EU Cyber Resilience Act

Does the CRA apply to SaaS?

The Cyber Resilience Act targets products with digital elements, including the remote data-processing solutions necessary for a product to function. Pure standalone cloud services may sit outside, but software products and product-linked back ends are often in scope.

The actual test: product, not service

The CRA targets products with digital elements and the remote data-processing solutions necessary for them to function — not cloud services as a category. A pure, standalone web application with no hardware or client-side product component is the case most likely to sit outside CRA scope; a backend that exists specifically to support a connected product (a companion app tied to a physical device, for instance) is much more likely to be in scope as part of that product.

Where the line actually gets tested

The harder cases sit in the middle: a SaaS platform that's also distributed as an installable agent or on-prem component, or a service whose entire value depends on a client-side product you also sell. There's no shortcut for these — classify the specific offering, including whether it has any “digital element” distributed to a customer at all, rather than relying on the general “is SaaS covered” question.

What to build regardless

Whether or not you're ultimately in scope, the underlying evidence — an SBOM for your service's dependencies, a vulnerability-handling process, and documented essential-requirements coverage — is worth having on its own merits, and is exactly what you'd need if a later product decision (an on-prem version, a client SDK) brings you into scope.

What to focus on

  • Distinguish a standalone service from a product (and its required back end).
  • Where in scope, maintain an SBOM and vulnerability handling for the service.
  • Document the essential requirements and update policy that apply.
  • Confirm scope for your specific offering — don't rely on the general SaaS question.

Frequently asked questions

Does the CRA apply to SaaS?
The CRA covers products with digital elements and the remote data-processing solutions necessary for them to function. Whether a given SaaS is in scope depends on how it relates to a product — classify yours to be sure.
What if I only sell a subscription, no hardware at all?
Then you're less likely to be in scope — the CRA is anchored to products with digital elements. But if your service exists to support a connected product (yours or a partner's), that link can still bring it into scope.

General information about the EU Cyber Resilience Act — not legal advice. Normproof provides tooling and audit-ready evidence; the manufacturer self-declares conformity. For your specific product, run the free readiness check or consult a qualified advisor.

See what the CRA requires for your saas & web products.

Run the free readiness check — your category, obligations, and deadlines in 60 seconds.