Cyber Resilience Act

Data connection

Practical term

The data connection is the feature on which the Cyber Resilience Act (CRA) hangs its entire scope. Under Article 2(1) the Regulation applies to products with digital elements made available on the market whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network.

The CRA nowhere defines the phrase “data connection” itself, and it defines neither “device” nor “network”. What it does define are the three qualifiers that give the sentence its reach: logical connection in Article 3, point (8), physical connection in point (9), indirect connection in point (10). Whether a product with digital elements is covered turns on those three.

Two tests, one variant each is enough

Article 2(1) combines two questions. One concerns the connection itself, the other what brings it about. Both have to be answered, but within each question a single variant suffices.

That also fixes the order. Starting with the kind of connection a product has is starting at the wrong end. Ask first what belongs to the intended purpose and the foreseeable use, and only then in which of the four forms the connection appears there. The indirect variant reaches furthest, because it catches products with no network access of their own as soon as the larger system they belong to can be connected.

Where the connection has to run

Two further definitions describe the target of the connection, without settling what a device or a network is. The electronic information system of Article 3, point (7), returns in the physical connection, which point (9) describes as a connection between electronic information systems or components. The end-point of point (11) is a device connected to a network and serving as an entry point to that network. Article 2(1) itself falls back on neither term.

What Article 2(1) does not require matters more than either definition. Internet access is nowhere mentioned. A connection to a single device is enough, and that device need not itself sit on a network.

When the condition is not met

The CRA gives no examples of products that fail Article 2(1). The reasoning falls to the manufacturer, who has to stand behind it towards customers, importers and authorities. It helps to run the assessment along the interfaces the product actually has rather than along an image of a connected product. The question is not whether a product is networked, but whether a single data connection belongs to its purpose or its foreseeable use.

The connection alone is not enough

Article 2 sets several carve-outs beside the condition. Paragraph 2 excludes products covered by Regulation (EU) 2017/745 on medical devices, Regulation (EU) 2017/746 on in vitro diagnostics or Regulation (EU) 2019/2144 on vehicle type-approval. Paragraph 3 excludes products certified under Regulation (EU) 2018/1139, paragraph 4 equipment falling within Directive 2014/90/EU on marine equipment. Paragraph 7 excludes products developed or modified exclusively for national security or defence purposes, and products specifically designed to process classified information.

Paragraph 6 further excludes spare parts that replace identical components and are manufactured to the same specifications. Under paragraph 5 the application of the Regulation may be limited or excluded for products covered by other Union rules laying down requirements that address all or some of the risks covered by Annex I. That requires the limitation to be consistent with the overall regulatory framework applying to those products and the sectoral rules to achieve the same level of protection or a higher one; the Commission establishes the necessity by delegated acts. The data connection is therefore the necessary condition of scope, not the sufficient one.

What the connection shapes in substance

The connection does not only open the scope, it shapes the requirements. Annex I, Part I, point 2 applies, by its opening sentence, on the basis of the cybersecurity risk assessment under Article 13(2) and only where applicable. Point 2(j) then requires products to be designed, developed and produced to limit attack surfaces, including external interfaces. Point 2(i) requires minimising the negative impact of the products themselves or of connected devices on the availability of services provided by other devices or networks.

Under Article 13(3) the cybersecurity risk assessment comprises at least an analysis based on intended purpose and reasonably foreseeable use, and the wording names the operational environment there as an example. Article 13(4) puts that assessment into the technical documentation required under Article 31 and Annex VII when the product is placed on the market. How a product connects therefore appears twice in the process: once as the entry question, once as content.

Annex II, point 4 adds that users must be told the intended purpose, including the security environment provided by the manufacturer. A manufacturer relying on a narrowly drawn intended purpose has to write it down and ship it. A limitation that exists only as an internal assumption carries no weight.

What the connection does not decide

The data connection says nothing about how a product is classified. Whether it belongs to the important products under Article 7 and Annex III or to the critical products under Article 8 and Annex IV is a separate question; which conformity assessment procedure follows from that is governed by Article 32. The kind or intensity of the connection plays no part. A permanently networked device may fall into the simplest procedure, while a password manager working purely locally counts as an important product under Article 7(1) read with Annex III, class I, point 3.

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.