CRARequired.com

Does the CRA apply to password managers?

Likely yes

Likely yes. A password manager or VPN client is installed software with a network connection, supplied in the course of a commercial activity: a product with digital elements [[F-005]] [[F-007]]. Whether security software sits in an important class is decided in the full check.

The deciding factors

Factors the rules engine reads for this fact pattern, and what each outcome means.
FactorIf trueIf falseSource
Made available on the EU marketScope questions continueLikely out of scopeF-101
Supplied in the course of a commercial activityScope questions continueLikely out of scope (or the open-source light regime)F-007
Has a direct or indirect connection to a device or networkIt is a product with digital elementsLikely out of scopeF-005
Product cannot perform a function without your own backendThat remote processing is part of the productOnly the installed part is the productF-107

Check your own product

Start the short scope check with the product type pre-selected. Every legally material fact — EU availability, commercial activity, exclusions, your role — is asked, never assumed.

Check my product

Example scenarios

Each scenario is a fixture: the shared CEMarque rules engine evaluates its inputs at build time and the page cannot be served if the outcome shown here differs from the engine's.

Edge cases

Why

Security products are products

The definition of a product with digital elements is technology-neutral: software with a direct or indirect connection to a device or network, supplied commercially [1] [2]. A password manager, VPN client or endpoint agent meets it as plainly as any other installed application.

Sync and service backends

Most security software depends on a service: vault sync, VPN endpoints, threat feeds. Where the product is designed to rely on your own remote data processing and cannot perform a function without it, that remote processing is part of the product with digital elements [3] [4]. The scope check asks this directly.

Open source and paid hosting

Free and open-source software that is not monetised is not considered placed on the market [5]. Offering paid hosting or paid support for the same client is a commercial activity, and the supplied product is then in scope [2].

Class is a separate question

Applicability does not depend on the product's category. The class a security product falls in, and the conformity route that follows, are determined in the full cited check on CEMarque; this page only establishes that the Regulation applies [1].

Timing

Article 14 reporting applies from 2026-09-11; full requirements and CE marking apply from 2027-12-11. Dates come from the Facts Table entries cited below, evaluated for the first example; run the check for your own product's dates.

What to do next

CRARequired only answers applicability. CEMarque carries your answers forward and adds your role, class, conformity route, dates, obligations, and a permanent cited verdict.

Check my product Run the full cited determination on CEMarque

Related applicability questions

Sources

  1. F-005 A product with digital elements is a software or hardware product and its remote data processing solutions, including components placed on the market separately, whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Art. 3(1), Art. 2(1) EUR-Lex ↩
  2. F-007 The Regulation applies to products made available on the market in the course of a commercial activity; charging a price, charging for support, monetising via advertising or data, or otherwise intending to monetise are commercial activity. Art. 2(1), Art. 3(22), Recitals EUR-Lex ↩
  3. F-006 Remote data processing means data processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the product from performing one of its functions. Art. 3(2) EUR-Lex ↩
  4. F-107 Where a product depends on your own remote data processing (a backend or API without which it cannot perform one of its functions), that remote processing is part of the product: it is covered by the essential requirements, the technical documentation and market surveillance alongside the client software or device. Art. 3(1)–(2), Annex I, Annex VII EUR-Lex ↩
  5. F-009 Free and open-source software not monetised is not considered placed on the market. Open-source software stewards (legal persons that systematically support free and open-source software intended for commercial activities) have a light regime: a documented cybersecurity policy, cooperation with authorities, and Article 14 reporting only where they are involved in development or where an incident affects their own development infrastructure; they do not affix CE marking and are not subject to fines. Art. 3(14), Art. 3(48), Art. 24, Art. 64(10)(b), Recitals 18–19 EUR-Lex ↩
  6. F-101 Made available on the market means supply for distribution or use on the EU market in the course of a commercial activity. Art. 3(22) EUR-Lex ↩

Facts v2026.09.4 · rules v2026.09.1 · page RP-013 v1 · last verified 25 September 2026 · reviewed by Claude (delegated by Ron) on 8 October 2026 · content 58e364691c4a26b5

CRARequired answers applicability only, using scope logic and cited regulatory facts maintained by CEMarque, which encodes Regulation (EU) 2024/2847 and published guidance as of Facts v2026.09.4 (10 September 2026). Results are "likely" or "conditional" readings of your answers, not a legal opinion and not a conformity assessment. Run the full cited determination on CEMarque before you act. Methodology.