The regulation · deep dive

Products with digital elements: does the CRA apply to you?

The CRA’s scope hangs on one deliberately broad phrase — “product with digital elements.” If yours is one, you’re in. Here’s what the definition covers, what’s carved out, and the edge cases (SaaS, open source) worth checking against your own architecture.

Updated 7 Jul 2026·~5 min read·For founders, CTOs & compliance leads

Every CRA question starts with one prior question: does it apply to me at all? The regulation answers with a single phrase, and it's written to be inclusive rather than narrow — which means most software and connected-hardware makers are in, and the interesting work is spotting the exceptions.

The definition

A product with digital elements is any software or hardware product — and its remote data-processing solutions — whose intended purpose includes a direct or indirect data connection to a device or network. Three things are doing the work there: it covers software as well as hardware; it reaches the cloud-side components a product needs to function; and the connectivity can be indirect, so "it doesn't talk to the internet directly" isn't an escape.

What's in scope

In everyday terms, that captures:

  • Connected software applications and their components.
  • IoT, embedded and connected hardware — see CRA for IoT & embedded.
  • Operating systems, libraries, firmware and development tools placed on the market.
  • The remote data-processing solutions a product relies on to do its job.

What's carved out

To avoid double regulation, products already governed by sector-specific EU rules are excluded — notably medical devices (MDR/IVDR), motor vehicles (type-approval), civil aviation, and marine equipment. If your product is comprehensively covered by one of those regimes, the CRA generally steps back. Everything else with digital elements is in.

The edges: SaaS and open source

Two boundaries are worth checking against your own architecture:

  • SaaS. Software delivered purely as a service is generally outside the CRA's product scope (it may fall under NIS2 instead). But a remote data-processing solution that's necessary for a product's function is pulled back in — so a device or app that depends on your cloud is usually covered as a whole. Pure SaaS: often out. Product-plus-cloud: usually in.
  • Open source. Non-commercial open-source development is largely out of scope, and open-source software stewards have a lighter, tailored regime. The line is commercial activity — monetised or shipped as part of a commercial offering, and the manufacturer obligations attach.

A quick test

Ask three questions: does the product have software in it or is it software; does its intended use involve a data connection (directly or indirectly); and is it placed on the EU market commercially, outside the carved-out sectors? Three yeses and you're almost certainly in scope — at which point the manufacturer's guide is where to go next.

Frequently asked

What is a "product with digital elements"?

Any software or hardware product, and its remote data-processing solutions, whose intended purpose includes a direct or indirect data connection to a device or network. It deliberately spans software, connected hardware, and the cloud-side components a product depends on to function.

Does the CRA apply to SaaS?

Software delivered purely as a service generally falls outside the CRA’s product scope, and may instead sit under rules like NIS2. But remote data-processing solutions that are necessary for a product’s functions are pulled back into scope, so a product-plus-cloud architecture usually is covered.

Does the CRA apply to open source?

Non-commercial open-source development is largely out of scope, and open-source software stewards get a lighter, tailored regime. Commercial activity is the dividing line — once open source is monetised or shipped as part of a commercial product, the manufacturer obligations attach.

Design partners

In scope? Start where it bites first.

If the CRA applies, the earliest pressure is proving which vulnerabilities you must report. See it on your product.