Not a product with digital elements ยท Regulation (EU) 2024/2847

Does the EU Cyber Resilience Act apply to a website?

Verified against the Official Journal text on

Out of scope on its own (Recital 12, Art. 3(1))

Almost certainly not, on its own. A plain website or web content is not a product with digital elements: the CRA covers shipped software or hardware, and the recitals say expressly that a website which does not support the functionality of a product with digital elements is outside scope. The service layer behind a site may instead fall under the NIS2 Directive. This picture changes the moment your site ships something installable (a desktop client, a browser extension, a mobile app, or an agent), or hosts a backend that a product of yours depends on to perform one of its functions.

Basis: Recital 12, Art. 3(1)

Judgment call: Whether something you distribute through the site counts as an installable product, or a backend a product depends on, is the judgment that flips this answer. Assess each artifact you ship.

Why a website is not a product with digital elements Recital 12, Art. 3(1)

The CRA defines a product with digital elements as a software or hardware product and its remote data processing solutions. A website is content served to a browser, not a product the user downloads or installs. The recitals draw the line plainly: websites that do not support the functionality of a product with digital elements do not fall within scope.

So a marketing site, a blog, a documentation portal, or a brochure site is not, by itself, something the CRA regulates. The regulation is about products placed on the market, and a plain website is not one of them.

NIS2 may still cover the service behind the site Recital 12

Being outside the CRA does not mean being outside all EU cybersecurity law. The recitals point to Directive (EU) 2022/2555 (NIS2) for cloud computing services and service models such as SaaS, PaaS, and IaaS. Depending on what your site is a front-end for, obligations can live there instead.

Treat "not in CRA scope" as an answer about products, not a clean bill of health for your whole operation. If the site fronts an online service, check whether NIS2 or sector rules reach it.

What flips a website into scope Art. 3(1), Art. 3(2)

Two things pull the CRA back in. First, if the site distributes anything installable (a desktop app, a browser extension, a mobile app, a firmware image, or an agent), that installable artifact is a product with digital elements in its own right, and you run the manufacturer programme for it.

Second, if the site hosts a backend that a product of yours depends on to perform a function, that backend can come into scope as a remote data processing solution, together with the product. A download button or a companion app is the usual trigger, so watch for those.

Frequently asked

Our company website has a login and a customer portal. Is it in scope of the CRA?

A portal delivered entirely in the browser is still web content, not a product with digital elements, so the CRA does not apply on that basis. The service layer behind it may fall under NIS2. Ship anything installable and the answer changes. (Recital 12, Art. 3(1))

We let visitors download a desktop tool from our site. Does that matter?

Yes. The downloadable tool is a product with digital elements in scope of the CRA, even though the site itself is not. You would run the manufacturer obligations for the tool you distribute to EU users. (Art. 3(1), Art. 2(1))

Does adding a browser extension change our position?

It can. A browser extension is installable software and a product with digital elements in its own right. Distributing one to EU users in the course of business brings it into CRA scope, separately from the website. (Art. 3(1), Art. 2(1))

Confirm your site really is out of scope

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes and flags the installable-component and backend questions that quietly pull a website back into scope.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.