Does CRA Apply to SaaS?
It depends on your architecture. CRA Recital (12) explicitly excludes "cloud services designed and developed outside the responsibility of a manufacturer of a product with digital elements." Pure browser-based SaaS is generally not covered by CRA — NIS2 applies instead for organizational cybersecurity obligations.
However, CRA does apply to:
- Downloadable components — mobile apps, desktop clients, SDKs, and agents that ship with your SaaS
- Cloud backends supporting a product with digital elements — e.g., the cloud service behind an IoT device or connected hardware
Which Requirements Apply to In-Scope Components?
Typically 8-12 of 22: Secure by Design, Secure by Default, SBOM, Vulnerability Handling, Security Updates, Data Protection, Access Control, and Incident Reporting (Article 14 from Sept 2026).
Classification
In-scope SaaS components are usually Default category (self-assess). Exceptions: IAM platforms, managed security, password managers, VPNs push to Class I.
Cost
DIY with free tools: €0 in software costs. Main investment: 2-4 weeks engineering time.
SaaS Action Items
- Take the CRA Assessment — check if your product has in-scope components
- Generate SBOM for downloadable components with CycloneDX or Trivy
- Publish security.txt
- Document secure development practices
Source: EU Regulation 2024/2847, Recital (12)
Get the CRA deadline calendar
A one-page PDF showing every CRA date that matters for your product team. Free — no spam, unsubscribe anytime.
Related articles
Ready to Take Action?
Start your CRA compliance journey with our free assessment tool.