CRA Bureau
All guides

Am I in scope of the Cyber Resilience Act?

8 min readUpdated 1 September 2026Cites Cyber Resilience Act

The test

Articles 2(1) and 3(1)

Exclusions that actually work

Article 2
  • Medical devices under Regulation (EU) 2017/745 or 2017/746.
  • Motor vehicle products under Regulation (EU) 2019/2144.
  • Civil aviation products under Regulation (EU) 2018/1139.
  • Marine equipment under Directive 2014/90/EU.
  • Products developed or modified exclusively for national security or defence, or specifically to process classified information.
  • Free and open-source software supplied outside the course of a commercial activity.

Where vendors get it wrong

The beliefThe reality
"We are pure SaaS, so we are out."True only if the customer installs nothing at all. A desktop agent, a mobile app, a CLI, an SDK, a browser extension or an on-premise appliance puts you in scope — and so does a backend that is a "remote data processing solution" integral to a product you sell.
"We are open source."The carve-out is for open source supplied outside a commercial activity. Charging for support, operating an open-core model, or having it developed by a company as part of its business are all commercial activity.
"We are not in the EU."There is no establishment requirement. If EU users can buy it, the Regulation reaches it. What your location changes is whether you need an EU-based importer or authorised representative.
"We are too small."There is no de minimis. The Commission’s own impact assessment expects 99.58% of the manufacturers in scope to be SMEs.
"We already have CE marking."Existing CE marking under other legislation does not cover the CRA. Cybersecurity conformity is a separate assessment against Annex I.

Being out of scope is a position you may have to defend

Check your own product

Free, no account needed.

Related guides