In scope, default category ยท Regulation (EU) 2024/2847

Are video games in scope of the EU CRA?

Verified against the Official Journal text on

In scope, default category (Art. 2(1), Art. 3(1))

Yes, for a game players download or install. A game is a software product with digital elements, and supplying it to EU players in the course of business is making it available on the market, whether it is paid, free-to-play, or ad-supported. Free of charge does not remove it from scope where the supply is commercial. Games are default-category products, so self-assessment under internal control is generally available. A purely browser-based game with nothing installed is more like an online service, and its own backend can come into scope where a downloadable client depends on it.

Basis: Art. 2(1), Art. 3(1), Art. 3(22)

Judgment call: Whether a browser-only title is a product with digital elements, or a service under NIS2, follows the same installable-component line as other online services; assess what the player actually receives.

A game is a software product Art. 2(1), Art. 3(1)

The CRA applies to products with digital elements made available on the market whose intended purpose or reasonably foreseeable use includes a data connection to a device or network. A downloadable or installed game that connects for multiplayer, updates, or online services is a product with digital elements. Distributing it to EU players through a store or launcher is supply on the Union market.

Studios often assume consumer entertainment sits outside cybersecurity regulation. It does not. A game is software like any other software product, and its scope turns on the same tests as a productivity tool or a utility.

Free-to-play still counts Art. 3(22), Recital 15

Making available on the market covers supply for distribution or use in the course of a commercial activity, in return for payment or free of charge. A free-to-play or ad-supported title distributed as part of a commercial business is in scope just as a paid title is. The revenue model does not decide scope; the commercial nature of the supply does.

The recitals treat an intention to monetise, including through a platform that monetises other services, as a marker of commercial activity. Most free games sit inside a commercial operation, so the free label rarely changes the answer.

Backends, browser titles, and the manufacturer programme Art. 3(2), Recital 12, Art. 13

Where a downloadable game depends on a backend you develop, or that is developed under your responsibility, and it cannot perform a function without it, that backend is in scope as a remote data processing solution together with the game. A purely browser-based game with nothing installed is closer to an online service, which sits under the NIS2 Directive.

For an in-scope game you build to the essential cybersecurity requirements, handle vulnerabilities (including a coordinated vulnerability disclosure policy), document, assess conformity, and CE mark. Reporting duties start 11 September 2026 and the full obligations apply from 11 December 2027.

What you must do

  • Design, develop, and produce the game in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities during the support period, including a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Draw up technical documentation, carry out conformity assessment, and affix the CE marking. (Art. 13(12), Art. 32)
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

Our game is free-to-play. Is it really in scope of the CRA?

Yes, where the supply is commercial. Making available on the market covers supply in the course of a commercial activity whether paid or free, and a free-to-play title inside a commercial business is in scope just as a paid one is. (Art. 3(22), Recital 15)

We run a purely browser-based game. What about us?

A game delivered entirely in the browser with nothing installed is closer to an online service, which sits under NIS2. This flips if you ship a downloadable client, which is then a product with digital elements in scope. (Recital 12, Art. 3(1))

Does our multiplayer backend fall under the CRA?

It can. Where a downloadable game needs a backend you develop, or are responsible for, and cannot perform a function without it, that backend is in scope as a remote data processing solution together with the game. (Art. 3(2), Recital 11)

Check your title against the CRA

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes: whether your game is in scope, whether its backend comes with it, and which obligations hit on which date.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.