Industry

CRA for SaaS Companies: What You Actually Need to Do

Pure browser-based SaaS is generally exempt from CRA under Recital (12). Learn when CRA does apply to cloud products and which requirements matter for downloadable components and SaaS-adjacent products.

March 2026 · 10 min read

Does CRA Apply to SaaS?

It depends on your architecture. CRA Recital (12) explicitly excludes "cloud services designed and developed outside the responsibility of a manufacturer of a product with digital elements." Pure browser-based SaaS is generally not covered by CRA — NIS2 applies instead for organizational cybersecurity obligations.

However, CRA does apply to:

  • Downloadable components — mobile apps, desktop clients, SDKs, and agents that ship with your SaaS
  • Cloud backends supporting a product with digital elements — e.g., the cloud service behind an IoT device or connected hardware

Which Requirements Apply to In-Scope Components?

Typically 8-12 of 22: Secure by Design, Secure by Default, SBOM, Vulnerability Handling, Security Updates, Data Protection, Access Control, and Incident Reporting (Article 14 from Sept 2026).

Classification

In-scope SaaS components are usually Default category (self-assess). Exceptions: IAM platforms, managed security, password managers, VPNs push to Class I.

Cost

DIY with free tools: €0 in software costs. Main investment: 2-4 weeks engineering time.

SaaS Action Items

  1. Take the CRA Assessment — check if your product has in-scope components
  2. Generate SBOM for downloadable components with CycloneDX or Trivy
  3. Publish security.txt
  4. Document secure development practices

Source: EU Regulation 2024/2847, Recital (12)

Get the CRA deadline calendar

A one-page PDF showing every CRA date that matters for your product team. Free — no spam, unsubscribe anytime.

Related articles

Ready to Take Action?

Start your CRA compliance journey with our free assessment tool.