can self-assess. The genuine judgment zone is a free plugin whose real purpose is to funnel users to a paid service or upsell: the recitals treat an intention to monetise, including through a platform monetising other services, as a marker of commercial activity, so "free" does not settle it.

Basis: Art. 3(1), Art. 3(22), Recital 15

Judgment call: Whether a free plugin that drives paid services is supplied in the course of a commercial activity is a judgment the recitals frame but do not fully settle; assess the intention to monetise.

A plugin or theme with code is a product Art. 3(1), Art. 2(1)

The CRA reaches products with digital elements made available on the market, which includes software the user installs. A CMS plugin, an app for a commerce platform, or a theme that ships executable code is installed into a site and almost always connects, so it fits the definition of a product with digital elements. Distributing it to EU users through a marketplace is supply on the Union market.

A theme that is purely static styling with no code is a weaker case, but the moment a theme or plugin carries logic, update mechanisms, or integrations, it behaves like the software product it is. Agencies and plugin shops that assumed this was outside their world are the common surprise here.

Free does not mean out of scope Art. 3(22), Recital 15

Making available on the market covers supply for distribution or use in the course of a commercial activity, in return for payment or free of charge. A free plugin that is part of your commercial activity is in scope just as a paid one is, so a large free tier does not put you outside the CRA by itself.

The recitals describe commercial activity broadly, including an intention to monetise, for instance through a platform through which the maker monetises other services. A free plugin whose purpose is to sell a paid upgrade, a subscription, or a hosted service is the paradigm case where "free" does not take you out.

Judgment call: The dividing line between a non-commercial free plugin and a free plugin that funnels paid services is a facts-and-intention judgment, not a bright-line rule.

The manufacturer programme and the dates Art. 13, Art. 3(2), Art. 71(2)

If your plugin, extension, or theme is in scope, you are its manufacturer. You build to the essential cybersecurity requirements, handle vulnerabilities during the support period (including a coordinated vulnerability disclosure policy), draw up technical documentation, run the conformity assessment, and affix the CE marking. Most plugins are default-category, so self-assessment is generally available.

Where the plugin depends on a backend you develop, that backend can come into scope with it as a remote data processing solution. Reporting duties start 11 September 2026 and the full obligations apply from 11 December 2027.

What you must do

  • Design, develop, and produce the plugin or theme in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities during the support period, including a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Draw up technical documentation, carry out conformity assessment, and affix the CE marking. (Art. 13(12), Art. 32)
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

We give our plugin away free on the marketplace. Are we in scope?

Quite possibly. Making available on the market covers supply in the course of a commercial activity whether paid or free. If the free plugin is part of your commercial activity, for instance to sell a paid tier, it is in scope. (Art. 3(22), Recital 15)

Our agency builds custom plugins for clients. Who is the manufacturer?

Whoever supplies the plugin under their own name carries the manufacturer obligations. If you develop and supply it, that is you; if you put your client's name on it, the roles may shift. Map each delivery to a role before deciding. (Art. 3(13), Art. 13)

Is a code-free theme in scope?

A theme that is purely static styling with no executable code is a weak case for being a product with digital elements. The moment it ships logic, integrations, or update mechanisms, it behaves like installable software and is likely in scope when supplied commercially. (Art. 3(1))

See where your plugin or theme lands

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes, including the commercial-activity question that decides whether a free plugin is in or out of scope.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.