Cyber Resilience Act
Does the Cyber Resilience Act cover a website, or a SaaS?
The test is not whether you sell software. It is whether the customer installs, embeds or runs any part of it themselves.
9 minute read4 sources
Two regimes, one of which has no small company exemption and one of which is not law in Ireland yet.
The Cyber Resilience Act and NIS2 are usually discussed together and they are almost opposites. The CRA is a product regulation: it reaches anybody who places a product with digital elements on the EU market, it has no SME exemption, and its first hard duty is a twenty four hour reporting clock. NIS2 is a sectoral regulation of operators, it has a size floor that excludes most small businesses, and Ireland has still not transposed it.
The practical consequence is that the smaller supplier is more likely to be caught by the one nobody is talking about. These articles work out which of the two, if either, reaches a given business, and say plainly when the answer is neither.
Built and handed over
Websites
A landing page or a full marketing site, built on Next.js and served from your own Vercel or Cloudflare account.
The record, written
Compliance assessment
One assessment across the regimes that actually reach an Irish SME: GDPR, the EU AI Act, accessibility, and a DPIA where the law asks for one.
Custom build
Workflow automation
Software that does a repeating job on a schedule.
Compliance audit
ISO 27001 readiness
A Statement of Applicability is the first document a certification body asks for, and the one most small businesses have never written.