Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

When is SaaS in scope of the EU Cyber Resilience Act?

Updated

Standalone SaaS and cloud services designed outside a manufacturer's responsibility are generally outside the CRA (Regulation (EU) 2024/2847) and may sit under NIS2. A remote data-processing solution integral to a product with digital elements can be in. This page is not legal advice and does not start a clock.

CRA SaaS-scope guide, last verified 9 September 2026 against Regulation (EU) 2024/2847 Articles 2–3 and 71 and Recitals 11–12, Directive (EU) 2022/2555 Articles 2, 3 and 6(30), the European Commission's CRA pages (last updated 7 September 2026), CRA implementation FAQs (last updated 4 September 2026), and 27 July 2026 guidance (C(2026) 5252) — those Commission materials are guidance, not the regulation. It is not legal advice, not a filing, not a determination that YOUR offering is in or out, and not a substitute for counsel.

This is the SaaS boundary, not YOUR offering

Audience: a SaaS founder, CTO, product, or compliance lead asking whether a browser-only service, an on-prem install, an agent, or a hybrid stack sits under the CRA. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the CRA applies, that NIS2 as transposed applies, that you are a manufacturer, that a product with digital elements has been made available on the Union market, or that a filing is due.

The CRA is Regulation (EU) 2024/2847 of 23 October 2024, OJ L 2024/2847, 20.11.2024. ELI: http://data.europa.eu/eli/reg/2024/2847/2024-11-20. It is a regulation, directly applicable, on products with digital elements made available on the Union market. NIS2 is Directive (EU) 2022/2555 — a different instrument. Member States transpose NIS2. This page quotes which kind of text it is relying on. Last verified 9 September 2026. Not legal advice.

  • Statute versus guidance: Articles 2 and 3 and Recitals 11–12 of Regulation (EU) 2024/2847 are the regulation. Recitals aid interpretation; they are not operative articles. Commission CRA pages, CRA implementation FAQs (last updated 4 September 2026), and the 27 July 2026 Commission guidance (C(2026) 5252) are Commission materials — guidance, not the regulation. The Commission page itself calls that 27 July 2026 guidance non-binding.
  • The CRA overview on this site is the pillar page. The statute-clock Article 14 guide on this site is the CRA Article 14 page under breach reporting. The CRA-cluster Article 14 overview on this site is the cluster reporting page. The NIS2 incident-reporting guide on this site is Article 23.
  • The who-is-covered guide on this site is the economic-operator roles page. A dedicated products-in-scope and readiness-checklist guide is not on this site yet. Naming them is not a link.

Decision tree — product, remote processing, or pure service

Work this table with counsel. It is a decision aid distilled from Articles 2 and 3 and Recitals 11–12. It is not a determination that YOUR offering is a product with digital elements, a remote data processing solution, or a pure service. This page does not classify YOUR stack. Last verified 9 September 2026. Not legal advice.

Decision aid — product with digital elements vs remote data-processing solution vs pure service (not a determination; not legal advice)
QuestionWhat the text saysKind of textWhat this page does not do
Is the offering a product with digital elements made available on the Union market?Article 2(1): this Regulation applies to products with digital elements made available on the market, the intended purpose or reasonably foreseeable use of which includes a direct or indirect logical or physical data connection to a device or network. Article 3(1): product with digital elements means a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately.Legal requirement — Articles 2(1) and 3(1). Only if they apply.Does not find that YOUR offering is a product with digital elements. Does not find that it has been made available on the Union market.
If there is a local product, is the remote backend a remote data processing solution?Article 3(2): remote data processing means data processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the product with digital elements from performing one of its functions.Legal requirement — Article 3(2). Three cumulative elements as the article states them.Does not find that YOUR API, database, or cloud path is a remote data processing solution. Does not run the three elements on YOUR facts.
Is the offering standalone SaaS or another cloud service designed and developed outside a manufacturer's responsibility?Recital 12: cloud solutions constitute remote data processing solutions within the meaning of this Regulation only if they meet the definition laid down in this Regulation. On the other hand, websites that do not support the functionality of a product with digital elements, or cloud services designed and developed outside the responsibility of a manufacturer of a product with digital elements do not fall within the scope of this Regulation. Directive (EU) 2022/2555 applies to cloud computing services and cloud service models, such as Software as a Service (SaaS), Platform as a Service (PaaS) or Infrastructure as a Service (IaaS).Recital 12 — a recital, not an operative article. Commission CRA FAQs (guidance, not the regulation) restated a standalone-SaaS reading; that FAQ is not the regulation.Does not find that YOUR SaaS is out. Does not treat Recital 12 as a substitute for Articles 2 and 3. Does not treat a Commission FAQ as rewriting Article 3(2).
Is the offering on-prem software made available on the Union market?Article 3(1) is a software or hardware product and its remote data processing solutions. Commission CRA FAQs (guidance, not the regulation) give examples of standalone software that can be downloaded and installed on a device. That FAQ is not a classification of YOUR installer.Article 3(1) is the legal requirement. The FAQ example is guidance, not the regulation.Does not classify YOUR on-prem offering. On-prem software that is a product with digital elements made available on the Union market is a different analysis from a browser-only service. This page does not run either analysis for YOU.
Is it an agent or hybrid — a local component plus a remote backend?Recital 11: such processing or storage at a distance includes the situation where a mobile application requires access to an application programming interface or to a database provided by means of a service developed by the manufacturer. In such a case, the service falls within the scope of this Regulation as a remote data processing solution. If a local component is a product with digital elements and a remote backend meets Article 3(2), both limbs may be in play.Recital 11 is a recital. Article 3(1)–(2) are the operative definitions. This page quotes both. It does not pick one for YOU.Does not decide that YOUR agent, desktop app, or hybrid stack is in or out. Does not split YOUR architecture into in-scope and out-of-scope parts.

Article 3 definitions — quoted, not applied to YOU

These are the operative definitions. Recitals 11–12 discuss them. Commission guidance interprets them. Counsel applies them to YOUR facts. This page does not. Last verified 9 September 2026. Not legal advice.

Article 3 as the regulation states it (not YOUR class; not a determination; not legal advice)
TermWhat Article 3 saysKind of textLast verified
Product with digital elements — Article 3(1)A software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately.Legal requirement — Article 3(1).9 September 2026
Remote data processing — Article 3(2)Data processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the product with digital elements from performing one of its functions.Legal requirement — Article 3(2). Three cumulative elements. This page does not find that YOUR cloud path meets them.9 September 2026
Software — Article 3(4)The part of an electronic information system which consists of computer code.Legal requirement — Article 3(4).9 September 2026
Making available on the market — Article 3(22)The supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity.Legal requirement — Article 3(22). This page does not find that YOUR supply is that activity.9 September 2026

Recitals 11 and 12 — recitals, not operative articles

Recital 11: the purpose of this Regulation is to ensure a high level of cybersecurity of products with digital elements and their integrated remote data processing solutions. Such remote data processing solutions should be defined as data processing at a distance for which the software is designed and developed by or on behalf of the manufacturer of the product with digital elements concerned, the absence of which would prevent the product with digital elements from performing one of its functions. Processing or storage at a distance falls within the scope of this Regulation only in so far as it is necessary for a product with digital elements to perform its functions. Recital 11's 'by or on behalf of the manufacturer' is recital language; Article 3(2) says 'by the manufacturer, or under the responsibility of the manufacturer'. This page quotes both. It does not collapse them.

Recital 12: cloud solutions constitute remote data processing solutions within the meaning of this Regulation only if they meet the definition laid down in this Regulation. For example, cloud enabled functionalities provided by a manufacturer of smart home devices that enable users to control the device at a distance fall within the scope of this Regulation. On the other hand, websites that do not support the functionality of a product with digital elements, or cloud services designed and developed outside the responsibility of a manufacturer of a product with digital elements do not fall within the scope of this Regulation. Directive (EU) 2022/2555 applies to cloud computing services and cloud service models, such as Software as a Service (SaaS), Platform as a Service (PaaS) or Infrastructure as a Service (IaaS). Entities providing cloud computing services in the Union which qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC, or exceed the ceilings for medium-sized enterprises provided for in paragraph 1 of that Article, fall within the scope of that Directive.

Recital 12 is a recital, not an operative article. It points to NIS2 for those cloud computing services. It does not rewrite Articles 2 and 3. Last verified 9 September 2026. Not legal advice.

Commission interpretation — guidance, not the regulation

The European Commission's CRA implementation FAQs (publication 3 December 2025; page last updated 4 September 2026) are Commission materials. The FAQ document itself says it is prepared by the Commission services and should not be considered as representative of the European Commission's official position, and that the replies do not extend rights and obligations deriving from applicable legislation. That FAQ is guidance, not the regulation.

That FAQ, as last verified, states: as stated in Recital 12, websites that do not support the functionality of a product with digital elements are not themselves products with digital elements. Websites that support the functionality of a product with digital elements may fall in scope of the CRA to the extent that they meet the definition of remote data processing (Article 3(2)). Similarly, services, such as standalone Software-as-a-Service (SaaS) or other cloud solutions designed and developed outside the responsibility of a manufacturer of a product with digital elements are not themselves products with digital elements. Where, on the other hand, such services meet the definition of remote data processing, they fall within the scope of the CRA.

Commission guidance of 27 July 2026 (C(2026) 5252 and Annex) addresses remote data processing solutions and open-source software. The Commission library page itself calls that guidance non-binding. It is guidance, not the regulation. It does not rewrite Article 71's dates. Article 14 still applies from 11 September 2026; full application remains 11 December 2027. This page does not treat that guidance as a substitute for Article 3(2).

Statute versus current Commission interpretation (not a ranking; not a determination; not legal advice)
TextWhat it isWhat this page does not do
Regulation (EU) 2024/2847 Articles 2 and 3Legal requirement — the regulation, only if it applies.Does not apply those articles to YOU.
Recitals 11 and 12Recitals of the regulation. They aid interpretation. They are not operative articles.Does not treat Recital 12 as a standalone SaaS exclusion that replaces Article 3(2).
Commission CRA implementation FAQs (last updated 4 September 2026)Commission materials. Guidance, not the regulation. The FAQ's own disclaimer says the replies do not extend rights and obligations.Does not treat a FAQ sentence as a finding that YOUR SaaS is out.
Commission guidance of 27 July 2026 (C(2026) 5252)Commission guidance, not the regulation. The Commission page itself calls it non-binding. It addresses remote data processing solutions and open-source software.Does not treat that guidance as rewriting 11 September 2026 or 11 December 2027.

On-prem, agents, and hybrid — quote, do not decide

On-prem software that is a product with digital elements made available on the Union market is a different analysis from a browser-only service. Article 2(1) and Article 3(1) are the tests for a product with digital elements. This page does not run them on YOUR installer, package, or appliance.

Agents and hybrid deployments can put both limbs in play. Recital 11's mobile-application example is a local component that requires access to an API or database provided by means of a service developed by the manufacturer; in that case the service falls within the scope of this Regulation as a remote data processing solution. If counsel finds a local component is a product with digital elements and a remote backend meets Article 3(2), both limbs may be in play. This page does not split YOUR architecture.

The in-repo CRA control-set comment says standalone browser-only SaaS is generally out of CRA scope. That sentence is this product's own illustrative readiness mapping, not a legal determination. It is not the regulation. This page does not treat that comment as an operative article. Counsel applies Articles 2 and 3 to YOUR facts.

CRA versus NIS2 — different instruments

Do not paste one instrument onto the other. Filing or being in-scope for NIS2 does not classify a CRA product class. A CRA product-class finding does not classify a NIS2 entity. The NIS2 incident-reporting guide on this site is Article 23. Last verified 9 September 2026. Not legal advice.

CRA versus NIS2 boundary (not a determination; not legal advice; last verified 9 September 2026)
QuestionCRA — Regulation (EU) 2024/2847NIS2 — Directive (EU) 2022/2555What this page does not do
What does it regulate?Products with digital elements made available on the Union market (Articles 2 and 3), including their remote data processing solutions as defined in Article 3(2).Essential and important entities of types referred to in Annexes I and II, as transposed by Member States (Articles 2 and 3).Does not find that YOU are a manufacturer. Does not find that YOU are an essential or important entity.
Where does standalone SaaS / cloud computing sit?Recital 12: cloud services designed and developed outside the responsibility of a manufacturer of a product with digital elements do not fall within the scope of this Regulation. Recital 12 is a recital. Articles 2 and 3 remain the operative tests.Recital 12 of the CRA points to this Directive for cloud computing services and cloud service models, such as SaaS, PaaS or IaaS. Article 6(30) of NIS2: cloud computing service means a digital service that enables on-demand administration and broad remote access to a scalable and elastic pool of shareable computing resources, including where such resources are distributed across several locations.Does not find that YOUR SaaS is a NIS2 cloud computing service. Does not size YOUR undertaking against Recommendation 2003/361/EC.
When might a remote backend still be in the CRA?When it meets Article 3(2): processing at a distance, software designed and developed by the manufacturer or under the manufacturer's responsibility, and absence would prevent the product from performing one of its functions. Recital 11's mobile-application / manufacturer-developed API example is a recital illustration of that limb.Being a NIS2 cloud computing service does not by itself place that backend inside Article 3(2), and meeting Article 3(2) does not by itself make the operator an essential or important entity.Does not run Article 3(2) on YOUR backend. Does not treat a NIS2 filing as a CRA product-class finding.
Does filing or being in-scope for one classify the other?No. A CRA Article 14 notification is not a NIS2 Article 23 report. Marking the bundled framework key cra in-scope is not a NIS2 entity class.No. A NIS2 Article 23 filing is not an Article 14 notification. Marking the bundled framework key nis2 in-scope is not a CRA product class.Does not treat dual mapping as a SaaS classification.
What kind of instrument?A regulation, directly applicable. Article 14 applies from 11 September 2026; the rest from 11 December 2027 (Article 71(2)).A directive. Member States transpose it. Transposition wording, portals, and dates vary. Verify YOUR Member State.Does not start an Article 14 clock. Does not start an Article 23 clock.

Article 71 dates — unchanged on this page

Last verified 9 September 2026 against Article 71 on EUR-Lex. Article 71(2): this Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026. Commission guidance of 27 July 2026 does not move those dates. This page does not start that clock.

What to do now

The list below is operational preparation. It is not a determination that the CRA or NIS2 applies to YOU, that you are a manufacturer, that your offering is a product with digital elements, a remote data processing solution, or a pure service, or that a reporting clock has started. Walk it with counsel.

  • Ask counsel whether YOUR offering is a product with digital elements made available on the Union market under Articles 2 and 3. This page does not run that test. Marking cra in an obligation map is not that determination.
  • If there is a local component, ask counsel whether any remote backend meets Article 3(2)'s three elements. This page does not run them.
  • Ask counsel whether Recital 12's cloud-service discussion, and the Commission FAQ standalone-SaaS reading (guidance, not the regulation), describe YOUR facts. Do not treat the in-repo control-set comment as the regulation.
  • Ask counsel whether NIS2 as transposed may apply to YOU as a cloud computing service provider or other Annex I or II type. The NIS2 incident-reporting guide on this site is Article 23. Being in NIS2 scope does not classify a CRA product class.
  • If counsel says Article 14 may apply, open the live Article 14 reporting guide on this site for the 24-hour / 72-hour / 14-day ladder. This page does not start that clock.
  • The who-is-covered guide on this site is the economic-operator roles page. A dedicated products-in-scope and readiness-checklist guide is not on this site yet. Naming them is not a link.

Checklist

This is a question list, not a filing, and not YOUR classification. Walk it with counsel. The CRA overview on this site is the pillar page. The live Article 14 reporting guide on this site is the ladder. The NIS2 incident-reporting guide on this site is Article 23.

  • Product with digital elements made available on the Union market — Articles 2 and 3? This page does not run that test.
  • Remote data processing solution — Article 3(2)'s three elements? This page does not run them.
  • Standalone SaaS or cloud service designed and developed outside a manufacturer's responsibility — Recital 12, plus Commission FAQ as guidance, not the regulation? This page does not decide.
  • On-prem, agent, or hybrid — both limbs may be in play? This page does not split YOUR architecture.
  • NIS2 as transposed — cloud computing service or other entity type? Filing NIS2 does not classify CRA, and vice versa.
  • Article 14 from 11 September 2026 if the CRA applies. This page does not start that clock.
  • Document the assessment, including a not-in-scope decision. This page does not keep YOUR file.

Where this shows up in ShipReady Metrics

The bundled framework keys cra and nis2 are customer-visible. cra's version label is Regulation (EU) 2024/2847 (starter subset). nis2's version label is Directive (EU) 2022/2555 Art. 21 (starter subset). Neither is in INTERNAL_TESTER_ONLY_FRAMEWORKS. Marking both in-scope on the obligation map illustrates dual mapping. It is vendor-neutral. It is not a SaaS classification, not a determination that you sell a product with digital elements, and not a finding that you are an essential or important entity.

The CRA control-set is a starter subset, illustrative readiness mapping, to be tailored by a compliance owner; not legal advice; not full conformity-assessment detail. The in-repo comment that standalone browser-only SaaS is generally out of CRA scope is that mapping, not a legal determination. Readiness is not compliance, not CE marking, and not a market-surveillance determination.

If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour / 72-hour / 14-day ladder from recorded awareness for findings the organisation classified as CRA-in-scope actively exploited vulnerabilities. That tracker is not a SaaS determination. It does not start an Article 14 clock, does not decide that the CRA applies, does not find that you sell a product with digital elements, and does not file with a CSIRT or ENISA. A named human still files. The NIS2 reporting page on this site is a different instrument.

There is no SaaS-scope wizard in the app. This page does not document a public demo URL. There is no public CRA demo path. A named human and counsel still decide.

Primary sources (last verified 9 September 2026)

Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.

Regulation (EU) 2024/2847 of 23 October 2024 (Cyber Resilience Act), Articles 2 and 3 and Recitals 11–12, is a legal requirement only if it applies. Recitals are not operative articles. Article 14 applies from 11 September 2026; the rest from 11 December 2027 (Article 71(2)). Directive (EU) 2022/2555 (NIS2), Articles 2, 3 and 6(30), is a different instrument; Member States transpose it. The European Commission's CRA policy page (updated 7 September 2026), CRA implementation FAQs (last updated 4 September 2026), and 27 July 2026 guidance (C(2026) 5252) are Commission materials, not the regulation. These are not a complete world list. Not legal advice.

The CRA overview on this site is the pillar page. The statute-clock Article 14 guide on this site is the live ladder. The CRA-cluster Article 14 overview on this site is the cluster page. The NIS2 incident-reporting guide on this site is Article 23. The reporting-deadlines page on this site is the statute table of clocks. The who-is-covered guide on this site is the economic-operator roles page. A dedicated products-in-scope and readiness-checklist guide is not on this site yet. Naming them is not a link.

Frequently asked questions

Is this legal advice?

No. It is a decision aid distilled from Regulation (EU) 2024/2847 Articles 2 and 3 and Recitals 11–12, with Commission 27 July 2026 guidance and Commission CRA FAQs labelled as guidance, not the regulation. Whether YOUR offering is a product with digital elements, a remote data-processing solution, or a pure service is a legal question for counsel on your facts. This page does not start a clock.

Does ShipReady decide our SaaS is in scope?

No. The product does not classify YOUR offering as a product with digital elements, a remote data-processing solution, or a pure service. There is no SaaS-scope wizard. Marking cra or nis2 in-scope on the obligation map is not that classification. Signed-in CRA reporting is not a SaaS determination. A named human still decides with counsel.

Does NIS2 in-scope mean CRA in-scope?

No. NIS2 (Directive (EU) 2022/2555) classifies essential and important entities as transposed. The CRA (Regulation (EU) 2024/2847) applies to products with digital elements made available on the Union market. Filing or being in-scope for one does not classify the other. Marking both framework keys is dual mapping, not a SaaS classification.

Is standalone browser-only SaaS automatically out?

This page does not decide. Recital 12 and Commission CRA FAQs (guidance, not the regulation) discuss standalone SaaS and cloud services designed outside a manufacturer's responsibility. The in-repo CRA control-set comment that standalone browser-only SaaS is generally out of CRA scope is this product's illustrative readiness mapping, not the regulation.

Does an Article 14 tracker mean we sell a product with digital elements?

No. Signed-in CRA reporting tracks recorded awareness for findings the organisation classified as CRA-in-scope. That tracker does not start an Article 14 clock, does not file, and does not find that you sell a product with digital elements. A named human still files.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.