What the guidance is, and how far it carries
On 27 July 2026 the Commission adopted guidance on the CRA, reference C(2026) 5252, built around 67 numbered worked examples plus five use cases on remote data processing. The guidance is not binding. Only the Court of Justice interprets EU law, so the examples tell you how the Commission reads the regulation rather than settling it. That still makes them the best available answer to the judgment calls clients ask you about, and citing them shows a client that a position is the Commission's reading rather than your opinion. Two rules on placing on the market run through everything else. Every copy of a version is placed on the market on the day that version is first supplied, so a customer buying two weeks later does not reset the date. And an update that is not a substantial modification does not create a fresh placing on the market, so the original date holds.
Which software is a product with digital elements
The test the guidance applies is whether the software is supplied to the user and executes on the user's device. A mobile app downloaded from an app store is in scope, and so is a desktop application built with web technology but packaged for local installation. A web application used only through a browser is not a product with digital elements, and an informational website is not one either. Where a locally installed client relies on data processing at a distance to do its job, that processing comes into scope with the client. Licensing source code counts as placing it on the market even before anyone compiles it, though the licensor is not responsible for what the licensee then adapts. Hardware and software supplied through different channels can still be one product, as with a printer that needs downloaded drivers or a wearable that needs a companion app to be configured at all. One product can also sit under two regimes at once, the way a hospital system can be both a product with digital elements and an EHR system under the European Health Data Space Regulation.
Supplied to the user and executing on the user's device is the line. A browser-only web app falls outside, a locally installed client falls inside and pulls its remote data processing with it.
Open source, stewards, and remote data processing
Free and open-source software leaves scope only while nobody monetises it. Charging for a version with support, gating releases or security updates behind donations, selling paid tiers of a free VPN, taking commission on a free marketplace app, or conditioning use on personal data processing unrelated to security or interoperability all make the supply commercial. Voluntary donations with unconditional access do not, optional consultancy sold separately from the software does not, and a manufacturer funding a feature that is then released openly to everyone does not. A contributor who sends a pull request never becomes responsible for the project. A publisher who maintains an unmonetised component that others integrate is a steward under Article 24, which includes not-for-profit foundations whose earnings after costs go to their objectives. Integrators always owe due diligence under Article 13(5), whatever the publisher is. Remote data processing turns on two questions. Is the processing necessary for the product to perform one of its functions, and was it developed under the manufacturer's responsibility. A manufacturer-built banking interface or robot vision service is a remote data processing solution, a general-purpose third-party SaaS is treated like a component instead, and a cellular network is neither because it only carries traffic.