A service accessed exclusively through a browser is generally outside CRA product scope on that basis alone. A backend that meets the remote data processing definition can form part of a covered product. The architecture and functional relationship determine the answer.
Apply this to your product

Answer the questions and see the reasoning.

Open saas & cloud scope

Separate a web service from a supplied product

The July 2026 Commission guidance distinguishes software supplied for local execution from software merely accessed remotely. A website or browser-only web application is not itself a product with digital elements simply because browser code executes on the user’s device.

A locally installed companion application is a different product boundary. Identify what the user obtains and runs, then check the associated backend separately. A browser extension or installed client should not be treated as pure SaaS without assessment.

Guidance section 2.2; Article 3(1)–(2)Commission guidance CRA text

Test the backend against both conditions

Remote data processing requires software designed and developed by the manufacturer or under its responsibility. Its absence must prevent the product from performing one of its functions. The test is not limited to the main or most commercially important function.

An unrelated web service used by the same customer is not automatically part of your product. Conversely, moving a necessary product function to the cloud does not automatically remove that function from CRA scope.

Article 3(2); guidance section 8CRA text Commission guidance

Typical SaaS arrangements

A browser-only invoicing service with no supplied client and no function supporting another digital product is likely outside product scope. An installed desktop agent relying on the supplier’s backend for a promised function needs a combined product assessment.

Optional supplier analytics that do not deliver a function of the user’s product generally differ from cloud processing needed for a product function. The word “optional” is not enough: record what stops working when the service is removed.

Guidance sections 2.2 and 8Commission guidance

Classification and responsibility

If the service is part of a product, classify the product as a whole by core functionality. Hosting does not create a separate Default exemption or automatically make the product Critical. The manufacturer must address covered remote processing in the product risk assessment and documentation.

Other laws may apply to services outside CRA product scope. An outside-scope result here is limited to the CRA question and does not assess NIS2, data protection or sector-specific rules.

Dates and next actions

Article 14 reporting for manufacturers applies from 11 September 2026, including to older in-scope products. Most requirements apply from 11 December 2027, subject to the rules for products already placed on the market and subsequent substantial modifications.

If you are the manufacturer of an in-scope product, establish the product risk assessment, support-period decision, vulnerability handling and technical documentation. Select the applicable conformity route before making a compliance claim. A reseller should use the importer and distributor assessment for its distinct duties.

Articles 13, 14, 19–20, 32, 69 and 71CRA text ↗

Frequently asked questions

Are all SaaS products excluded?

No. Pure remote service access and a backend forming part of a supplied product need different analyses.

Must the cloud support the product’s primary function?

The definition refers to one of its functions. Restricting the test to a primary function can incorrectly exclude relevant processing.

This guide supports an initial assessment. Your result depends on the product facts and the applicable measures. Read how to use this guidance.