Back to all articles
Fundamentals·22 July 2026·4 min read

Does the CRA apply to your product? A 60-second test

Three questions decide whether the Cyber Resilience Act covers what you sell. Here they are, with the edge cases that trip people up.

Most of the confusion about the CRA is people assuming it does not apply to them. Here is the short version. Answer three questions.

  1. Does your product include software or digital elements, such as firmware, an app, or a network or cloud connection?
  2. Is it made available on the EU market, meaning sold, distributed, or imported into the EU?
  3. Is it already covered by its own sector rules, such as a medical device, a motor vehicle, or an aviation product?

If the answer to the first two is yes and the third is no, the CRA almost certainly applies to your product. That is the whole test at a high level.

The edge cases that trip people up

Software counts. A lot of teams assume the CRA is about connected hardware. It covers standalone software with digital elements too: apps, operating systems, VPN clients, password managers, and libraries sold commercially. If you ship software into the EU, do not assume you are out.

Pure SaaS is usually out, with one catch. A service that runs entirely online, with nothing to download or install, is generally outside CRA scope. The catch is that if your cloud service is the remote backend that a covered product depends on to work, it gets pulled into that product's scope.

Sector-regulated products are excluded, but not unregulated. Medical devices, motor vehicles, and aviation products have their own cybersecurity regimes, so the CRA steps back for them. That is an exclusion from the CRA, not from cybersecurity duties in general.

Want a straight answer for your specific product? Our free applicability check runs these questions and tells you where you stand in about a minute, with no signup.