Defining Products with Digital Elements
Navigate the EU Cyber Resilience Act scope. Learn how software, connected hardware, and remote processing solutions define your mandatory legal obligations.

Under the EU Cyber Resilience Act (Regulation 2024/2847), a 'product with digital elements' encompasses any software or hardware and its associated remote data processing solutions that feature a logical or physical connection to a device or network. This broad scope captures commercial standalone software, IoT devices, embedded firmware, and SaaS components. Purely non-commercial open-source software remains outside this regulatory framework.
Core Scope Criteria for Covered Products
Regulatory bodies apply three technical benchmarks to determine if your offering falls under the CRA mandate:
- Logical or Physical Connectivity: Any capability to exchange data via network interfaces, protocols, or direct physical connections like USB, Bluetooth, or Ethernet.
- Commercial Activity: Products developed or supplied for commercial gain, including paid software, freemium services, and commercialized hardware.
- Remote Data Processing Solutions: Cloud services or backends developed or controlled by the manufacturer that are essential for the digital product's core functionality.
CRA Risk Classifications for Digital Products
The Cyber Resilience Act categorizes digital products into specific risk tiers to dictate the stringency of required security conformity assessments.
Default Class (Standard Software)
Covers the vast majority of commercial software, connected consumer goods, and development tools with standard security risk profiles.
Important Class I (Annex III)
Includes identity management software, password managers, web browsers, network interfaces, and system administration tools.
Important Class II (Annex III)
Applies to high-risk software such as firewalls, hypervisors, intrusion detection systems, and microprocessors requiring third-party audits.
Critical Class (Annex IV)
Covers hardware security modules, smartcards, and critical infrastructure control devices subject to rigorous conformity assessments.
Evaluating Your Software Stack and Connected Hardware
Determining if your technology falls under the CRA requires a comprehensive audit of both local software components and their associated cloud-based endpoints.
- Commercial desktop, mobile, and web-based applications
- Hardware devices integrating firmware, microcontrollers, or embedded OS
- SaaS architectures deploying local agents, desktop clients, or mobile apps
- Proprietary software integrated into third-party industrial machinery

Key Exemptions and Boundary Conditions
While the CRA scope is extensive, specific categories are explicitly excluded from its requirements:
- Open Source Software: Non-commercial open-source projects are exempt. However, if an open-source component is integrated into a commercial product, the manufacturer assumes full liability.
- Sector-Specific Regulations: Products already governed by equivalent cybersecurity regimes, such as medical devices (MDR), aviation equipment, or motor vehicles, are exempt.
- Pure Cloud Services: Cloud platforms (SaaS/PaaS/IaaS) lacking any downloadable client, agent, or remote processing tie-in to a physical product fall under the NIS2 Directive.
Critical Enforcement Deadlines and Regulatory Penalties
The Cyber Resilience Act took effect on 10 December 2024. Companies must meet two critical compliance milestones:
- 11 September 2026: Mandatory reporting of exploited vulnerabilities and incidents to ENISA and national CSIRTs (24h early warnings, 72h notifications, 14d final reports).
- 11 December 2027: Full implementation of security controls, Annex VII technical documentation, and EU Declarations of Conformity for all products on the EU market.
Non-compliance risks severe administrative fines reaching up to EUR 15 million or 2.5% of total worldwide annual turnover, whichever is higher.
Identify CRA Vulnerabilities in Your Repositories
Connect your GitHub repositories to generate automated Software Bills of Materials (SBOM) and calculate your current compliance score.
4 Steps to Prepare Your Digital Products for CRA Compliance
- 1
1. Map Your Architecture
Inventory all software components, dependencies, firmware, and connected remote data processing services across your product ecosystem.
- 2
2. Generate Automated SBOMs
Export detailed Software Bills of Materials supporting npm, PyPI, Go, Rust, .NET, PHP, Ruby, Java, and CycloneDX formats.
- 3
3. Set Up Continuous Vulnerability Monitoring
Track disclosed vulnerabilities in real-time to satisfy the mandatory 24h/72h/14d ENISA incident reporting requirements.
- 4
4. Assemble Annex VII Technical Documentation
Generate pre-filled technical files, SECURITY.md policies, and EU Declaration of Conformity drafts to support your self-assessment.
How CRAcheck Assists Affected Companies
Navigating the CRA requires deep visibility into your codebase. CRAcheck provides a dedicated self-assessment platform for software vendors and hardware manufacturers.
- GitHub Repository Integration: Connect your repositories to instantly inspect direct and transitive software dependencies.
- Multi-Ecosystem SBOM Generation: Automatically create standard CycloneDX SBOMs across 9 key ecosystems including npm, PyPI, Go, and Java.
- Compliance Scorecard: Receive a benchmark score out of 100 evaluating your technical readiness against CRA standards.
- Pre-filled Documentation Workflows: Export drafts for EU Declarations of Conformity, Annex VII documentation, and ENISA notification templates.
Note: CRAcheck is a self-assessment support tool and does not replace mandatory third-party audits or official notified body certifications.
Frequently Asked Questions About Products with Digital Elements
Is a SaaS backend considered a product with digital elements?+
Pure SaaS solutions typically fall under NIS2. However, if your SaaS requires a local client, mobile app, agent, or connected hardware, those components and their coupled remote processing solutions qualify under the CRA.
Are open-source libraries integrated into commercial software subject to CRA?+
Yes. While standalone non-commercial open-source projects are exempt, any open-source code integrated into a commercial product becomes the manufacturer's regulatory responsibility.
When do CRA enforcement actions begin?+
Vulnerability reporting obligations commence on 11 September 2026. Full technical compliance and CE marking requirements become mandatory on 11 December 2027.
Does CRAcheck certify my software as compliant?+
No. CRAcheck is a self-assessment tool designed to help you organize SBOMs, track security risks, and prepare documentation. It does not issue official regulatory certifications.
Prepare Your Digital Products for the EU CRA
Evaluate your codebase, calculate your compliance score, and build automated SBOMs with CRAcheck today.
Same topic — Glossaire
New to the Cyber Resilience Act? Start with the complete guide.
The CRA guideFrom the blog
Check your CRA compliance in 1 minute
Free, no sign-up. Scan your repo and get your compliance score + pre-filled documents.