Pure browser SaaS is NIS2 territory, not the CRA Art. 3(1), Recital 12
A product with digital elements is a software or hardware product, something shipped, not a service consumed in a browser (Art. 3(1)). The recitals are explicit that cloud computing service models such as Software as a Service, Platform as a Service, and Infrastructure as a Service fall under Directive (EU) 2022/2555 (NIS2), not the CRA (Recital 12).
So a web app with no installable component is outside the CRA on its face. That is not a free pass: NIS2 may still reach you, and this answer flips as soon as you distribute something users install.
Inventory your downloadable surface Art. 3(1)
The practical task is to list everything you ship that a user runs on their own device or in their own browser. Each of these is, on its own, a product with digital elements and a candidate for CRA scope (Art. 3(1)). Teams routinely forget the smaller items, and the smaller items are exactly what pulls a "we are just SaaS" company into scope.
- Desktop or native clients (Windows, macOS, Linux). (Art. 3(1))
- Browser extensions and add-ons. (Art. 3(1))
- Mobile apps (iOS, Android). (Art. 3(1))
- Background agents, sync daemons, or device connectors. (Art. 3(1))
- Command-line tools, SDKs, and libraries you distribute. (Art. 3(1))
The backend can come into scope with the client Art. 3(2), Recital 11
When a component you ship relies on a backend that you develop, or that is developed under your responsibility, and without which one of the product's functions would not work, that backend is a remote data processing solution and is in scope together with the product (Art. 3(2), Recital 11). The recital gives the worked example of a mobile app that needs an API or database provided by the manufacturer: that service is then in scope.
This does not sweep your whole cloud estate into the CRA. The requirements reach the remote data processing that a product needs to function, not the security of your corporate network as a whole (Recital 11). A third-party backend developed outside your responsibility is not yours to certify.
What in-scope components then have to do Art. 13, Art. 14, Art. 7
For each downloadable component that is in scope, you are its manufacturer and carry the full programme: essential cybersecurity requirements, vulnerability handling with a coordinated disclosure policy, technical documentation, conformity assessment, CE marking, and reporting (Art. 13, Art. 14). Check whether any component matches an important category, for example an identity or access component, because that changes the conformity route (Art. 7, Annex III).