Does CRA apply to your SaaS product?
This is the first question every software company needs to answer — and it is not straightforward.
CRA applies to "products with digital elements" — hardware or software products placed on the EU market. Pure SaaS (software delivered as a service, not as a product you place on a market) may be out of scope. But if your SaaS includes a downloadable component, an SDK, an API client library, a browser extension, or an on-premise agent — those components may be CRA in-scope products with digital elements.
The CRA Scope Checker gives you a 60-second verdict based on your product's characteristics. No login required.
CRA for software — what the regulation says
CRA covers software products placed on the EU market, including:
- Desktop and mobile applications
- Firmware and embedded software
- Operating systems
- Software development tools and compilers (if placed on the market as standalone products)
- SDKs and libraries placed on the market under a commercial licence
Likely out of scope under CRA (may still have NIS2 obligations):
- Pure SaaS where no software is downloaded or installed by the end user
- Open-source software not commercialised (specific exemption, with conditions)
- Custom software developed for a single customer under bespoke contract
If CRA applies — software-specific obligations
Annex I Part I for software products:
- No known exploitable vulnerabilities at time of market placement (§2(1)) — requires dependency scanning in CI/CD
- Secure update mechanism (§2(8)) — for products with auto-update capability
- Data minimisation (§2(11)) — for products processing personal data
Annex I Part II:
- SBOM in SPDX or CycloneDX format, transitive depth (§1)
- CVD policy publicly accessible (§1)
- Vulnerability log maintained
Key software architecture implication: your CI/CD pipeline must integrate SCA (software composition analysis) scanning and SBOM generation. Manual SBOM creation does not scale across releases.
→ SBOM under CRA — format, depth, CI/CD integration
NIS2 — if you are also an essential or important entity
SaaS providers to critical sectors (energy, health, finance, public administration, digital infrastructure) may qualify as essential or important entities under NIS2. If so, you have Article 21 security obligations in addition to CRA product obligations.
The NIS2 × CRA overlap is significant — 6 shared obligation areas. One SBOM, one CVD policy, and a shared incident response process can satisfy both.
→ NIS2 × CRA overlap — shared evidence strategy → NIS2 Applicability Checker
What NexCyber provides for SaaS companies
- Scope determination: CRA applicability for each product/component in your stack
- Obligation mapping: CRA Annex I + NIS2 Article 21 in one assessment
- SBOM completeness tracking: automated check against CRA requirements
- Evidence layer: CVD policy, vulnerability log, technical file with 10-year retention
- MRCC: compliance signal for enterprise procurement requiring CRA evidence
Tools
- CRA Scope Checker — is your software a CRA product?
- NIS2 Applicability Checker — entity classification
- SBOM Readiness Checker — CRA Annex I completeness
- EU Market Access Score — cross-regulation readiness
Related answers
- NIS2 × CRA overlap
- SBOM under CRA
- CRA Article 14 vulnerability reporting
- Audit-ready evidence for CRA
NexCyber — EU Market Access Compliance Platform