CRA by product type
Start with what you build or supply. Explore concrete CRA scenarios for software, connected hardware, cloud services and open-source projects.
Does the Cyber Resilience Act apply to SaaS?
A service accessed exclusively through a browser is generally outside CRA product scope on that basis alone. A backend that meets the remote data processing definition can form part of a covered product. The architecture and functional relationship determine the answer.
Read the guide CRA for mobile appsDoes the Cyber Resilience Act apply to mobile apps?
An app supplied for installation and execution on a phone can be a product with digital elements. If commercially supplied on the EU market and not excluded, it is likely within CRA scope, even when the download is free.
Read the guide CRA for desktop softwareDoes the Cyber Resilience Act apply to desktop software?
Commercial desktop software supplied for local execution on the EU market is likely within CRA scope if the connectivity criteria are met and no exclusion applies. The programming language or installer format does not decide the result.
Read the guide CRA for connected devicesDoes the Cyber Resilience Act apply to IoT devices?
Connected hardware commercially supplied on the EU market is commonly within CRA scope. Assess the device, embedded software and qualifying remote processing as a product, then check any sector exclusion and its actual core functionality.
Read the guide CRA for libraries & componentsDoes the Cyber Resilience Act apply to software libraries?
A separately supplied software library can be a product with digital elements. Commercial supply, FOSS distribution and stewardship must be assessed separately from the obligations of a manufacturer integrating the library.
Read the guide CRA for routers & networkingCyber Resilience Act requirements for routers
A product whose core functionality matches the router description in Implementing Regulation 2025/2392 is likely Important Class I. That category does not automatically mean every router needs a notified body; Article 32 conditions determine the route.
Read the guide CRA for firewalls & intrusion protectionCyber Resilience Act requirements for firewalls
A product whose core functionality matches the firewall, intrusion detection or intrusion prevention description is likely Important Class II. It generally requires third-party assessment, subject to the CRA’s specific conditions and exceptions.
Read the guide CRA for open-source projectsDoes the Cyber Resilience Act apply to open-source software?
FOSS developed or supplied outside a commercial activity is excluded from ordinary CRA product obligations. Commercial editions can be covered, and qualifying legal entities sustaining specific FOSS can have the separate obligations of a software steward.
Read the guide