Cyber Resilience Act

Remote data processing

Legal definition Art. 3(2) CRA

“data processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the product with digital elements from performing one of its functions”
Regulation (EU) 2024/2847, Art. 3(2) CRA

The definition of a product with digital elements explicitly draws remote data processing solutions into the product. This term therefore decides how far the Cyber Resilience Act (CRA) reaches beyond the shipped device or the installed software.

Two elements must coincide: the software is designed and developed by the manufacturer or under its responsibility, and without it the product could not perform one of its functions.

The function test

Everything turns on the word “one”. The test does not ask whether the product would be entirely useless without the remote processing, but whether any of its functions would fall away.

That sets a low threshold. A device that still works in a basic sense without the cloud but loses remote control, its analytics or its update distribution has lost a function, and the backend is part of the product.

What this means for SaaS

The often-quoted line that “pure SaaS is outside the CRA” is true, but it answers the wrong question. What matters is not the business model but the role of the service:

  • Standalone SaaS that supports no product with digital elements is generally out of scope.
  • A backend to an app or device without which a function would fail counts as part of the product and is regulated with it.

Anyone offering both should document the assessment per service rather than for the company as a whole.

Practical consequences

Where a backend is part of the product, the product’s requirements apply to it as well: the essential cybersecurity requirements cover that part too, its components belong in scope, and vulnerabilities in it are handled like any other.

This has an uncomfortable architectural consequence: a backend cannot be moved out of scope by operating it under a separate organisational roof. What counts is the functional dependency.

Distinguishing it from a mere integration

Not every outbound connection is remote data processing. Where your product integrates a third-party service you neither designed nor developed, the first element of the definition is missing. That service is then environment, not part of the product. You still have to build the integration securely.

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.