Kilde › Guides › CRA › CRA scope: software, SaaS, open source…
Current to 26 August 2026 · updates land in the changelog.
Before any classification or reporting question comes the scope question. The CRA covers “products with digital elements”: software or hardware products and their remote data processing solutions, including components placed on the market separately — where the intended or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network.
Standalone software is squarely a product with digital elements — the CRA is not a hardware law. Pure SaaS and cloud services, by contrast, generally sit under NIS2 rather than the CRA. The boundary term is remote data processing (Article 3(2)): a cloud back-end counts as part of the product when the product functionally depends on it and it is developed by or on behalf of the manufacturer. A mobile app that is useless without its vendor cloud: one product, cloud included. A generic cloud service consumed by many products: not dragged in.
Sectors with their own regimes are carved out: medical devices (MDR 2017/745) and IVDs (2017/746), motor vehicles under the type-approval regime (2019/2144), civil-aviation equipment within its certification framework (2018/1139), marine equipment (2014/90), spare parts made to identical specifications, and products for national-security, defence or classified purposes. Note the pattern in Annex III item 19: a wearable that is a regulated medical device is excluded here precisely because the MDR applies instead.
Non-commercial free and open-source software is out of scope. Supplying FOSS in the course of a commercial activity is in scope — monetisation patterns matter. Between the two sits the open-source software steward (Article 3(14)): foundations and similar entities supporting qualifying FOSS get a light-touch regime and are exempt from administrative fines (Article 64(10)(b)).
Scope attaches duties to roles: the manufacturer — including anyone marketing under their own name or trademark, white-labellers included — carries the heavy set; importers and distributors carry verification duties. If your products are in scope, the first live obligation is the September 2026 reporting duty — and it covers everything already in the field.
The CRA Reporting-Ready Pack: the staged 24h / 72h / final-report runbook and templates, vulnerability-vs-incident triage worksheet, CSIRT-routing and main-establishment worksheet, platform registration runbook, CVD policy and evidence log — built from the regulation and the ENISA platform guides, with pinpoint citations.
Get the pack — US$390 Free 4-page sample (PDF)Instant download · 14-day unconditional refund · single-organisation licence · full product page
General information only — not legal advice, and never a conformity assessment. Whether a specific product falls in a listed category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, and reporting-platform mechanics are ENISA-published material marked subject to change. Sources are Regulation (EU) 2024/2847 (CELEX 32024R2847; Annex III/IV item texts read verbatim from EUR-Lex) and our audited kit research. © 2026 Kilde.
Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com