Why a website is not a product with digital elements Recital 12, Art. 3(1)
The CRA defines a product with digital elements as a software or hardware product and its remote data processing solutions. A website is content served to a browser, not a product the user downloads or installs. The recitals draw the line plainly: websites that do not support the functionality of a product with digital elements do not fall within scope.
So a marketing site, a blog, a documentation portal, or a brochure site is not, by itself, something the CRA regulates. The regulation is about products placed on the market, and a plain website is not one of them.
NIS2 may still cover the service behind the site Recital 12
Being outside the CRA does not mean being outside all EU cybersecurity law. The recitals point to Directive (EU) 2022/2555 (NIS2) for cloud computing services and service models such as SaaS, PaaS, and IaaS. Depending on what your site is a front-end for, obligations can live there instead.
Treat "not in CRA scope" as an answer about products, not a clean bill of health for your whole operation. If the site fronts an online service, check whether NIS2 or sector rules reach it.
What flips a website into scope Art. 3(1), Art. 3(2)
Two things pull the CRA back in. First, if the site distributes anything installable (a desktop app, a browser extension, a mobile app, a firmware image, or an agent), that installable artifact is a product with digital elements in its own right, and you run the manufacturer programme for it.
Second, if the site hosts a backend that a product of yours depends on to perform a function, that backend can come into scope as a remote data processing solution, together with the product. A download button or a companion app is the usual trigger, so watch for those.