Does the CRA apply to password managers?
Likely yes
Likely yes. A password manager or VPN client is installed software with a network connection, supplied in the course of a commercial activity: a product with digital elements [[F-005]] [[F-007]]. Whether security software sits in an important class is decided in the full check.
The deciding factors
| Factor | If true | If false | Source |
|---|---|---|---|
| Made available on the EU market | Scope questions continue | Likely out of scope | F-101 |
| Supplied in the course of a commercial activity | Scope questions continue | Likely out of scope (or the open-source light regime) | F-007 |
| Has a direct or indirect connection to a device or network | It is a product with digital elements | Likely out of scope | F-005 |
| Product cannot perform a function without your own backend | That remote processing is part of the product | Only the installed part is the product | F-107 |
Check your own product
Start the short scope check with the product type pre-selected. Every legally material fact — EU availability, commercial activity, exclusions, your role — is asked, never assumed.
Example scenarios
-
Subscription password manager with desktop and mobile apps
Likely in scope · role: _
Installed software sold in the EU: a product with digital elements in scope.
Deciding fact: Art. 3(1), Art. 2(1)
-
VPN client that cannot connect without your own service
Likely in scope · role: _ · remote processing in scope
The client is the product, and because it cannot perform its function without your backend, that remote processing is part of it.
Deciding fact: Art. 3(1), Art. 2(1)
-
Open-source password manager stewarded by a non-profit foundation, no paid tier
Open-source light regime may apply · role: _
Free and open-source software that is not monetised is not considered placed on the market.
Deciding fact: Art. 3(14), Art. 3(48), Art. 24, Art. 64(10)(b), Recitals 18–19
-
Security app sold only in markets outside the EU
Likely out of scope · role: _
Not made available on the EU market, so the Regulation does not apply.
Deciding fact: Art. 3(22)
Each scenario is a fixture: the shared CEMarque rules engine evaluates its inputs at build time and the page cannot be served if the outcome shown here differs from the engine's.
Edge cases
- _
- _
- _
- _
Why
Security products are products
The definition of a product with digital elements is technology-neutral: software with a direct or indirect connection to a device or network, supplied commercially [1] [2]. A password manager, VPN client or endpoint agent meets it as plainly as any other installed application.
Sync and service backends
Most security software depends on a service: vault sync, VPN endpoints, threat feeds. Where the product is designed to rely on your own remote data processing and cannot perform a function without it, that remote processing is part of the product with digital elements [3] [4]. The scope check asks this directly.
Open source and paid hosting
Free and open-source software that is not monetised is not considered placed on the market [5]. Offering paid hosting or paid support for the same client is a commercial activity, and the supplied product is then in scope [2].
Class is a separate question
Applicability does not depend on the product's category. The class a security product falls in, and the conformity route that follows, are determined in the full cited check on CEMarque; this page only establishes that the Regulation applies [1].
Timing
Article 14 reporting applies from 2026-09-11; full requirements and CE marking apply from 2027-12-11. Dates come from the Facts Table entries cited below, evaluated for the first example; run the check for your own product's dates.
What to do next
CRARequired only answers applicability. CEMarque carries your answers forward and adds your role, class, conformity route, dates, obligations, and a permanent cited verdict.
Check my product Run the full cited determination on CEMarque
Related applicability questions
Sources
- F-005 A product with digital elements is a software or hardware product and its remote data processing solutions, including components placed on the market separately, whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Art. 3(1), Art. 2(1) EUR-Lex ↩
- F-007 The Regulation applies to products made available on the market in the course of a commercial activity; charging a price, charging for support, monetising via advertising or data, or otherwise intending to monetise are commercial activity. Art. 2(1), Art. 3(22), Recitals EUR-Lex ↩
- F-006 Remote data processing means data processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the product from performing one of its functions. Art. 3(2) EUR-Lex ↩
- F-107 Where a product depends on your own remote data processing (a backend or API without which it cannot perform one of its functions), that remote processing is part of the product: it is covered by the essential requirements, the technical documentation and market surveillance alongside the client software or device. Art. 3(1)–(2), Annex I, Annex VII EUR-Lex ↩
- F-009 Free and open-source software not monetised is not considered placed on the market. Open-source software stewards (legal persons that systematically support free and open-source software intended for commercial activities) have a light regime: a documented cybersecurity policy, cooperation with authorities, and Article 14 reporting only where they are involved in development or where an incident affects their own development infrastructure; they do not affix CE marking and are not subject to fines. Art. 3(14), Art. 3(48), Art. 24, Art. 64(10)(b), Recitals 18–19 EUR-Lex ↩
- F-101 Made available on the market means supply for distribution or use on the EU market in the course of a commercial activity. Art. 3(22) EUR-Lex ↩
CRARequired answers applicability only, using scope logic and cited regulatory facts maintained by CEMarque, which encodes Regulation (EU) 2024/2847 and published guidance as of Facts v2026.09.4 (10 September 2026). Results are "likely" or "conditional" readings of your answers, not a legal opinion and not a conformity assessment. Run the full cited determination on CEMarque before you act. Methodology.