Does the Cyber Resilience Act apply to my product?
If you place a product with digital elements on the EU market, it applies — regardless of where your company is based. The exclusions are narrow and specific: products already covered by sector legislation, pure cloud services, and non-commercial open source. Everything else is in.
The three-part test
Ask these in order.
1. Is it a "product with digital elements"?
The regulation means any software or hardware product, including its remote data processing solutions, whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. In practice this captures nearly all modern software and nearly all connected hardware. Standalone software counts. A mobile app counts.
2. Is it placed on the EU market?
"Placed on the market" means the first making available in the EU in the course of a commercial activity. Selling from outside the EU to EU customers counts. Offering a free product commercially — for instance monetised by data or by an upsell — can also count.
3. Is it excluded?
The main exclusions: medical devices under the MDR and IVDR, motor vehicles under Regulation 2019/2144, civil aviation under 2018/1139, marine equipment, and products developed exclusively for national security or military purposes. Spare parts that restore an original function are also treated separately.
The four edge cases that actually cause confusion
The Commission's July 2026 guidance devotes most of its 67 examples to these.
Remote data processing
This is the SaaS question and it is the most misunderstood part of the regulation. A pure cloud service is not a product and falls under NIS2. But where remote processing is integral to the product — the product does not perform its function without it — that processing is treated as part of the product and is in scope. A smart thermostat whose scheduling runs in the vendor's cloud brings that cloud component into scope.
Open source
Non-commercial open-source software is excluded. The line is monetisation in the course of a commercial activity, not whether money changes hands for the software itself. The regulation also creates a lighter category — the open-source software steward — for foundations and bodies that support open source used commercially, with duties well short of a manufacturer's. The open-source position in detail →
Substantial modification
If you modify a product already on the market in a way that affects its compliance with the essential requirements, or changes its intended purpose, you may become the manufacturer for that product — with all the duties that follow. This catches integrators, white-labellers and anyone shipping a materially altered version of someone else's product.
Importers and distributors
Not manufacturers, but not free of duties either. Importers must verify the manufacturer carried out conformity assessment and that documentation exists. Distributors must check the CE mark and documentation are present. If you put your own name or trademark on a product, you become the manufacturer.
Read this diagram as text
- Is it a software or connected hardware product? If no, the CRA does not apply.
- If yes — is it placed on the EU market in the course of a commercial activity? If no, the CRA does not apply.
- If yes — is it already covered by the MDR, IVDR, motor vehicle or civil aviation rules? If yes, those rules apply instead.
- If no — is it non-commercial open-source software? If yes, it is excluded.
- If no — the CRA applies and Annex VII technical documentation is required.
Get told when the requirements change
None of the 35 CRA harmonised standards is published yet. When they land — and when deadlines move — we email you. No more than twice a month.