The first pass at Cyber Resilience Act scope usually lists the obvious products: routers, cameras, industrial controllers, smart devices. Then the portfolio review finds the software.
What counts as a product with digital elements
The CRA covers products with digital elements whose intended or reasonably foreseeable use includes a direct or indirect data connection. That includes software on its own, not only software inside hardware. In practice:
Product type | In scope? |
|---|---|
Desktop and mobile applications | Yes |
Endpoint agents and collectors | Yes |
Command-line tools and SDKs supplied commercially | Yes |
Installers, update clients and firmware | Yes |
Remote data processing a product needs to function | Yes, pulled in with the product |
Pure browser-delivered SaaS | No |
Non-commercial open-source software | No |
Medical devices, vehicles, aviation | No, covered by sector rules |
The line that catches SaaS businesses is remote processing. A cloud service on its own is out. But the locally installed connector, sync client or on-premise collector that ships with it is a product in its own right, and the remote processing it depends on is pulled in with it.

The CRA applies wherever the product is made available in the EU, regardless of where the manufacturer sits.
In plain language
If customers in the EU install or run something you supply, it is probably in scope. Being a "software company" or being based outside the EU does not take you out.
What scope brings with it
Secure by design and by default, shipped with a secure configuration and a minimised attack surface
No known exploitable vulnerabilities at the point of sale
Security updates for a support period of at least five years, unless expected use is shorter
A software bill of materials in machine-readable form
Vulnerability handling and reporting, including the 24-hour clock already live since 11 September 2026
Run the inventory again
Most portfolios have more in scope than the first pass suggests. A useful second pass asks four questions of every product line: does anything run on the customer's device or network, does it connect, is it supplied commercially, and is it available in the EU. Anything that answers yes four times needs a class, an owner and a plan before 11 December 2027.
Next step. Our CRA briefing pack covers scope, the four risk tiers, the reporting clock and the dates that have already slipped. Get the briefing pack →
For any comments or information please reach out to info@astragar.com







