Cyber Resilience Act
Indirect connection
Legal definition Art. 3(10) CRA
“a connection to a device or network, which does not take place directly but rather as part of a larger system that is directly connectable to such device or network”
An indirect connection is the concept through which the Cyber Resilience Act (CRA) reaches products that are attached to no device and no network of their own. Article 3, point (10) describes it as a connection that does not take place directly but as part of a larger system that is itself directly connectable to that device or network.
For the scope of the Regulation the distinction makes no difference. Article 2(1) sets the direct and the indirect connection side by side, and either one opens it. The conditions standing alongside are covered by Data connection. What follows is about the one variant that is most often overlooked.
Two conditions
The definition asks for two things, and both have to hold:
- The product is part of a larger system. The connection comes about through that system, not through the product itself.
- That larger system can be connected directly to the device or network.
The clause “which does not take place directly” is not a third condition; it only marks the boundary. Where a direct connection exists anyway, point (10) is not needed.
“Connectable” describes no state of affairs
The decisive word sits at the end of the definition. What is required is not that the larger system is connected but that it can be. The German text says “verbunden werden kann” and carries the same meaning.
The installation a customer actually runs therefore does not answer the question. A plant operating today without a network connection, whose controller ships with an interface for one, meets the condition. On top of that, Article 2(1) works from intended purpose or reasonably foreseeable use in any event, not from the individual case.
Indirect is not a connection type of its own
Article 2(1) speaks of a “direct or indirect logical or physical data connection”. Two pairs of terms with different jobs are packed into that phrase. Direct and indirect describe the route a connection takes. Whether it comes about through a software interface or by physical means is settled by the Logical connection in point (8) and the Physical connection in point (9). An indirect connection, too, is one or the other on every leg.
Why the CRA reaches this far
Recital 9 gives the reason. All products with digital elements integrated in or connected to a larger electronic information system can, under certain conditions, serve as an attack vector. Even hardware and software considered less critical can facilitate the initial compromise of a device or network and let malicious actors gain privileged access or move laterally across systems.
From that the recital draws an explicit conclusion. Because cyber threats can propagate through various products before reaching a target, for example by chaining together multiple vulnerability exploits, manufacturers are expected to secure products that are only indirectly connected to other devices or networks as well.
What the definition leaves open
Point (10) leaves two questions unanswered. The first is depth. Nowhere does the Regulation say how many intermediate stages may sit between the product and the network. All it asks is that there be a larger system capable of being connected directly.
The second concerns that system itself, which is not defined. What is defined is the Electronic information system in point (7), a system including electrical or electronic equipment capable of processing, storing or transmitting digital data, and the End-point in point (11), a device connected to a network that serves as an entry point to that network. Recital 9 speaks of a larger electronic information system, point (10) only of a larger system. Whether that difference is deliberate, the text does not say.
What this means for components
A Component is, under Article 3, point (6), software or hardware intended for integration into an electronic information system. Where it is placed on the market separately, point (1) makes it a product with digital elements in its own right. Together with point (10) that means a part needs no network access of its own to be covered. It is enough that the system it belongs in can have one.
Responsibility does not travel upwards with the integration. The manufacturer of the larger system exercises due diligence under Article 13(5) when integrating third-party components, but that duty sits beside the component manufacturer’s own. It does not replace it.
Practical questions
-
A prohibition in the manual narrows the intended purpose, but it does not remove reasonably foreseeable use. Article 2(1) names both, and the second is not under the manufacturer’s control. Where the interface is physically present and readily usable, the note alone rarely carries. The CRA does not say where exactly the line runs. But Article 13(3) expressly names the operational environment as an example of the conditions of use the cybersecurity risk assessment has to work from, and that is where the assumption belongs.
-
Against your own product. What governs is its intended purpose and reasonably foreseeable use, not one particular customer’s installation. Record what kind of systems the component is built for and whether such systems can be connected to a device or network. Article 13(3) requires an analysis based on intended purpose and reasonably foreseeable use in any event, naming the operational environment as an example. Article 13(4) requires a clear justification in the technical documentation where individual essential requirements do not apply.
-
The scope is the same, and the CRA does not scale obligations by proximity to a network. The difference takes effect only through the risk assessment: Annex I, Part I, point 2 applies on the basis of that assessment and only where applicable, and under Article 13(3) the assessment has to state whether and in what manner those requirements apply. The vulnerability handling requirements in Annex I, Part II carry no such qualifier. They apply unchanged.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.