Cyber Resilience Act
Electronic information system
Legal definition Art. 3(7) CRA
“a system, including electrical or electronic equipment, capable of processing, storing or transmitting digital data”
An electronic information system is, under Article 3, point (7) of the Cyber Resilience Act (CRA), a system including electrical or electronic equipment that is capable of processing, storing or transmitting digital data. The definition describes a capability rather than a class of product.
No manufacturer obligation in the Regulation attaches directly to this term. It carries weight all the same, because three other definitions cannot be stated without it, namely software, hardware and component.
Three capabilities, any one of which is enough
Processing, storing and transmitting sit side by side with an “or”. A system need not do all three. A storage medium that only holds data meets the definition, and so does a media converter that neither evaluates nor keeps data but merely passes it on.
The words “capable of” matter just as much. What is required is the ability, not its actual use. An interface that is present but switched off on delivery changes nothing about the classification.
The one real limit sits in the words digital data. A purely analogue signal chain falls outside. In practice that objection rarely carries far, because a microcontroller, an analogue-to-digital converter or a digital display already crosses the line.
Why the equipment is named explicitly
The insertion “including electrical or electronic equipment” makes clear that the devices themselves belong to the system, not only what runs on them. It names electrical equipment alongside electronic equipment, so older technology is not left outside merely because it manages without modern electronics.
What is built on the term
Article 3 uses the electronic information system as a building block for three further definitions:
- Software is, under point (4), the part of an electronic information system which consists of computer code. Software is therefore not defined as a thing in its own right but as part of a system.
- Hardware is, under point (5), a physical electronic information system, or parts thereof capable of processing, storing or transmitting digital data.
- A Component is, under point (6), software or hardware intended for integration into an electronic information system.
Through those three, the term reaches the Product with digital elements, which Article 3, point (1) describes as a software or hardware product. Every CRA obligation addressed to a product therefore rests indirectly on point (7).
Point (5) repeats the capability formula although point (7) already contains it. The language versions attach the qualifier differently, to the system in German and to its parts in English. Nothing turns on it, since point (7) requires the capability in any event.
How the term enters the scope test
Article 2(1) fixes scope by reference to a direct or indirect logical or physical data connection to a device or network. The electronic information system does not appear in that sentence. The scope test itself is set out under Data connection.
The term enters that test through the physical variant alone. A Physical connection is, under Article 3, point (9), a connection between electronic information systems or components implemented using physical means such as electrical, optical or mechanical interfaces, wires or radio waves. A Logical connection under point (8) manages without the term, since it is a virtual representation of a data connection implemented through a software interface.
Why the definition is drawn so wide
Recital 9 gives the reason. Under certain conditions, all products with digital elements integrated in or connected to a larger electronic information system can serve as an attack vector for malicious actors. Even hardware and software considered to be less critical can therefore facilitate the initial compromise of a device or network, enabling malicious actors to gain privileged access to a system or to move laterally across systems. The recital concludes that manufacturers should ensure that all products with digital elements are designed and developed in accordance with the essential cybersecurity requirements. It carves out no exemption for simple products.
Where the system boundary is actually needed
Annex I, Part I assumes in several places that it is clear where your system ends. Point (2)(j) requires products to be designed, developed and produced to limit attack surfaces, including external interfaces. An interface can only be called external once the boundary has been drawn.
Point (2)(i) requires the negative impact by the products themselves or connected devices on the availability of services provided by other devices or networks to be minimised. Both requirements apply, per the opening sentence, on the basis of the cybersecurity risk assessment referred to in Article 13(2), and only where applicable. Where your system ends is therefore not a matter of vocabulary but an assumption against which the Annex I requirements are measured.
Not the same as the NIS2 network and information system
The two terms sound alike and come from neighbouring legal acts, yet they are built quite differently. Article 6, point (1) of the NIS2 Directive lists three things: electronic communications networks; devices or groups of connected devices that carry out automatic processing of digital data pursuant to a programme; and the digital data itself, where stored, processed, retrieved or transmitted for the operation, use, protection and maintenance of those elements. The CRA works with a single capability formula and does not count the data as part of the system.
The two meet in Article 57(1), point (c). Where a market surveillance authority finds, following an evaluation under Article 54, that a compliant product presents a Significant cybersecurity risk together with a risk to the availability, authenticity, integrity or confidentiality of services offered using an electronic information system by essential entities within the meaning of Article 3(1) of the NIS2 Directive, it requires the economic operator to take appropriate measures. The CRA thus describes the services of those entities in its own system vocabulary.
What the term does not do
Trying to keep a product out of scope by way of point (7) almost never works. Nearly everything the CRA sets out to cover can process, store or transmit digital data. Anyone testing whether a product is caught is better off starting at Article 2(1) and the four connection variants than at the question whether a system exists at all.
Practical questions
-
The CRA asks for no section headed “system boundary”. It does ask for a cybersecurity risk assessment which, under Article 13(3), must comprise at least an analysis based on the intended purpose and reasonably foreseeable use of the product, such as the operational environment or the assets to be protected. Annex I, Part I, point (2)(j) also speaks of external interfaces, and what counts as external cannot be judged until the boundary is drawn. In practice a list of every interface, stating which side you answer for, is usually enough.
-
On the wording of Article 3, point (7), quite possibly, since a network of equipment that transmits digital data meets the definition. Nothing practical follows from it. The CRA defines neither “device” nor “network”, and it regulates products made available on the market rather than the operation of networks. The NIS2 Directive applies to the entities that run networks, so far as they fall within its scope. Your device stays your product even where the network behind it belongs to someone else.
-
Yes. It can process, store and transmit digital data, and size is irrelevant under Article 3, point (7). What decides the legal position is its role. Built into something else it is a component under point (6); placed on the market separately it is a product with digital elements under point (1). Nothing follows from being a system as such.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.