Back to all articles
Fundamentals·30 July 2026·6 min read

When your cloud backend is part of the product

Pure SaaS sits outside the CRA. A backend your product cannot work without does not. The Art. 3(2) test has three parts and all three must hold.

The CRA regulates products, not services, which is why a pure online service with nothing to download or install generally falls outside it. That reassures a lot of teams who then stop reading, which is a mistake if their product talks to a backend they operate.

Art. 3(1) defines a product with digital elements as the software or hardware product and its remote data processing solutions. The backend is not adjacent to the product. Where it qualifies, it is part of it.

The three-part test

Para 184 sets out the Art. 3(2) definition as three elements, and they are cumulative. All three must hold.

  1. The data processing happens at a distance, rather than locally on the user's device.
  2. Without that processing, the product could not perform one of its functions.
  3. The software is designed and developed by the manufacturer, or under the manufacturer's responsibility.

Miss any one and it is not a remote data processing solution for CRA purposes, though it may well be regulated in its own right under other law.

Where the line falls in practice

The guidance is candid that at a distance resists an exhaustive definition and needs a case-by-case call. Recital 11 contrasts data processed remotely by the manufacturer with data processed locally on the user's device, and remote processing typically happens outside the user's environment.

The second element does the most work. The question is not whether the backend adds value but whether the product still performs its function without it. An optional analytics dashboard is one thing; a thermostat that cannot hold a schedule when the cloud is unreachable is another.

The third element matters for teams building on someone else's platform. A backend you neither built nor are responsible for is not your remote data processing solution, though it is still a dependency your risk assessment has to reckon with.

What follows if it is in scope

The product has to be treated as a whole. The guidance is specific that this starts with the risk assessment under Art. 13(2), and carries through the lifecycle duties including Art. 14 reporting. An actively exploited vulnerability in the backend is a vulnerability in the product.

The practical failure mode is a team that assessed the device thoroughly and never assessed the API it depends on, because the API felt like infrastructure rather than product.