Independent information resource Product security · EU CRA
CRA scope / 06

What Is a Remote Data Processing Solution Under the CRA?

Understand the Cyber Resilience Act definition of a remote data processing solution, including manufacturer-controlled APIs, databases, cloud processing, necessary remote functions and the limits of the product boundary.

IN BRIEF

A remote data processing solution is not simply any cloud service used by a digital product. The CRA focuses on manufacturer-controlled remote software that is necessary for a product function. APIs, databases, remote storage or processing can therefore form part of the product when the statutory definition is satisfied.

01 / 08

Article 3 Gives Remote Data Processing a Specific Definition

The CRA defines remote data processing as data processing at a distance for which software is designed and developed by the manufacturer of the product with digital elements, or under that manufacturer's responsibility, and whose absence would prevent the product from performing one of its functions. The definition therefore contains both an organisational element and a functional element. The software needs to fall within the manufacturer's development responsibility, and the remote processing needs to be necessary for a product function.

02 / 08

The CRA Treats Necessary Remote Processing as Part of the Product

The purpose of including remote data processing is to prevent an artificial split between local product software and essential manufacturer-controlled remote functionality. A product can depend on processing or storage taking place away from the user's device and still need to be secured as one functional product. Where the statutory definition is met, the manufacturer needs to account for that remote solution when considering the cybersecurity of the product with digital elements.

03 / 08

A Mobile App Requiring an API Is the CRA's Own Example

Recital 11 provides an explicit example. A mobile application may require access to an application programming interface or a database provided through a service developed by the manufacturer. If the application cannot perform one of its functions without that service, the service can fall within CRA scope as a remote data processing solution. The example is useful because it shows that the product boundary can extend beyond the code installed on the user's device.

04 / 08

Remote Databases Can Form Part of the Product

A database used remotely can form part of the CRA product where the conditions in the definition are satisfied. The important point is not simply that data is stored in the cloud. Teams need to ask whether software developed by or under the responsibility of the manufacturer provides the remote processing and whether the product would lose a function if that processing or storage were unavailable. A database used only for optional analytics can present a different result from a database essential to the user-facing product function.

05 / 08

Cloud Infrastructure Is Not Automatically Remote Data Processing

Recital 12 makes clear that cloud solutions qualify as remote data processing solutions only when they meet the CRA definition. Using infrastructure-as-a-service, third-party hosting, generic object storage or another cloud platform does not automatically make the whole provider environment part of the product. The manufacturer should identify the product-specific software and remote functionality rather than treating every underlying infrastructure layer as the same legal object.

06 / 08

Optional Remote Services Need Separate Analysis

The statutory definition focuses on remote processing whose absence would prevent the product from performing one of its functions. An optional telemetry service, marketing analytics platform or unrelated customer-support system therefore does not become part of the product merely because the software communicates with it. The product architecture should distinguish functions required for the product to operate as designed from ancillary services that are not necessary for a product function.

07 / 08

The CRA Does Not Turn the Entire Manufacturer Network Into the Product

Recital 11 distinguishes the security of a remote data processing solution from measures aimed at managing risks to the manufacturer's network and information systems as a whole. The CRA product boundary can include necessary remote functionality without extending to every corporate server, identity system, employee workstation or internal business application. This distinction is useful when separating CRA product security from broader organisational cybersecurity obligations under other legislation.

08 / 08

Map Remote Functions Before Performing the Risk Assessment

Product teams should create an architecture map showing local software, remote APIs, databases, processing services, identity services, external dependencies and communications paths. For each remote element, record who designs and controls the software, which product function depends on it and what happens if the service becomes unavailable. Elements that meet the remote data processing definition should then be carried into the product cybersecurity risk assessment, testing and technical documentation.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.