Guides · 2026-07-22 · 6 min
Is Your Software in Scope of the EU Cyber Resilience Act?
The short answer
If you distribute software that users download and run — plugins, desktop or mobile apps, CLI tools, firmware, self-hosted binaries — and you make it available on the EU market in the course of a commercial activity, the EU Cyber Resilience Act (Regulation (EU) 2024/2847) almost certainly applies to you. Pure SaaS is out of scope: the CRA regulates products, not services. Open source is out of scope only as long as it is not monetised. The regulation entered into force on 10 December 2024; its main obligations apply from 11 December 2027, and the vulnerability-reporting duties start earlier, on 11 September 2026.
What counts as a “product with digital elements”
The CRA covers any software or hardware product — and its “remote data processing solutions” — made available on the EU market, including software components placed on the market separately. Software alone qualifies; no hardware is needed. That includes:
- Mobile and desktop applications, games, CLI tools
- Plugins, extensions, themes and add-ons sold or distributed separately (Etsy-style digital goods do not count, but a WordPress or Shopify plugin does)
- Firmware and embedded software
- Libraries, SDKs and other components supplied on their own
“Making available on the market” means supplying the product for distribution or use in the EU in the course of a commercial activity — whether or not money changes hands. A free app monetised through ads or paid tiers is commercial. And you do not need to be established in the EU: if EU customers are part of your market, you are the manufacturer under the CRA.
Why pure SaaS is out of scope — and the remote-processing nuance
The CRA is product legislation. A web application, hosted API or cloud platform that users only access as a service is not “placed on the market” as a product; cloud services fall under the NIS2 Directive instead, if the provider meets its thresholds.
There is one important nuance. Article 3(2) defines remote data processing as processing at a distance, designed by or on behalf of the manufacturer, without which the product could not perform one of its functions. That processing is treated as part of the product. In practice:
- A mobile app that requires your sync backend for a core feature → the app and that backend function are inside the CRA perimeter.
- A purely browser-based dashboard with no distributed client → a service, outside the CRA.
Rule of thumb: if nothing is installed on the user's side, you are likely in NIS2 territory; if you ship a client that depends on your cloud, both are covered.
Open source: the commercial-activity test
Free and open-source software developed or supplied outside a commercial activity is out of scope. Accepting donations without the intention of making a profit, or contributions from companies to an open repository, does not by itself make a project commercial.
Monetisation flips the switch. Typical in-scope signals:
- Selling a commercial or “pro” version of the software
- Dual licensing (free community licence + paid commercial licence)
- Paid support or maintenance contracts that go beyond recovering costs
- Charging for the software itself, even once
A monetised open-source product carries the full manufacturer obligations. Separately, the CRA created a lighter role — the open-source software steward — for foundations and similar entities that systematically support the development of open-source products intended for commercial use: they must adopt a cybersecurity policy and cooperate with authorities, but do not CE-mark anything.
Sector exclusions
Some product categories are excluded because sector rules already cover cybersecurity:
- Medical devices and in-vitro diagnostics (Regulations (EU) 2017/745 and 2017/746)
- Motor vehicles under the type-approval framework (Regulation (EU) 2019/2144)
- Civil aviation equipment (Regulation (EU) 2018/1139)
- Marine equipment (Directive 2014/90/EU)
- Products developed exclusively for national security or defence purposes
- Spare parts that replace identical components
If your software ships only as a component of one of those regulated products, the sector framework applies instead of the CRA.
Check your product in two minutes
Scope is a yes/no chain: product or service, commercial or not, excluded sector or not. Our free CRA scope check walks through exactly these questions and tells you where you land — and if you are in scope, a structured self-assessment dossier helps you prepare the documentation the regulation expects. The self-assessment remains the manufacturer's own; this guide is documentary information, not legal advice.
Frequently asked
Does the Cyber Resilience Act apply to SaaS?
No. Pure SaaS is a service, not a product placed on the market, and falls under NIS2 instead. Exception: remote processing that is integral to a shipped product (e.g. a required app backend) is covered as part of that product.
Is open-source software covered by the CRA?
Not if it is developed and supplied outside a commercial activity. It is covered once monetised — commercial versions, dual licensing, or paid support beyond cost recovery.
When does the CRA start applying?
It entered into force on 10 December 2024. Vulnerability and incident reporting applies from 11 September 2026, and the main obligations from 11 December 2027.
Does the CRA apply to companies outside the EU?
Yes. Any manufacturer making a product with digital elements available on the EU market is covered, regardless of where the company is established.
Are free apps in scope?
Often yes. Making software available free of charge is still a commercial activity when it is monetised otherwise, for example through ads, data, or paid tiers.
Documentary information, not legal advice. Sourced from Regulation (EU) 2024/2847 and official Commission/ENISA material — check the linked sources for your specific case.