Cyber Resilience Act · 2026/2027

Does the Cyber Resilience Act apply to my product?

Informational content. It does not replace individual legal advice or conformity assessment.

CRA scope is not determined by the company’s industry alone or by labels such as “SaaS”, “IoT” or “software vendor”. Start with the specific product with digital elements, how it is made available on the EU market, the organisation’s role and any remote data processing that is part of the product’s functionality.

The output should be a documented scope assessment with a visible basis for the conclusion — not an unexplained yes/no result.

Step 1. Identify the product

Start with the thing a user actually buys, downloads, installs, integrates or receives as a component.

Record:

  • product name and identifier;
  • version or version family;
  • intended purpose;
  • main functions;
  • delivery model;
  • brand under which it reaches the market;
  • markets where it is made available.

If the team cannot draw the product boundary, the rest of the assessment will depend on assumptions that are difficult to review later.

Step 2. Check the definition of a product with digital elements

The CRA defines a product with digital elements as a software or hardware product and its remote data processing solutions. Software or hardware components placed on the market separately can also fall within the definition.

For remote services, the functional relationship matters. The Regulation describes remote data processing as processing at a distance for which the software is designed and developed by or under the responsibility of the manufacturer and whose absence would prevent the product from performing one of its functions.

This is why “it runs in the cloud” is not a sufficient scope test. Map the product and dependencies first.

Step 3. Determine the organisation’s role

The relevant role may be:

  • manufacturer;
  • authorised representative;
  • importer;
  • distributor;
  • another person carrying out a substantial modification and making the product available on the market.

One important case is an importer or distributor that places a product on the market under its own name or trademark, or substantially modifies it. Under the CRA, manufacturer obligations can then apply to that actor.

Step 4. Do not ignore products already on the market

The main CRA requirements apply from 11 December 2027, but that does not mean products already on the market can be ignored for reporting today.

Article 69(3) states that Article 14 reporting obligations apply to products with digital elements that fall within the scope of the Regulation even if they were placed on the market before 11 December 2027.

For an existing product that is still in use, the vulnerability and incident reporting workflow is therefore a current operational question.

Step 5. Check exclusions and sector-specific legislation

Do not rely on a short online list of “industries excluded from CRA”. The Regulation has its own scope, exclusions and interactions with sector-specific EU law.

A defensible process is to:

  1. record the legal provision and source used for the assessment;
  2. record the review date;
  3. separate facts from assumptions;
  4. flag questions that require qualified legal review instead of converting uncertainty into a confident product claim.

Minimum scope-assessment record

Field What to record
Product name, version, identifier
Organisation role manufacturer / importer / distributor / other
Market where the product is made available
Digital functions software, hardware, interfaces, components
Remote processing what runs remotely and whether it is required for a product function
Basis CRA provision, Commission guidance, assumptions
Result likely in scope / likely out of scope / needs deeper assessment
Decision owner person approving the assessment
Review date when the decision should be revisited

When to reassess

A scope assessment should not become a forgotten PDF. Revisit it when, for example:

  • the intended purpose changes;
  • a new remote service becomes necessary for a product function;
  • the product is substantially modified;
  • the distribution model or brand changes;
  • the organisation takes on a different economic-operator role;
  • new Commission or authority guidance changes the basis of the decision.

How Pulsar keeps the decision traceable

Pulsar can keep the basis of the assessment with supporting documents and connect the outcome to risks, actions and evidence. The value is not an unexplained automated answer. It is the ability to show later what was assessed, which sources were used, who approved the outcome and what actions followed.

Pulsar does not replace individual legal assessment.

See how to run one assessment in Pulsar GRC

Sources

Sources checked: 12 September 2026.