If you ship software: CRA and NIS2

Cyber Resilience Act

Does the Cyber Resilience Act cover a website, or a SaaS?

The test is not whether you sell software. It is whether the customer installs, embeds or runs any part of it themselves.

By Oscar CobbeCurrent as at 9 minute read4 sources

The definition everything turns on

Regulation (EU) 2024/2847 applies to products with digital elements made available on the market whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network.

Article 3(1) defines a product with digital elements as a software or hardware product and its remote data processing solutions, including software or hardware components placed on the market separately.

Article 3(2) defines remote data processing as data processing at a distance for which the software is designed and developed by the manufacturer, or under the manufacturer's responsibility, and the absence of which would prevent the product from performing one of its functions.

Those two definitions are the whole scope test. Everything below is them applied.

A browser-only SaaS is outside it

Recital 12 is explicit. Cloud solutions are remote data processing solutions within the meaning of the Regulation only where they meet its definition, and cloud services designed and developed outside the responsibility of a manufacturer of a product with digital elements do not fall within scope. The recital goes on to say that Directive (EU) 2022/2555, NIS2, applies to cloud computing services including Software as a Service.

So a product a customer only ever reaches through a browser, where nothing is installed and nothing is embedded, is not a product with digital elements. That is the correct answer for a large share of Irish software companies and it is worth reaching before anybody starts a readiness programme.

A website is treated the same way. Recital 12 says websites that do not support the functionality of a product with digital elements do not fall within scope. A marketing site, a brochure site or an ordinary online shop is not in this Regulation.

The sentence that pulls the backend back in

Recital 11 gives the example directly: a mobile application that requires access to an API or a database provided by a service the manufacturer developed. Ship the app and the app is a product with digital elements. The backend it cannot function without is its remote data processing solution, and it comes into scope with it. The same logic reaches the cloud functionality behind a smart home device, which is the Regulation's own illustration.

The test, in the order it decides things

One question does most of the work: does the customer install, embed or run any part of it themselves.

What you shipIn scope
Browser-only SaaS, nothing installedNo
Marketing site or ordinary online shopNo
Mobile appYes, and the backend it depends on
Desktop client, agent or browser extensionYes
Firmware, or a connected deviceYes
A library or component sold or supplied commerciallyYes
Free and open source, not monetised by youNo, unless you are its steward

Open source, and the steward

Recital 18 says that providing a product with digital elements qualifying as free and open-source software that is not monetised by its manufacturers should not be considered a commercial activity, and that the Regulation does not apply to natural or legal persons contributing source code to free and open-source products that are not under their responsibility. Recital 20 adds that merely hosting on an open repository or a package manager is not making available on the market.

There is a middle category the Regulation invented for this. An open-source software steward is a legal person, other than a manufacturer, whose purpose is systematically providing sustained support for the development of specific free and open-source products intended for commercial activities, and which ensures the viability of those products.

A steward's duties under Article 24 are lighter than a manufacturer's: a documented cybersecurity policy, cooperation with market surveillance authorities on request, and the actively exploited vulnerability and severe incident reporting duties to the extent it is involved in development. A steward may not affix CE marking.

There is no small company exemption

This is the part most likely to be misread as relief. There is no turnover threshold and no headcount exemption anywhere in the scope provisions.

What exists is proportionality in the process. Article 33(5) lets micro and small enterprises use a simplified technical documentation form, which notified bodies must accept. Article 32(6) requires conformity assessment fees to be reduced proportionately for SMEs. Article 33 obliges member states to run awareness and training and to provide a dedicated communication channel.

None of that changes whether you are in scope. A two-person Irish company placing a connected product or commercial software on the EU market is a manufacturer with a manufacturer's obligations.

What is excluded outright

Article 2 carves out products already governed by their own sectoral regimes: medical devices under Regulation (EU) 2017/745 and in vitro diagnostics under Regulation (EU) 2017/746, motor vehicle type approval under Regulation (EU) 2019/2144, products certified under the civil aviation regulation, and marine equipment under Directive 2014/90/EU.

It also excludes spare parts made to replace identical components to the same specifications, and products developed or modified exclusively for national security or defence, or specifically designed to process classified information.

If you are in one of those, you are not free of cybersecurity obligations. You are in a different regime.

If you are in scope, the first date has passed

Article 71 sets three dates. Chapter IV, the notified body framework, applied from 11 June 2026. Article 14, reporting, applies from 11 September 2026. Everything else, including the essential requirements and CE marking, applies from 11 December 2027.

The sting is in Article 69. Paragraph 2 exempts products placed on the market before 11 December 2027 from the requirements unless they undergo a substantial modification after that date. Paragraph 3 then disapplies that exemption for Article 14. So the reporting duty reaches every in-scope product already in customers' hands, fifteen months before the requirements those products would be judged against apply at all.

The reporting clocks and what they actually measure from are set out separately, and two of them are commonly misstated.

Who supervises this in Ireland

As at 31 August 2026 we have not found a published Irish designation of a market surveillance authority for the Cyber Resilience Act. The National Cyber Security Centre's own CRA page, updated on 28 August 2026, names none and routes reporting through the single reporting platform, from which reports reach the national CSIRT and ENISA simultaneously.

That is a statement about what is published. We are not asserting that no designation exists, and we are not naming a body we cannot source.

It is also not a reason to wait. The reporting duty applies directly under a Regulation, and the platform it runs through is a European one rather than an Irish one.

Sources

  1. 1.Regulation (EU) 2024/2847, the Cyber Resilience Act · EUR-Lex, Publications Office of the European Union
  2. 2.The EU Cyber Resilience Act · National Cyber Security Centre, Ireland
  3. 3.Cyber Resilience Act · European Commission
  4. 4.Directive (EU) 2022/2555 (NIS2), which covers cloud services · EUR-Lex, Publications Office of the European Union

Free, and the answers stay in your browser

Run the scope test on one product

Five questions in the order the Regulation asks them, and it names the duties that follow with the article behind each one. The answers stay in your browser and it prints as a document.

Run the free check

If it does reach you

The work is a vulnerability handling process, a coordinated disclosure policy, a software bill of materials and somebody who knows what to do in the first twenty four hours. We build those into how the thing is already developed rather than beside it.

Talk to us

Who wrote this

Oscar Cobbe · Founder, FourWinds Digital

Writes and maintains the legal explainers on this site, and does the compliance work behind them. Every date and article number here is checked against the instrument itself before it is published, and corrected in place when the law moves.

More about how we work →

Read next

More on If you ship software: CRA and NIS2

Written on 31 August 2026 and accurate as at that date. This is general information about how the rules work, not legal advice on your situation. We are not solicitors and we say so when you need one.