Scope depends on what you ship ยท Regulation (EU) 2024/2847

Does the EU Cyber Resilience Act apply to SaaS?

Verified against the Official Journal text on

Depends on what you ship (Art. 3(1), Art. 3(2), Recital 12)

Usually not, with one sharp exception worth understanding. A purely browser-based service with nothing to install is not a product with digital elements, and the recitals place cloud service models such as SaaS, PaaS, and IaaS under the NIS2 Directive instead. The exception is the moment you ship any downloadable or installable component: a desktop client, a mobile app, a browser extension, or an agent. That component is then a product in scope, and a backend you develop that it depends on to work comes into scope with it as a remote data processing solution.

Basis: Recital 11, Recital 12, Art. 3(1), Art. 3(2)

Judgment call: Whether a backend is "developed under the responsibility of the manufacturer" and whether the product function "would not work" without it are functional tests with no bright line. Close calls deserve documented reasoning.

Why plain SaaS sits outside the CRA Recital 12, Art. 3(1)

A product with digital elements is a software or hardware product, plus the remote data processing solutions it depends on. A service delivered entirely through the browser, with nothing the user downloads or installs, is not that kind of product. The recitals are explicit that Directive (EU) 2022/2555 (NIS2) applies to cloud computing services and to service models such as SaaS, PaaS, and IaaS.

That is why a great many SaaS companies read the CRA, conclude it is not their regulation, and stop there. For a genuinely browser-only product that conclusion holds. The problem is that very few modern products are genuinely browser-only, which is where the scope surprise lives.

The scope surprise: any downloadable component pulls you in Art. 3(1), Art. 2(1)

The CRA attaches to products, not to your business model. If your SaaS ships anything the customer installs, that thing is a product with digital elements in its own right: a desktop client, a mobile companion app, a browser extension, a CLI, a sync agent, or downloadable firmware for a paired device. Selling the service as "cloud" does not exempt the installable piece.

This is the single most common way a company that believed it was out of scope turns out to be a manufacturer. If you distribute even one installable artifact to EU users in the course of business, treat that artifact as in scope and run the manufacturer programme for it.

Your backend can come into scope with the component Art. 3(2), Recital 11

Remote data processing means data processing at a distance where the software is developed by the manufacturer, or under the manufacturer's responsibility, and without which the product could not perform one of its functions. The recitals give the example directly: a mobile application that needs an API or database provided by a service the manufacturer developed pulls that service into scope.

So the backend behind your installable component is not automatically safe just because it lives in the cloud. Where it is yours and the component cannot do its job without it, it is in scope as part of the product. A genuinely third-party backend outside your responsibility is a different matter.

When the deadlines apply to you Art. 14, Art. 71(2)

If you conclude an installable component puts you in scope, the CRA timeline applies to that product. Reporting duties for actively exploited vulnerabilities and severe incidents start on 11 September 2026, and the full manufacturer obligations apply from 11 December 2027. If you stay genuinely browser-only, neither date binds you under the CRA, though NIS2 obligations may.

What you must do

  • For any installable component, design, develop, and produce it in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities in the component and its in-scope backend during the support period, including a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
If an installable component puts you in scope, reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply to the in-scope component: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

We are pure SaaS with no downloads. Are we in scope of the CRA?

Most likely not. A service delivered entirely in the browser is not a product with digital elements, and the recitals put cloud service models under NIS2 instead. Revisit this the moment you ship anything a customer installs. (Recital 12, Art. 3(1))

We offer a desktop client and a mobile app alongside the web app. Now what?

Those installable components are products with digital elements in scope of the CRA, even though the core service is cloud. Run the manufacturer programme for each installable artifact you distribute to EU users. (Art. 3(1), Art. 2(1))

Does our cloud backend fall under the CRA too?

It can. Where the backend is developed by you or under your responsibility and an in-scope component cannot perform a function without it, the backend is in scope as a remote data processing solution. A genuinely third-party backend outside your responsibility is not. (Art. 3(2), Recital 11)

Is NIS2 or the CRA the right regime for us?

They can both apply to different parts. The cloud service layer is NIS2 territory; any installable product you ship, plus the backend it depends on, is CRA territory. Map each part of your offering separately. (Recital 12, Art. 3(2))

Find out if a component puts you in scope

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes, including the downloadable-component question that catches most SaaS teams by surprise.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.