Cyber Resilience Act

Indirect connection

Legal definition Art. 3(10) CRA

“a connection to a device or network, which does not take place directly but rather as part of a larger system that is directly connectable to such device or network”
Regulation (EU) 2024/2847, Art. 3(10) CRA

An indirect connection is the concept through which the Cyber Resilience Act (CRA) reaches products that are attached to no device and no network of their own. Article 3, point (10) describes it as a connection that does not take place directly but as part of a larger system that is itself directly connectable to that device or network.

For the scope of the Regulation the distinction makes no difference. Article 2(1) sets the direct and the indirect connection side by side, and either one opens it. The conditions standing alongside are covered by Data connection. What follows is about the one variant that is most often overlooked.

Two conditions

The definition asks for two things, and both have to hold:

  • The product is part of a larger system. The connection comes about through that system, not through the product itself.
  • That larger system can be connected directly to the device or network.

The clause “which does not take place directly” is not a third condition; it only marks the boundary. Where a direct connection exists anyway, point (10) is not needed.

“Connectable” describes no state of affairs

The decisive word sits at the end of the definition. What is required is not that the larger system is connected but that it can be. The German text says “verbunden werden kann” and carries the same meaning.

The installation a customer actually runs therefore does not answer the question. A plant operating today without a network connection, whose controller ships with an interface for one, meets the condition. On top of that, Article 2(1) works from intended purpose or reasonably foreseeable use in any event, not from the individual case.

Indirect is not a connection type of its own

Article 2(1) speaks of a “direct or indirect logical or physical data connection”. Two pairs of terms with different jobs are packed into that phrase. Direct and indirect describe the route a connection takes. Whether it comes about through a software interface or by physical means is settled by the Logical connection in point (8) and the Physical connection in point (9). An indirect connection, too, is one or the other on every leg.

Why the CRA reaches this far

Recital 9 gives the reason. All products with digital elements integrated in or connected to a larger electronic information system can, under certain conditions, serve as an attack vector. Even hardware and software considered less critical can facilitate the initial compromise of a device or network and let malicious actors gain privileged access or move laterally across systems.

From that the recital draws an explicit conclusion. Because cyber threats can propagate through various products before reaching a target, for example by chaining together multiple vulnerability exploits, manufacturers are expected to secure products that are only indirectly connected to other devices or networks as well.

What the definition leaves open

Point (10) leaves two questions unanswered. The first is depth. Nowhere does the Regulation say how many intermediate stages may sit between the product and the network. All it asks is that there be a larger system capable of being connected directly.

The second concerns that system itself, which is not defined. What is defined is the Electronic information system in point (7), a system including electrical or electronic equipment capable of processing, storing or transmitting digital data, and the End-point in point (11), a device connected to a network that serves as an entry point to that network. Recital 9 speaks of a larger electronic information system, point (10) only of a larger system. Whether that difference is deliberate, the text does not say.

What this means for components

A Component is, under Article 3, point (6), software or hardware intended for integration into an electronic information system. Where it is placed on the market separately, point (1) makes it a product with digital elements in its own right. Together with point (10) that means a part needs no network access of its own to be covered. It is enough that the system it belongs in can have one.

Responsibility does not travel upwards with the integration. The manufacturer of the larger system exercises due diligence under Article 13(5) when integrating third-party components, but that duty sits beside the component manufacturer’s own. It does not replace it.

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.