EU Cyber Resilience Act · updated 2026-09-23

Does the Cyber Resilience Act apply to SaaS?

Short answer: pure SaaS, no. SaaS with a shipped component, yes.

The CRA regulates "products with digital elements". A cloud service that is not tied to such a product is out of scope and is addressed by a different law, NIS2. The line is drawn by the definition of "remote data processing".

The test in the regulation

Article 3 defines a product with digital elements as a software or hardware product together with its remote data processing solutions. The trick is the narrow definition of that phrase: Art. 3(2) limits it to data processing "for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the product with digital elements from performing one of its functions".

So the cloud part is in scope only when it is part of a product you ship. Recital 12 says the rest plainly: cloud solutions developed outside the responsibility of a manufacturer of a product with digital elements do not fall within the scope. Standalone cloud services, SaaS, are pointed to the NIS2 Directive instead.

Three cases

Why this matters more than it looks

The distinction is not academic. Once in scope you owe an SBOM, technical documentation, a vulnerability-handling process, a support period of at least five years (Art. 13(8)), and, since 11 September 2026, the 24-hour reporting duty for actively exploited vulnerabilities (Art. 14). Many SaaS companies ship a "small" agent and never realise that agent pulled the entire company into a product-safety regime.

The boundary is also contested at the edges. Industry groups have asked the Commission for clearer guidance on hybrid cases, and harmonised standards are still being drafted. If you sit near the line, document your reasoning: which functions depend on the cloud, and which do not.

Where the company sits is irrelevant

None of this depends on where you are incorporated. The CRA applies to products placed on the EU market, so a US or Israeli company shipping a client to EU customers is covered exactly like a German one.

Sources, primary only: Regulation (EU) 2024/2847 — EUR-Lex · European Commission — CRA summary · European Commission — CRA reporting · ENISA — Single Reporting Platform. Not legal advice; the regulation text controls.

← All explainers