Answer the questions and see the reasoning.
Separate a web service from a supplied product
The July 2026 Commission guidance distinguishes software supplied for local execution from software merely accessed remotely. A website or browser-only web application is not itself a product with digital elements simply because browser code executes on the user’s device.
A locally installed companion application is a different product boundary. Identify what the user obtains and runs, then check the associated backend separately. A browser extension or installed client should not be treated as pure SaaS without assessment.
Test the backend against both conditions
Remote data processing requires software designed and developed by the manufacturer or under its responsibility. Its absence must prevent the product from performing one of its functions. The test is not limited to the main or most commercially important function.
An unrelated web service used by the same customer is not automatically part of your product. Conversely, moving a necessary product function to the cloud does not automatically remove that function from CRA scope.
Typical SaaS arrangements
A browser-only invoicing service with no supplied client and no function supporting another digital product is likely outside product scope. An installed desktop agent relying on the supplier’s backend for a promised function needs a combined product assessment.
Optional supplier analytics that do not deliver a function of the user’s product generally differ from cloud processing needed for a product function. The word “optional” is not enough: record what stops working when the service is removed.
Classification and responsibility
If the service is part of a product, classify the product as a whole by core functionality. Hosting does not create a separate Default exemption or automatically make the product Critical. The manufacturer must address covered remote processing in the product risk assessment and documentation.
Other laws may apply to services outside CRA product scope. An outside-scope result here is limited to the CRA question and does not assess NIS2, data protection or sector-specific rules.
Dates and next actions
Article 14 reporting for manufacturers applies from 11 September 2026, including to older in-scope products. Most requirements apply from 11 December 2027, subject to the rules for products already placed on the market and subsequent substantial modifications.
If you are the manufacturer of an in-scope product, establish the product risk assessment, support-period decision, vulnerability handling and technical documentation. Select the applicable conformity route before making a compliance claim. A reseller should use the importer and distributor assessment for its distinct duties.
Frequently asked questions
Are all SaaS products excluded?
No. Pure remote service access and a backend forming part of a supplied product need different analyses.
Must the cloud support the product’s primary function?
The definition refers to one of its functions. Restricting the test to a primary function can incorrectly exclude relevant processing.