Solutions · By Industry · Saas

SaaS & Software

CRA scope determination for software products, with NIS2 overlap mapped in.

Pain

Does CRA even apply to your SaaS? Most teams can't answer that with confidence.

What you want

A clear scope verdict for every product/component in your stack, not a generic regulatory summary.

What you get

CRA Scope Checker + NIS2 Article 21 mapping in one assessment, SBOM completeness tracking built into your CI/CD.

Does CRA apply to your SaaS product?

This is the first question every software company needs to answer — and it is not straightforward.

CRA applies to "products with digital elements" — hardware or software products placed on the EU market. Pure SaaS (software delivered as a service, not as a product you place on a market) may be out of scope. But if your SaaS includes a downloadable component, an SDK, an API client library, a browser extension, or an on-premise agent — those components may be CRA in-scope products with digital elements.

The CRA Scope Checker gives you a 60-second verdict based on your product's characteristics. No login required.


CRA for software — what the regulation says

CRA covers software products placed on the EU market, including:

  • Desktop and mobile applications
  • Firmware and embedded software
  • Operating systems
  • Software development tools and compilers (if placed on the market as standalone products)
  • SDKs and libraries placed on the market under a commercial licence

Likely out of scope under CRA (may still have NIS2 obligations):

  • Pure SaaS where no software is downloaded or installed by the end user
  • Open-source software not commercialised (specific exemption, with conditions)
  • Custom software developed for a single customer under bespoke contract

If CRA applies — software-specific obligations

Annex I Part I for software products:

  • No known exploitable vulnerabilities at time of market placement (§2(1)) — requires dependency scanning in CI/CD
  • Secure update mechanism (§2(8)) — for products with auto-update capability
  • Data minimisation (§2(11)) — for products processing personal data

Annex I Part II:

  • SBOM in SPDX or CycloneDX format, transitive depth (§1)
  • CVD policy publicly accessible (§1)
  • Vulnerability log maintained

Key software architecture implication: your CI/CD pipeline must integrate SCA (software composition analysis) scanning and SBOM generation. Manual SBOM creation does not scale across releases.

SBOM under CRA — format, depth, CI/CD integration


NIS2 — if you are also an essential or important entity

SaaS providers to critical sectors (energy, health, finance, public administration, digital infrastructure) may qualify as essential or important entities under NIS2. If so, you have Article 21 security obligations in addition to CRA product obligations.

The NIS2 × CRA overlap is significant — 6 shared obligation areas. One SBOM, one CVD policy, and a shared incident response process can satisfy both.

NIS2 × CRA overlap — shared evidence strategyNIS2 Applicability Checker


What NexCyber provides for SaaS companies

  • Scope determination: CRA applicability for each product/component in your stack
  • Obligation mapping: CRA Annex I + NIS2 Article 21 in one assessment
  • SBOM completeness tracking: automated check against CRA requirements
  • Evidence layer: CVD policy, vulnerability log, technical file with 10-year retention
  • MRCC: compliance signal for enterprise procurement requiring CRA evidence

Tools


Related answers


NexCyber — EU Market Access Compliance Platform

Versus what you do today

Big4 consulting · In-house spreadsheet · NexCyber.

DimensionBig4 / ConsultingIn-house spreadsheetNexCyber
First assessment delay
4–8 weeks
2–6 weeks
5 minutes
Cost per regulation cycle
€90k–170k
€30k+ hidden
Included
Reproducibility
Slide deck of the day
Depends on editor
Deterministic, identical re-runs
Article-level traceability
Footnote
Often missing
Live link to EUR-Lex
Update when law changes
Re-billed mission
Restart from scratch
Automatic, MRCC re-signed
Deliverable format
Static PDF
XLSX/Word
PDF + MRCC machine-verifiable
Auditor verification
Email + chase
Not verifiable
sha256 verified in seconds
Multi-regulation simultaneous
1 mission per regulation
Duplicates & conflicts
5 regulations, 1 source of truth
New product line evolution
Re-billed mission
Full re-entry
Clone + delta
Run free assessment