Cyber Resilience Act
Data connection
Practical term
The data connection is the feature on which the Cyber Resilience Act (CRA) hangs its entire scope. Under Article 2(1) the Regulation applies to products with digital elements made available on the market whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network.
The CRA nowhere defines the phrase “data connection” itself, and it defines neither “device” nor “network”. What it does define are the three qualifiers that give the sentence its reach: logical connection in Article 3, point (8), physical connection in point (9), indirect connection in point (10). Whether a product with digital elements is covered turns on those three.
Two tests, one variant each is enough
Article 2(1) combines two questions. One concerns the connection itself, the other what brings it about. Both have to be answered, but within each question a single variant suffices.
- Trigger: Intended purpose or reasonably foreseeable use. The second is not under the manufacturer’s control.
- Connection: direct or indirect, logical or physical. Four combinations, of which one is enough.
That also fixes the order. Starting with the kind of connection a product has is starting at the wrong end. Ask first what belongs to the intended purpose and the foreseeable use, and only then in which of the four forms the connection appears there. The indirect variant reaches furthest, because it catches products with no network access of their own as soon as the larger system they belong to can be connected.
Where the connection has to run
Two further definitions describe the target of the connection, without settling what a device or a network is. The electronic information system of Article 3, point (7), returns in the physical connection, which point (9) describes as a connection between electronic information systems or components. The end-point of point (11) is a device connected to a network and serving as an entry point to that network. Article 2(1) itself falls back on neither term.
What Article 2(1) does not require matters more than either definition. Internet access is nowhere mentioned. A connection to a single device is enough, and that device need not itself sit on a network.
When the condition is not met
The CRA gives no examples of products that fail Article 2(1). The reasoning falls to the manufacturer, who has to stand behind it towards customers, importers and authorities. It helps to run the assessment along the interfaces the product actually has rather than along an image of a connected product. The question is not whether a product is networked, but whether a single data connection belongs to its purpose or its foreseeable use.
The connection alone is not enough
Article 2 sets several carve-outs beside the condition. Paragraph 2 excludes products covered by Regulation (EU) 2017/745 on medical devices, Regulation (EU) 2017/746 on in vitro diagnostics or Regulation (EU) 2019/2144 on vehicle type-approval. Paragraph 3 excludes products certified under Regulation (EU) 2018/1139, paragraph 4 equipment falling within Directive 2014/90/EU on marine equipment. Paragraph 7 excludes products developed or modified exclusively for national security or defence purposes, and products specifically designed to process classified information.
Paragraph 6 further excludes spare parts that replace identical components and are manufactured to the same specifications. Under paragraph 5 the application of the Regulation may be limited or excluded for products covered by other Union rules laying down requirements that address all or some of the risks covered by Annex I. That requires the limitation to be consistent with the overall regulatory framework applying to those products and the sectoral rules to achieve the same level of protection or a higher one; the Commission establishes the necessity by delegated acts. The data connection is therefore the necessary condition of scope, not the sufficient one.
What the connection shapes in substance
The connection does not only open the scope, it shapes the requirements. Annex I, Part I, point 2 applies, by its opening sentence, on the basis of the cybersecurity risk assessment under Article 13(2) and only where applicable. Point 2(j) then requires products to be designed, developed and produced to limit attack surfaces, including external interfaces. Point 2(i) requires minimising the negative impact of the products themselves or of connected devices on the availability of services provided by other devices or networks.
Under Article 13(3) the cybersecurity risk assessment comprises at least an analysis based on intended purpose and reasonably foreseeable use, and the wording names the operational environment there as an example. Article 13(4) puts that assessment into the technical documentation required under Article 31 and Annex VII when the product is placed on the market. How a product connects therefore appears twice in the process: once as the entry question, once as content.
Annex II, point 4 adds that users must be told the intended purpose, including the security environment provided by the manufacturer. A manufacturer relying on a narrowly drawn intended purpose has to write it down and ship it. A limitation that exists only as an internal assumption carries no weight.
What the connection does not decide
The data connection says nothing about how a product is classified. Whether it belongs to the important products under Article 7 and Annex III or to the critical products under Article 8 and Annex IV is a separate question; which conformity assessment procedure follows from that is governed by Article 32. The kind or intensity of the connection plays no part. A permanently networked device may fall into the simplest procedure, while a password manager working purely locally counts as an important product under Article 7(1) read with Annex III, class I, point 3.
Practical questions
-
Article 2(1) asks for a data connection, not for any connection at all. A line carrying nothing but power transfers no data. On an ordinary USB socket, however, the data lines are physically present, and reasonably foreseeable use includes plugging the device into a computer. A manufacturer relying on charge-only should be able to show that the data paths are genuinely unpopulated or permanently disabled.
-
Yes, so far as it forms part of the product. Under Article 3, point (1), a product with digital elements includes its remote data processing solutions. Remote data processing is defined in point (2) as data processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the product from performing one of its functions. The server is then in scope not as a product of its own but as part of yours. Recital 11 draws the limit explicitly: remote processing is covered only so far as it is necessary for the product to perform its functions.
-
The CRA does not require it. Products outside its scope carry no obligations, and that includes documentation. The reasoning is needed anyway, the moment a customer, an importer or a market surveillance authority asks why there is no CE marking. A short dated note recording the intended purpose you assessed and the interfaces the product actually has usually covers it.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.