Independent information resource Product security · EU CRA
CRA scope / 10

Does the CRA Apply to Software Components Sold Separately?

Learn how the Cyber Resilience Act treats software components placed on the market separately, including commercial libraries, modules, dependencies, manufacturer responsibilities and open-source distinctions.

IN BRIEF

A commercial software component does not automatically escape the CRA because it is intended to be integrated into someone else's finished product. When a software component is separately placed on the market, it can be a product with digital elements in its own right, while the downstream manufacturer remains responsible for the security of the finished product it markets.

01 / 09

Article 3 Expressly Includes Separately Marketed Components

The CRA definition of a product with digital elements expressly includes software and hardware components being placed on the market separately. This wording makes component scope a deliberate part of the Regulation rather than an accidental extension of finished-product rules. A component supplier should therefore not assume that only the final application, device or system can be a CRA product.

02 / 09

The Key Question Is Whether the Component Is Placed on the Market Separately

A software module used only inside one manufacturer's internal development environment is not the same situation as a component supplied to customers or downstream manufacturers as its own product. Teams should identify whether the component is being made available or placed on the Union market, who supplies it, under whose name it is marketed and the commercial context of the supply.

03 / 09

Commercial Libraries Can Require CRA Analysis

Commercial libraries, SDKs, middleware components, security modules and other software building blocks can potentially qualify as products with digital elements when separately marketed. Their role as inputs into larger products does not by itself remove them from scope. The supplier should define the component's intended purpose, connectivity, supported versions and cybersecurity responsibilities in the same disciplined way as other software manufacturers.

04 / 09

The Component Supplier and Downstream Manufacturer Have Different Roles

A component manufacturer can have responsibilities for the separately marketed component, while a downstream manufacturer remains responsible for the finished product with digital elements that it places on the market. Downstream integration therefore does not transfer all product responsibility back to the component supplier. The finished-product manufacturer needs to assess risks arising from integrated components and exercise due diligence when selecting and maintaining them.

05 / 09

A Dependency Is Not Automatically a Separately Marketed CRA Product

Software products can contain hundreds or thousands of dependencies. The fact that code appears in a dependency tree does not itself prove that the dependency is a separately placed product within the CRA market framework. Teams should distinguish internal code, non-commercial open-source dependencies, third-party commercial components and software components separately supplied on the Union market.

06 / 09

Component Vulnerability Information Matters Downstream

A vulnerability in a component can affect many downstream products. CRA readiness therefore depends on component suppliers and downstream manufacturers being able to identify affected versions, communicate relevant security information and distribute corrections. Manufacturers of finished products should maintain enough component information to determine whether a newly disclosed vulnerability affects their marketed products.

07 / 09

Open-Source Components Need Their Own CRA Analysis

The CRA contains specific treatment for free and open-source software and for open-source software stewards. A publicly available library should therefore not be classified simply by saying that all components are covered or all open source is exempt. The commercial context, the actor making the software available and the Regulation's open-source provisions need to be considered. This cluster contains a later dedicated article on free software.

08 / 09

Component Scope Does Not Automatically Determine Product Classification

A component can be within CRA scope without automatically falling into an important or critical category. Classification depends on whether its core functionality matches the categories and technical descriptions established under the CRA. The component's use inside an important downstream product also does not necessarily mean that the component has the identical classification.

09 / 09

Maintain a Component Product Record

A component manufacturer should maintain a product record containing the component name, version, intended purpose, interfaces, dependencies, supported environments, security-update mechanism, vulnerability process and distribution model. Downstream manufacturers should maintain corresponding records showing which component versions are integrated into which finished-product versions. These records make vulnerability and support decisions substantially more reliable.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.