Answer the questions and see the reasoning.
A practical sequence for determining scope
First identify the actual product or separately supplied component. Then establish its intended and foreseeable connections, EU supply and commercial context. Check exclusions only after identifying the product accurately.
The supply of a product and its use inside an organisation are different facts. Mere internal use does not automatically establish that a product was made available on the market. A free download can still be supplied commercially, while publication of community source code may not be commercial supply.
- Define the product and the relevant version or unit.
- Identify the entity responsible for that supply.
- Check EU market availability and the commercial arrangement.
- Examine product-specific exclusions and any special FOSS role.
Connectivity includes more than the internet
The connection can be logical or physical, direct or indirect, to a device or a network. A product operating locally is not automatically excluded simply because it never contacts a cloud server. Software can interact with a host system; hardware can communicate through local interfaces.
Keep the distinction between software supplied for execution by the user and a service merely accessed remotely. The Commission guidance treats locally installed clients, including those built with web technologies, differently from websites accessed exclusively in a browser.
Read sector exclusions narrowly
Certain products covered by medical-device, in-vitro diagnostic, motor-vehicle and civil-aviation legislation are excluded under the conditions in Article 2. Marine equipment and products exclusively developed or modified for national security or defence also require checking the specific exclusion text.
The exclusion is not an industry-wide exemption for every component or software tool used by a hospital, aircraft manufacturer or defence supplier. Delegated Regulation 2025/1535 also addresses certain products covered by the L-category vehicle framework. If coverage under the sectoral act is uncertain, seek further assessment.
Distinguish FOSS supply from stewardship
Non-commercial FOSS is excluded from the ordinary product obligations, but a legal entity sustaining specific FOSS intended for commercial activities may qualify as a steward under Article 24. Contributors do not automatically become manufacturers.
Optional paid consulting around freely available FOSS does not by itself make its supply commercial. Access to a paid edition or maintenance conditioned on remuneration is a different scenario. Pure recovery of actual costs can be treated differently from profit-seeking supply. Assess the particular edition, supplier and arrangement.
Keep a record of the boundary decision
Retain a short architecture description, distribution terms, a list of remote dependencies and the evidence for any exclusion. Revisit the decision when the product, delivery model, branding or commercial arrangement changes.
Once scope and role are established, classification is the next step. Scope alone does not determine whether internal control or a notified body is available for conformity assessment.
Frequently asked questions
Is a software library a product?
A separately supplied software component can be a product with digital elements. Its commercial supply and any FOSS treatment still need to be assessed.
Does a cloud dependency always fall within scope?
No. The definition requires a functional dependency and software designed or developed by or under the responsibility of the manufacturer. It is not enough that a service is useful to the business.