Why plain SaaS sits outside the CRA Recital 12, Art. 3(1)
A product with digital elements is a software or hardware product, plus the remote data processing solutions it depends on. A service delivered entirely through the browser, with nothing the user downloads or installs, is not that kind of product. The recitals are explicit that Directive (EU) 2022/2555 (NIS2) applies to cloud computing services and to service models such as SaaS, PaaS, and IaaS.
That is why a great many SaaS companies read the CRA, conclude it is not their regulation, and stop there. For a genuinely browser-only product that conclusion holds. The problem is that very few modern products are genuinely browser-only, which is where the scope surprise lives.
The scope surprise: any downloadable component pulls you in Art. 3(1), Art. 2(1)
The CRA attaches to products, not to your business model. If your SaaS ships anything the customer installs, that thing is a product with digital elements in its own right: a desktop client, a mobile companion app, a browser extension, a CLI, a sync agent, or downloadable firmware for a paired device. Selling the service as "cloud" does not exempt the installable piece.
This is the single most common way a company that believed it was out of scope turns out to be a manufacturer. If you distribute even one installable artifact to EU users in the course of business, treat that artifact as in scope and run the manufacturer programme for it.
Your backend can come into scope with the component Art. 3(2), Recital 11
Remote data processing means data processing at a distance where the software is developed by the manufacturer, or under the manufacturer's responsibility, and without which the product could not perform one of its functions. The recitals give the example directly: a mobile application that needs an API or database provided by a service the manufacturer developed pulls that service into scope.
So the backend behind your installable component is not automatically safe just because it lives in the cloud. Where it is yours and the component cannot do its job without it, it is in scope as part of the product. A genuinely third-party backend outside your responsibility is a different matter.
When the deadlines apply to you Art. 14, Art. 71(2)
If you conclude an installable component puts you in scope, the CRA timeline applies to that product. Reporting duties for actively exploited vulnerabilities and severe incidents start on 11 September 2026, and the full manufacturer obligations apply from 11 December 2027. If you stay genuinely browser-only, neither date binds you under the CRA, though NIS2 obligations may.