Does the CRA cover my web application?
Also asked
- Is SaaS covered by the Cyber Resilience Act?
- Is my Electron or progressive web app a product with digital elements?
- Does the CRA apply to my marketing website?
- Which EU rules apply to my cloud service if the CRA does not?
Generally no. Commission guidance confirms that software which executes remotely and is merely accessed by the user is not, on that basis alone, a product with digital elements. A web application reached exclusively through a browser therefore falls outside the CRA, as does a website that only presents information. Two things pull you back in. Shipping a client that users install and run locally is in scope, even where it is built with web technologies. And your backend enters scope where it supports a function of some other product.
Falling outside the CRA does not mean falling outside EU cybersecurity law. NIS2 covers cloud computing service providers, and DORA covers financial entities and their ICT providers.
At a glance
- Browser-only web app
- Not a product with digital elements
- Informational website
- Not a product with digital elements
- Downloadable or installed client
- In scope, even if built with web technologies
- Backend supporting another product
- In scope as remote data processing
- Source
- Guidance C(2026) 5252 points 20 to 21, Examples 3 to 6
Last reviewed 27 July 2026
Verified against Regulation (EU) 2024/2847 Articles 2, 3 and 24 and recitals 11 and 12 as published in OJ L, 20.11.2024, and Commission guidance C(2026) 5252 final of 27 July 2026, points 17 to 24.
Where the line sits
Article 3(1) defines a product with digital elements as a software or hardware product and its remote data processing solutions.[2] Commission guidance C(2026) 5252 explains what that requires of software. For software to fall in scope, it must be provided to a user, obtained by that user, and operated on or as part of an electronic information system on the user's side.[5]
Software that executes remotely and is merely accessed by the user does not meet that description. The guidance names web applications, including progressive web apps, where they are accessed exclusively through a web browser. Recitals 11 and 12 support the reading, treating processing at a distance as relevant only to the extent it is necessary for a product to perform its functions.[4]
Websites get the same treatment. Even though a website technically executes to a limited extent on the user's device, recital 12 means websites are not themselves products with digital elements. A site that merely presents information to visitors is outside the CRA even where a product links to it.
What pulls you back into scope
The delivery model decides this, and the technology stack does not. A desktop application built using web technologies but packaged for local installation is supplied to the user and executes on the user's device, so it is a product with digital elements.[5] The same applies to a browser extension. A mobile application downloaded from an app store is squarely in scope.
So the common pattern of a browser-based product that also ships a desktop or mobile client splits. The browser-accessed part is out of scope on its own account. The installed client is in scope. Where that client relies on data processing at a distance in order to perform one of its functions, and that software was designed and developed by you or under your responsibility, the processing is part of the product as a remote data processing solution.
That last point catches many teams by surprise. Your backend does not escape the CRA because it lives on a server. It escapes because nothing you place on the market depends on it.
The second gate, commercial activity
Scope also requires that the product is made available on the EU market in the course of a commercial activity.[1] The guidance devotes a full section to what that means for free and open-source software, and the tests are decisive rather than cumulative.
Charging a price puts you in. So does monetising other services through the software, or requiring the processing of personal data as a condition of use for reasons beyond security, compatibility or interoperability. Selling optional professional services around software that anyone can download freely does not. Accepting donations generally does not, unless access or updates are in practice conditioned on donating.[5]
Where free and open-source software is published but not placed on the market, the publisher may still be an open-source software steward under Article 24, with a narrower and graduated set of obligations.[3]
What applies instead
A browser-only web application sits outside the CRA and inside other regimes. Recital 12 of the CRA itself points to Directive (EU) 2022/2555, which establishes cybersecurity risk-management requirements for cloud computing service providers, further specified by Implementing Regulation (EU) 2024/2690.[6]
Financial entities and their ICT service providers face Regulation (EU) 2022/2554 on digital operational resilience. Any service processing personal data remains subject to the GDPR, including its own breach-notification timetable. The Commission has said it may issue further guidance on how the CRA interacts with the AI Act and with DORA.[5]
The practical step is to establish scope before doing classification work. Determining whether you are in scope at all takes minutes, and it decides whether the Annex III and IV classification exercise is relevant to you.
Sources
Every claim above traces to one of these. Items marked Binding are law in force. Everything else is interpretive and is labelled as such.
- [1]
Publications Office of the European Union · Article 2(1) · CELEX:32024R2847 · OJ L, 20.11.2024
Accessed 2026-07-27
- [2]
Publications Office of the European Union · Article 3(1) and 3(2) · CELEX:32024R2847 · OJ L, 20.11.2024
“a software or hardware product and its remote data processing solutions”
Accessed 2026-07-27
- [3]
Publications Office of the European Union · Article 24(1) to (3) · CELEX:32024R2847 · OJ L, 20.11.2024
Accessed 2026-07-27
- [4]
Publications Office of the European Union · Recitals 11 and 12 · CELEX:32024R2847 · OJ L, 20.11.2024
Accessed 2026-07-27
- [5]Commission guidance on the application of Regulation (EU) 2024/2847 (Cyber Resilience Act), C(2026) 5252 final, points 17 to 24 and 40 to 68Commission guidance
European Commission · C(2026) 5252
Non-binding. Only the Court of Justice of the European Union can give an authoritative interpretation of the CRA.
Accessed 2026-07-27
- [6]
Publications Office of the European Union · Article 1 and the Annex · CELEX:32024R2690
Accessed 2026-07-27
Further reading on this site
Follow-up questions
We sell a browser-only SaaS to manufacturers who are in scope. Does that matter?+
Not for your own CRA status. It may matter commercially, because your customers must risk-assess external dependencies and exercise Article 13(5) due diligence on integrated components. Expect security questionnaires and requests for evidence such as ISO/IEC 27001 or NIS2 conformity.
Does an authentication portal count as remote data processing?+
Yes, where the product needs it. Guidance point 194 gives an authentication portal that issues credentials or tokens required for the product to operate as an example of a website that does fall within remote data processing, provided the other criteria are met.
Work out where your product actually lands
Free CRA classification for your product, a vulnerability disclosure portal on your own domain, and Article 14 deadline tracking. Receiving and tracking reports is free for every manufacturer placing products with digital elements on the EU market.