Cyber Resilience Act · 2026/2027
Does the Cyber Resilience Act apply to my product?
Informational content. It does not replace individual legal advice or conformity assessment.
CRA scope is not determined by the company’s industry alone or by labels such as “SaaS”, “IoT” or “software vendor”. Start with the specific product with digital elements, how it is made available on the EU market, the organisation’s role and any remote data processing that is part of the product’s functionality.
The output should be a documented scope assessment with a visible basis for the conclusion — not an unexplained yes/no result.
Step 1. Identify the product
Start with the thing a user actually buys, downloads, installs, integrates or receives as a component.
Record:
- product name and identifier;
- version or version family;
- intended purpose;
- main functions;
- delivery model;
- brand under which it reaches the market;
- markets where it is made available.
If the team cannot draw the product boundary, the rest of the assessment will depend on assumptions that are difficult to review later.
Step 2. Check the definition of a product with digital elements
The CRA defines a product with digital elements as a software or hardware product and its remote data processing solutions. Software or hardware components placed on the market separately can also fall within the definition.
For remote services, the functional relationship matters. The Regulation describes remote data processing as processing at a distance for which the software is designed and developed by or under the responsibility of the manufacturer and whose absence would prevent the product from performing one of its functions.
This is why “it runs in the cloud” is not a sufficient scope test. Map the product and dependencies first.
Step 3. Determine the organisation’s role
The relevant role may be:
- manufacturer;
- authorised representative;
- importer;
- distributor;
- another person carrying out a substantial modification and making the product available on the market.
One important case is an importer or distributor that places a product on the market under its own name or trademark, or substantially modifies it. Under the CRA, manufacturer obligations can then apply to that actor.
Step 4. Do not ignore products already on the market
The main CRA requirements apply from 11 December 2027, but that does not mean products already on the market can be ignored for reporting today.
Article 69(3) states that Article 14 reporting obligations apply to products with digital elements that fall within the scope of the Regulation even if they were placed on the market before 11 December 2027.
For an existing product that is still in use, the vulnerability and incident reporting workflow is therefore a current operational question.
Step 5. Check exclusions and sector-specific legislation
Do not rely on a short online list of “industries excluded from CRA”. The Regulation has its own scope, exclusions and interactions with sector-specific EU law.
A defensible process is to:
- record the legal provision and source used for the assessment;
- record the review date;
- separate facts from assumptions;
- flag questions that require qualified legal review instead of converting uncertainty into a confident product claim.
Minimum scope-assessment record
| Field | What to record |
|---|---|
| Product | name, version, identifier |
| Organisation role | manufacturer / importer / distributor / other |
| Market | where the product is made available |
| Digital functions | software, hardware, interfaces, components |
| Remote processing | what runs remotely and whether it is required for a product function |
| Basis | CRA provision, Commission guidance, assumptions |
| Result | likely in scope / likely out of scope / needs deeper assessment |
| Decision owner | person approving the assessment |
| Review date | when the decision should be revisited |
When to reassess
A scope assessment should not become a forgotten PDF. Revisit it when, for example:
- the intended purpose changes;
- a new remote service becomes necessary for a product function;
- the product is substantially modified;
- the distribution model or brand changes;
- the organisation takes on a different economic-operator role;
- new Commission or authority guidance changes the basis of the decision.
How Pulsar keeps the decision traceable
Pulsar can keep the basis of the assessment with supporting documents and connect the outcome to risks, actions and evidence. The value is not an unexplained automated answer. It is the ability to show later what was assessed, which sources were used, who approved the outcome and what actions followed.
Pulsar does not replace individual legal assessment.
See how to run one assessment in Pulsar GRC
Related guidance
Sources
- Regulation (EU) 2024/2847 — EUR-Lex
- European Commission — CRA legislative summary
- European Commission — CRA guidance, 27 July 2026
Sources checked: 12 September 2026.