Independent information resource Product security · EU CRA
CRA scope / 05

When Does the CRA Apply to SaaS?

Understand when SaaS and cloud-hosted functionality can fall within the Cyber Resilience Act, including software products, remote data processing solutions, APIs, databases and manufacturer-controlled remote functions.

IN BRIEF

For SaaS and cloud architectures, the key CRA question is what product is being supplied and whether remote processing forms an integrated, necessary part of that product. Manufacturer-developed APIs, databases or cloud functions can be remote data processing solutions when the product cannot perform a function without them.

01 / 09

The CRA Does Not Use SaaS as a Standalone Scope Category

The CRA defines products with digital elements, software, hardware and remote data processing rather than creating a broad legal category called SaaS. This means a company should not decide scope merely from the commercial label software as a service. The first question is what software product or digital functionality is supplied. The next question is whether cloud-hosted processing forms part of that product under the Regulation's remote data processing definition.

02 / 09

A Software Product Can Still Be Covered When It Uses the Cloud

A covered software product does not leave CRA scope merely because some of its processing occurs remotely. The CRA was designed to address products whose functionality can be divided between local software and manufacturer-controlled remote processing. A mobile or desktop application can therefore have a CRA product boundary that includes both the local application and qualifying remote functionality.

03 / 09

Remote Data Processing Has a Specific Legal Definition

Article 3 defines remote data processing as processing at a distance for which the software is designed and developed by the manufacturer, or under the manufacturer's responsibility, and whose absence would prevent the product with digital elements from performing one of its functions. Both parts matter. The processing needs to sit under the manufacturer's development responsibility and it needs to be functionally necessary in the sense described by the Regulation.

04 / 09

A Manufacturer-Developed API Can Be Part of the CRA Product

Recital 11 gives a useful example. Where a mobile application requires access to an API or database provided through a service developed by the manufacturer, that service can fall within CRA scope as a remote data processing solution. This means product teams should not define the CRA boundary solely around downloadable client code where essential manufacturer-controlled API functionality exists remotely.

05 / 09

Cloud Storage or Processing Can Also Require Analysis

Remote storage or processing can form part of the CRA product where it satisfies the remote data processing definition. The important question is not whether the infrastructure is called cloud, hosted or serverless. Teams need to identify what software was designed under the manufacturer's responsibility, what product function relies on that remote processing and whether the function would cease to operate without it.

06 / 09

Not Every Cloud Dependency Becomes Part of the Product

Recital 12 makes clear that cloud solutions are remote data processing solutions only when they meet the CRA definition. A generic infrastructure provider, optional analytics service or unrelated third-party cloud dependency does not automatically become part of the manufacturer's product with digital elements. The architecture should distinguish necessary manufacturer-controlled product functionality from supporting services and infrastructure.

07 / 09

Purely Remote SaaS Still Requires Product Analysis

A service delivered entirely through a browser should not be classified solely by saying that all SaaS is covered or that all SaaS is excluded. Teams should determine whether what is supplied is software that qualifies as a product with digital elements under the CRA market framework and how the Commission's current implementation guidance applies to that deployment model. The facts of distribution, commercial activity, product responsibility and technical architecture matter.

08 / 09

The CRA Does Not Regulate the Manufacturer's Entire Cloud Environment

The Regulation's treatment of remote data processing does not mean that all of the manufacturer's network and information systems become part of the CRA product. Recital 11 distinguishes security requirements for the integrated remote data processing solution from organisational measures aimed at managing risks to the manufacturer's network and information systems as a whole. Product teams should therefore define the remote functionality that supports the product instead of treating the entire corporate cloud estate as one CRA product.

09 / 09

Map SaaS Architecture Function by Function

A practical SaaS scope assessment should map the user-facing software, client applications, APIs, databases, authentication services, processing functions, external dependencies and infrastructure. For each remote function, record who designed and controls the software, whether the product depends on it to perform a function and how the function relates to the marketed product. This functional map provides a stronger CRA boundary than simply describing the business as SaaS.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.