Cyber Resilience Act
Product with digital elements
Legal definition Art. 3(1) CRA
“a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately”
No other term in the Cyber Resilience Act (CRA) has such immediate consequences. If a product falls under it, the entire set of obligations applies, from the essential cybersecurity requirements through conformity assessment to the reporting obligations. If it does not, none of them do.
The definition is deliberately broad. It covers software and hardware alike, and it explicitly pulls in two things that are easy to miss: the associated remote data processing, and components marketed on their own.
The data connection is the real test
The definition alone does not say when the regulation bites. That is in Article 2(1): it covers products whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network.
Two phrases widen this considerably:
- “Indirect” also covers a device that only reaches a network by a detour, via a USB stick or an intermediate system. It needs no connection of its own.
- “Reasonably foreseeable use” means not only what the product is meant for, but how it will predictably be used in practice.
In practice that leaves only fully isolated products outside.
Remote data processing is part of the product
The definition explicitly draws remote data processing solutions into the product. What is meant is processing at a distance for which the software is designed and developed by the manufacturer or under the responsibility of the manufacturer, and without which the product could not perform one of its functions.
This produces the distinction most often misunderstood: a pure software-as-a-service offering is generally outside the CRA. But as soon as a backend is what makes a device or application work at all, it becomes part of the product and is regulated along with it.
Components marketed separately
Anyone placing a library, a module or a hardware component on the market in its own right is placing a product with digital elements on the market, with all the obligations that follow. That the component is only ever built into other products and never reaches end users changes nothing.
For suppliers this is the decisive sentence of the whole definition. It also means that manufacturers appear more than once along a supply chain: the component maker is the manufacturer of the component, the device maker is the manufacturer of the device.
What is excluded
Article 2 carves out a manageable number of products, mostly because they already fall under their own, at least equivalent rules:
- medical devices and in-vitro diagnostics (Regulations (EU) 2017/745 and 2017/746)
- motor vehicles (Regulation (EU) 2019/2144)
- civil aviation products certified under Regulation (EU) 2018/1139
- marine equipment within the meaning of Directive 2014/90/EU
- spare parts replacing identical components built to the same specifications
- products developed or modified exclusively for national security or defence, and products specifically designed to process classified information
The list is exhaustive. “We are industrial, not consumer” and “our product is for internal use only” are not on it.
Why classification should happen early
Whether a product falls under the CRA determines effort, timeline and in part the product architecture. It cannot sensibly be caught up on as deadlines approach. The vulnerability handling requirements in particular assume processes that have to be built first.
For companies with several products, a documented classification per product, including the reasoning, pays off. It is the basis for every later discussion with customers, assessment bodies and authorities. It also forces the borderline cases to be decided deliberately rather than left open.
Practical questions
-
As a rule, yes. An app is a software product, and as soon as it exchanges data with a device or network by design or predictable use, the test in Article 2 is met. The distribution route does not matter: whether the app arrives via a store, a website or pre-installed on a device changes nothing about its classification.
-
No. The CRA attaches to making a product available on the Union market. Products demonstrably distributed only outside the EU are not covered. Conversely it applies regardless of where a company is based: placing products on the EU market from a third country carries the same obligations as for a supplier inside the Union.
-
That depends on how it reaches the market. Firmware marketed separately, whether as a licence or as an update package for third parties, is a product of its own, with all the obligations. Firmware that is an integral part of a device is a component, and responsibility sits with the manufacturer of the device. Technically it is the same thing in both cases; what decides is how it is marketed.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.