Components placed on the market ยท Regulation (EU) 2024/2847

Are software libraries and SDKs in scope of the CRA?

Verified against the Official Journal text on

In scope when supplied commercially (Art. 3(1), Recital 18)

They can be. A software or hardware component intended for integration into an electronic information system is caught by the definition of a product with digital elements when it is placed on the market separately. The commercial-activity test still governs: for a component intended for integration by other manufacturers, supplying it counts as making it available on the market only where the original manufacturer monetises it. Separately, if you integrate third-party components into your own product, you carry a due diligence duty on those components, and your vulnerability handling extends to them. So a library sits in scope either as a product you supply or as a component you must vet.

Basis: Art. 3(1), Recital 18, Art. 13(5)

Judgment call: Whether supplying a specific component is a commercial activity, and how much due diligence a given component needs, are judgment calls the recitals frame but do not fully settle.

A component can be a product in its own right Art. 3(1), Recital 18

The CRA defines a product with digital elements to include software or hardware components placed on the market separately, and it defines a component as software or hardware intended for integration into an electronic information system. A library, SDK, or module you distribute for others to build on can therefore be a product with digital elements when placed on the market on its own.

The commercial-activity test still decides scope. For components intended for integration by other manufacturers, the recitals say supply counts as making available on the market only if the original manufacturer monetises the component. An unmonetised open-source component you publish is treated differently from one you sell or license commercially.

If you integrate third-party components Art. 13(5), Art. 13(6), Annex I Part II

The other side of libraries is consuming them. When you integrate components sourced from third parties into your product, you must exercise due diligence so those components do not compromise your product's cybersecurity, including for open-source components not made available on the market in a commercial activity.

Your vulnerability handling covers the product in its entirety, including all integrated components. On identifying a vulnerability in a component, you must report it to whoever manufactures or maintains the component, remediate it in your product, and, where you developed a fix, share the relevant code or documentation with them.

Information for integrators Annex II (8)(f)

If you supply a component intended for integration into other products with digital elements, the information accompanying it must include what the integrator needs to comply with the essential cybersecurity requirements and the documentation requirements. That makes the interface between component supplier and integrator part of the compliance chain, not an afterthought.

Practically, that means documenting security properties, intended use, and the information an integrator needs to meet Annex I, so your customers can carry their own obligations. Where the CRA text is thin on a specific component scenario, treat the gap as a point to reason through and record.

Judgment call: The CRA sets the integrator-information duty but leaves the exact contents to the manufacturer's judgment for a given component; document what an integrator would reasonably need.

What you must do

  • If you place a component on the market commercially: build it to the essential requirements, handle its vulnerabilities, document it, assess conformity, and CE mark, as its manufacturer. (Art. 13, Annex I)
  • When integrating third-party components into your product, exercise due diligence so they do not compromise its cybersecurity. (Art. 13(5))
  • On finding a vulnerability in a component, report it to the party maintaining it, remediate it in your product, and share any fix you develop. (Art. 13(6))
  • Provide integrators with the information they need to meet the essential requirements and documentation duties. (Annex II (8)(f))

The dates that decide your planning

11 September 2026
For a component in scope, reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply to an in-scope component: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

We publish a free open-source library. Is it in scope of the CRA?

For a component intended for integration by other manufacturers, supply counts as making available on the market only if the original manufacturer monetises the component. An unmonetised open-source library is generally not in scope on that basis. (Recital 18, Art. 3(22))

We sell a commercial SDK. What are our duties?

A component placed on the market commercially is a product with digital elements, so the manufacturer obligations apply: build to the essential requirements, handle vulnerabilities, document, assess conformity, CE mark, and give integrators the information they need. (Art. 3(1), Art. 13, Annex II (8)(f))

We only consume third-party libraries. Does the CRA reach us?

Through your own product, yes. You must exercise due diligence on integrated third-party components, and your vulnerability handling covers the product in its entirety, including those components. (Art. 13(5), Annex I Part II)

See how a library maps to the CRA

The Vexwatch Scope Checker walks the same cited decision tree, including the commercial-activity and component questions that decide whether your library is a product you supply or one you must vet.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.