CRARequired.com

Does the CRA apply to SaaS?

It depends

It depends on one fact. A cloud service that is not part of a product is outside the Regulation and may fall under NIS2 instead [[F-008]]. But where your own backend is essential to an installed app, agent or device, that remote data processing is part of the product and in scope with it [[F-006]] [[F-107]].

The deciding factors

Factors the rules engine reads for this fact pattern, and what each outcome means.
FactorIf trueIf falseSource
Made available on the EU marketScope questions continueLikely out of scopeF-101
Supplied in the course of a commercial activityScope questions continueLikely out of scope (or the open-source light regime)F-007
Any installed component, device or downloadable clientThat part is a product with digital elementsNot a product; NIS2 may applyF-005
Product cannot perform a function without your own backendThat remote processing is part of the productOnly the installed part is the productF-107

Check your own product

Start the short scope check with the product type pre-selected. Every legally material fact — EU availability, commercial activity, exclusions, your role — is asked, never assumed.

Check my product

Example scenarios

Each scenario is a fixture: the shared CEMarque rules engine evaluates its inputs at build time and the page cannot be served if the outcome shown here differs from the engine's.

Edge cases

Why

Two regimes, one boundary

This Regulation regulates products. Cloud services that are not part of a product are outside it and may fall under the NIS2 Directive instead [1] [2]. The boundary is not "does it run on a server" but "is there a product with digital elements, and is this service part of it".

The remote data processing test

Remote data processing is processing at a distance for which the software is designed and developed by the manufacturer, or under the manufacturer's responsibility, and without which the product could not perform one of its functions [3]. Where that is true of your backend, the backend is part of the product and is covered by the same essential requirements and documentation as the installed part [4].

Ask two questions. Did you design the backend for this product [3]? Would a function stop working without it [3]? Two yeses, and the backend travels with the product into scope [4].

What is outside

A web application with no installed component, no device and no downloadable client is not a product with digital elements [5] [1]. Your obligations there come from NIS2 if you fall within its scope, and from other rules, not from this Regulation [2]. Establish which applies rather than assuming the cautious answer: the two regimes impose different kinds of obligation, so preparing for the wrong one wastes effort [1] [2].

Common shapes

A browser product with a companion desktop agent, a mobile app whose features are server-side, a device that is inert without your cloud, a CLI that calls your API: each has an installed or shipped part, and each depends on your own remote processing, so each is a product in scope together with its backend [5] [4]. A pure dashboard you log into is not [5].

What to do next

CRARequired only answers applicability. CEMarque carries your answers forward and adds your role, class, conformity route, dates, obligations, and a permanent cited verdict.

Check my product Run the full cited determination on CEMarque

Related applicability questions

Sources

  1. F-008 Cloud services that are not part of a product are outside the Regulation (they fall under NIS2); remote data processing essential to a product is within scope as part of that product. Art. 3(1)–(2), Recitals EUR-Lex ↩
  2. F-103 Cloud services may fall under NIS2 (Directive (EU) 2022/2555) rather than the CRA. NIS2 EUR-Lex ↩
  3. F-006 Remote data processing means data processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the product from performing one of its functions. Art. 3(2) EUR-Lex ↩
  4. F-107 Where a product depends on your own remote data processing (a backend or API without which it cannot perform one of its functions), that remote processing is part of the product: it is covered by the essential requirements, the technical documentation and market surveillance alongside the client software or device. Art. 3(1)–(2), Annex I, Annex VII EUR-Lex ↩
  5. F-005 A product with digital elements is a software or hardware product and its remote data processing solutions, including components placed on the market separately, whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Art. 3(1), Art. 2(1) EUR-Lex ↩
  6. F-007 The Regulation applies to products made available on the market in the course of a commercial activity; charging a price, charging for support, monetising via advertising or data, or otherwise intending to monetise are commercial activity. Art. 2(1), Art. 3(22), Recitals EUR-Lex ↩
  7. F-101 Made available on the market means supply for distribution or use on the EU market in the course of a commercial activity. Art. 3(22) EUR-Lex ↩

Facts v2026.09.4 · rules v2026.09.1 · page RP-002 v1 · last verified 25 September 2026 · reviewed by Claude (delegated by Ron) on 8 October 2026 · content d26903ac3684ec51

CRARequired answers applicability only, using scope logic and cited regulatory facts maintained by CEMarque, which encodes Regulation (EU) 2024/2847 and published guidance as of Facts v2026.09.4 (10 September 2026). Results are "likely" or "conditional" readings of your answers, not a legal opinion and not a conformity assessment. Run the full cited determination on CEMarque before you act. Methodology.