SaaS and web applications
Does the Cyber Resilience Act apply to SaaS?
Pure SaaS is the segment most likely to be wrong in both directions. Teams assume the CRA is a hardware regulation and stop reading, or assume everything digital is caught and start a programme they may not need. The deciding question is narrower than either.
This page does not tell you whether the CRA applies to you. It cannot: the answer turns on inputs only you have. What it does is name the questions that decide it, with the article behind each, so the free check takes two minutes instead of an afternoon.
The assumption to check first
“We ship no software to anyone, so the CRA cannot reach us.”
Often true, and it stops being true the moment your service is what makes a product work. Article 3(2) defines a remote data processing solution, and a service that satisfies all three of its legs is treated as part of the product with digital elements.
What actually decides it
Is data processed at a distance?
Article 3(2), Regulation (EU) 2024/2847
First of three legs. All three must hold, so this alone decides nothing.
Is the processing done by or on behalf of the manufacturer?
Article 3(2), Regulation (EU) 2024/2847
Second leg. A third-party SaaS a customer happens to use is not this.
Would the absence of that processing break a function of the product?
Article 3(2), Regulation (EU) 2024/2847
Third leg, and the one that usually decides. Degraded is not broken. If the device still does its job without your service, this leg fails and the CRA does not reach you through it.
Is it supplied in the course of a commercial activity?
Article 3(22), Regulation (EU) 2024/2847
Paid or free makes no difference. "Free" is the most common reason a team wrongly assumes it is out.
Is the product placed on the EU market?
Article 2(1), Regulation (EU) 2024/2847
Scope follows the market, not your address. A company outside the EU that sells into it is in; an EU company selling only elsewhere is not.
What to do next
- 1.Run the scope check with your real answers rather than the ones you expect.
- 2.If it comes back outside scope, keep the determination. It is a two-minute answer to a question a customer will eventually ask in a security review.
- 3.If it comes back inside scope, the reporting clock is the near-term problem, not the essential requirements.