EU Cyber Resilience Act
Does the CRA apply to SaaS?
The Cyber Resilience Act targets products with digital elements, including the remote data-processing solutions necessary for a product to function. Pure standalone cloud services may sit outside, but software products and product-linked back ends are often in scope.
The actual test: product, not service
The CRA targets products with digital elements and the remote data-processing solutions necessary for them to function — not cloud services as a category. A pure, standalone web application with no hardware or client-side product component is the case most likely to sit outside CRA scope; a backend that exists specifically to support a connected product (a companion app tied to a physical device, for instance) is much more likely to be in scope as part of that product.
Where the line actually gets tested
The harder cases sit in the middle: a SaaS platform that's also distributed as an installable agent or on-prem component, or a service whose entire value depends on a client-side product you also sell. There's no shortcut for these — classify the specific offering, including whether it has any “digital element” distributed to a customer at all, rather than relying on the general “is SaaS covered” question.
What to build regardless
Whether or not you're ultimately in scope, the underlying evidence — an SBOM for your service's dependencies, a vulnerability-handling process, and documented essential-requirements coverage — is worth having on its own merits, and is exactly what you'd need if a later product decision (an on-prem version, a client SDK) brings you into scope.
What to focus on
- Distinguish a standalone service from a product (and its required back end).
- Where in scope, maintain an SBOM and vulnerability handling for the service.
- Document the essential requirements and update policy that apply.
- Confirm scope for your specific offering — don't rely on the general SaaS question.
Frequently asked questions
- Does the CRA apply to SaaS?
- The CRA covers products with digital elements and the remote data-processing solutions necessary for them to function. Whether a given SaaS is in scope depends on how it relates to a product — classify yours to be sure.
- What if I only sell a subscription, no hardware at all?
- Then you're less likely to be in scope — the CRA is anchored to products with digital elements. But if your service exists to support a connected product (yours or a partner's), that link can still bring it into scope.
General information about the EU Cyber Resilience Act — not legal advice. Normproof provides tooling and audit-ready evidence; the manufacturer self-declares conformity. For your specific product, run the free readiness check or consult a qualified advisor.