For SaaS companies ยท Regulation (EU) 2024/2847

Does the CRA apply to your SaaS company?

Verified against the Official Journal text on

Partly, and the part that matters is your downloadable surface. A purely browser-based service with nothing installed is not a product with digital elements; the CRA recitals place cloud service models like SaaS under the NIS2 Directive instead (Recital 12). But the moment you ship anything a user installs, a desktop client, browser extension, mobile app, background agent, or CLI, that component is a product with digital elements in CRA scope (Art. 3(1)). A backend you develop that the component depends on comes into scope with it, as a remote data processing solution (Art. 3(2)).

Basis: Art. 3(1), Art. 3(2), Recital 11, Recital 12

Judgment call: Whether a backend is "under the responsibility of the manufacturer" and whether its absence "would prevent one of the product's functions" are functional tests with no bright line; close calls need verifying.

Pure browser SaaS is NIS2 territory, not the CRA Art. 3(1), Recital 12

A product with digital elements is a software or hardware product, something shipped, not a service consumed in a browser (Art. 3(1)). The recitals are explicit that cloud computing service models such as Software as a Service, Platform as a Service, and Infrastructure as a Service fall under Directive (EU) 2022/2555 (NIS2), not the CRA (Recital 12).

So a web app with no installable component is outside the CRA on its face. That is not a free pass: NIS2 may still reach you, and this answer flips as soon as you distribute something users install.

Inventory your downloadable surface Art. 3(1)

The practical task is to list everything you ship that a user runs on their own device or in their own browser. Each of these is, on its own, a product with digital elements and a candidate for CRA scope (Art. 3(1)). Teams routinely forget the smaller items, and the smaller items are exactly what pulls a "we are just SaaS" company into scope.

  • Desktop or native clients (Windows, macOS, Linux). (Art. 3(1))
  • Browser extensions and add-ons. (Art. 3(1))
  • Mobile apps (iOS, Android). (Art. 3(1))
  • Background agents, sync daemons, or device connectors. (Art. 3(1))
  • Command-line tools, SDKs, and libraries you distribute. (Art. 3(1))

The backend can come into scope with the client Art. 3(2), Recital 11

When a component you ship relies on a backend that you develop, or that is developed under your responsibility, and without which one of the product's functions would not work, that backend is a remote data processing solution and is in scope together with the product (Art. 3(2), Recital 11). The recital gives the worked example of a mobile app that needs an API or database provided by the manufacturer: that service is then in scope.

This does not sweep your whole cloud estate into the CRA. The requirements reach the remote data processing that a product needs to function, not the security of your corporate network as a whole (Recital 11). A third-party backend developed outside your responsibility is not yours to certify.

What in-scope components then have to do Art. 13, Art. 14, Art. 7

For each downloadable component that is in scope, you are its manufacturer and carry the full programme: essential cybersecurity requirements, vulnerability handling with a coordinated disclosure policy, technical documentation, conformity assessment, CE marking, and reporting (Art. 13, Art. 14). Check whether any component matches an important category, for example an identity or access component, because that changes the conformity route (Art. 7, Annex III).

What you must do

  • For each in-scope component: design, develop, and produce it to the essential cybersecurity requirements, and handle vulnerabilities with a coordinated vulnerability disclosure policy. (Art. 13(1), Art. 13(8), Annex I)
  • Treat a backend you develop that a shipped component depends on as a remote data processing solution in scope with that component. (Art. 3(2), Recital 11)
  • Draw up technical documentation, carry out conformity assessment, affix the CE marking, and report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 13(12), Art. 14, Art. 31, Art. 32)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

We are pure web SaaS with no downloads. Are we in CRA scope?

On its face, no. A service consumed only in the browser is not a product with digital elements, and the recitals put SaaS under NIS2 rather than the CRA. Confirm you genuinely ship nothing installable, because a single extension or helper app changes the answer. (Art. 3(1), Recital 12)

Does our browser extension really count as a product?

Yes. A browser extension is software a user installs, so it is a product with digital elements in its own right. It carries the manufacturer obligations independently of whether the rest of your offering is a browser-only service outside scope. (Art. 3(1))

Is our entire cloud backend now regulated by the CRA?

No. The CRA reaches the remote data processing a shipped product needs to function, not the security of your whole network. A backend you develop that a client depends on is in scope with that client; unrelated infrastructure and third-party services are not. (Art. 3(2), Recital 11)

When do we need to be ready?

Reporting duties for actively exploited vulnerabilities and severe incidents start 11 September 2026. The full obligations for in-scope components, including conformity assessment and CE marking, apply from 11 December 2027. (Art. 71(2))

Map your surface to scope, free

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes, one pass per shipped component, so you can see exactly which parts of your SaaS the CRA reaches.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.