Resources

The CRA Is Not a Hardware Rule: Software in Scope Is Bigger Than You Think

Resources

The CRA Is Not a Hardware Rule: Software in Scope Is Bigger Than You Think

Resources

The CRA Is Not a Hardware Rule: Software in Scope Is Bigger Than You Think

The first pass at Cyber Resilience Act scope usually lists the obvious products: routers, cameras, industrial controllers, smart devices. Then the portfolio review finds the software.

What counts as a product with digital elements

The CRA covers products with digital elements whose intended or reasonably foreseeable use includes a direct or indirect data connection. That includes software on its own, not only software inside hardware. In practice:

Product type

In scope?

Desktop and mobile applications

Yes

Endpoint agents and collectors

Yes

Command-line tools and SDKs supplied commercially

Yes

Installers, update clients and firmware

Yes

Remote data processing a product needs to function

Yes, pulled in with the product

Pure browser-delivered SaaS

No

Non-commercial open-source software

No

Medical devices, vehicles, aviation

No, covered by sector rules

The line that catches SaaS businesses is remote processing. A cloud service on its own is out. But the locally installed connector, sync client or on-premise collector that ships with it is a product in its own right, and the remote processing it depends on is pulled in with it.

The CRA applies wherever the product is made available in the EU, regardless of where the manufacturer sits.

The CRA applies wherever the product is made available in the EU, regardless of where the manufacturer sits.

In plain language

If customers in the EU install or run something you supply, it is probably in scope. Being a "software company" or being based outside the EU does not take you out.

What scope brings with it

  • Secure by design and by default, shipped with a secure configuration and a minimised attack surface

  • No known exploitable vulnerabilities at the point of sale

  • Security updates for a support period of at least five years, unless expected use is shorter

  • A software bill of materials in machine-readable form

  • Vulnerability handling and reporting, including the 24-hour clock already live since 11 September 2026

Run the inventory again

Most portfolios have more in scope than the first pass suggests. A useful second pass asks four questions of every product line: does anything run on the customer's device or network, does it connect, is it supplied commercially, and is it available in the EU. Anything that answers yes four times needs a class, an owner and a plan before 11 December 2027.

Next step. Our CRA briefing pack covers scope, the four risk tiers, the reporting clock and the dates that have already slipped. Get the briefing pack →

For any comments or information please reach out to info@astragar.com

Get Started Now

Know the Real Cyber Risk Behind the Data

Get Started Now

Know the Real Cyber Risk Behind the Data

Get Started Now

Know the Real Cyber Risk Behind the Data

©Astragar All rights reserved.