CRA reporting obligations apply from 11 September 2026View the timeline
Practical CRA guidance

CRA by product type

Start with what you build or supply. Explore concrete CRA scenarios for software, connected hardware, cloud services and open-source projects.

CRA for SaaS & cloud services

Does the Cyber Resilience Act apply to SaaS?

A service accessed exclusively through a browser is generally outside CRA product scope on that basis alone. A backend that meets the remote data processing definition can form part of a covered product. The architecture and functional relationship determine the answer.

Read the guide
CRA for mobile apps

Does the Cyber Resilience Act apply to mobile apps?

An app supplied for installation and execution on a phone can be a product with digital elements. If commercially supplied on the EU market and not excluded, it is likely within CRA scope, even when the download is free.

Read the guide
CRA for desktop software

Does the Cyber Resilience Act apply to desktop software?

Commercial desktop software supplied for local execution on the EU market is likely within CRA scope if the connectivity criteria are met and no exclusion applies. The programming language or installer format does not decide the result.

Read the guide
CRA for connected devices

Does the Cyber Resilience Act apply to IoT devices?

Connected hardware commercially supplied on the EU market is commonly within CRA scope. Assess the device, embedded software and qualifying remote processing as a product, then check any sector exclusion and its actual core functionality.

Read the guide
CRA for libraries & components

Does the Cyber Resilience Act apply to software libraries?

A separately supplied software library can be a product with digital elements. Commercial supply, FOSS distribution and stewardship must be assessed separately from the obligations of a manufacturer integrating the library.

Read the guide
CRA for routers & networking

Cyber Resilience Act requirements for routers

A product whose core functionality matches the router description in Implementing Regulation 2025/2392 is likely Important Class I. That category does not automatically mean every router needs a notified body; Article 32 conditions determine the route.

Read the guide
CRA for firewalls & intrusion protection

Cyber Resilience Act requirements for firewalls

A product whose core functionality matches the firewall, intrusion detection or intrusion prevention description is likely Important Class II. It generally requires third-party assessment, subject to the CRA’s specific conditions and exceptions.

Read the guide
CRA for open-source projects

Does the Cyber Resilience Act apply to open-source software?

FOSS developed or supplied outside a commercial activity is excluded from ordinary CRA product obligations. Commercial editions can be covered, and qualifying legal entities sustaining specific FOSS can have the separate obligations of a software steward.

Read the guide