The Key Principle: What CRA Covers
The CRA applies to "products with digital elements" placed on the EU market. This means:
CRA Definition
A product with digital elements is any software or hardware product that includes software components and has a direct or indirect logical or physical data connection to a device or network.
If your product doesn't meet this definition, or falls into a specific exemption category, CRA does not apply.
Complete CRA Exemption List
Fully Exempt (Article 2)
- Medical devices — Regulation (EU) 2017/745 (Article 2(2)(a))
- In vitro diagnostic devices — Regulation (EU) 2017/746 (Article 2(2)(b))
- Motor vehicles — Regulation (EU) 2019/2144 (Article 2(2)(c))
- Civil aviation equipment certified under Regulation (EU) 2018/1139 (Article 2(3))
- Marine equipment under Directive 2014/90/EU (Article 2(4))
- Spare parts — components replacing identical parts to the same specification (Article 2(6))
- National security and defence products — developed exclusively for national security/defence or to process classified information (Article 2(7))
- Non-commercial open source software — developed and supplied outside any commercial activity (Recital 18)
Outside Scope / Nuanced
- SaaS platforms (pure browser-based, no downloadable components — outside scope per Recital 12; NIS2 applies instead)
- Prototype/R&D products not placed on the EU market (outside scope per Article 2(1))
- Products used exclusively within the manufacturer's own organisation and never supplied to any external party (outside scope per Article 2(1) — CRA only covers products 'made available on the market')
Common Misconceptions — NOT Exempt
- Custom or bespoke software developed under contract for a single client — delivering software to a customer IS placing a product on the market; no exemption exists
- Open source software monetized by its manufacturer or otherwise supplied in the course of a commercial activity — note that mere financial support/sponsorship from a company, or a company contributing to development, does NOT by itself remove the exemption (Recital 18)
- Internal tools that are also made available to any external party
Sector-Specific Exemptions Explained
Medical Devices (MDR/IVDR)
If your product is classified as a medical device under Regulation (EU) 2017/745 (MDR) or an in-vitro diagnostic device under Regulation (EU) 2017/746 (IVDR), it is exempt from CRA.
Caveat
General-purpose software or hardware that is also used in medical settings but is not a certified medical device still falls under CRA. The exemption only applies to products bearing the CE mark under MDR/IVDR.
Automotive Products
Type-approved vehicles and their components under Regulation (EU) 2019/2144 and UNECE regulations are exempt. This includes connected car systems and autonomous driving components.
Aviation & Marine
Products falling under aviation safety (Regulation 2018/1139) or marine equipment (Directive 2014/90/EU) certification schemes are exempt from CRA.
Open Source Exemption (Detailed)
This is one of the most debated CRA exemptions. Here's exactly how it works:
The Open Source Rule
Open source software is exempt ONLY IF it is:
- Made available free of charge
- Developed outside the course of a commercial activity
- Not integrated into a commercial product by the same organization
What This Means in Practice
Open Source "Steward" Role
The CRA introduces a new role: Open Source Software Steward. This applies to legal persons (organizations, not individuals) that systematically support open source development for commercial benefit. Stewards have reduced obligations but must still:
- Develop cybersecurity policy
- Cooperate with market surveillance authorities
- Document known vulnerabilities
SaaS & Cloud Services Exemption
This is NOT a Blanket Exemption
The CRA exempts "remote data processing solutions" where data is processed not on the user's device but on the service provider's infrastructure.
When SaaS IS Exempt
- Pure web applications accessed only via browser
- No downloadable components or client-side code (beyond standard web tech)
- No on-premise agents, SDKs, or plugins required
When SaaS is NOT Exempt
- Desktop or mobile apps that connect to your cloud (the app is covered)
- On-premise agents or connectors (those components are covered)
- SDKs or libraries customers embed in their products (those are covered)
- Browser extensions (those are covered)
Not sure if your SaaS product has covered components?
Take the Assessment →Common Gray Areas (FAQ)
"What about APIs? Are they covered?"
APIs themselves are not "products with digital elements." However, if you provide an SDK or library that customers use to access your API, that SDK is covered by CRA.
"What about firmware updates for exempt products?"
If the product itself is exempt (e.g., medical device), its firmware updates are also outside CRA scope. The exemption follows the product, not the software.
"What if I sell both in EU and outside EU?"
CRA applies only to products "placed on the EU market." If you have separate product lines for EU and non-EU, only the EU line needs compliance. However, most companies apply the same security standards globally.
"What about refurbished/secondhand products?"
Previously sold products returning to market are generally outside CRA scope unless substantially modified. Minor repairs don't trigger new CRA obligations.
Still Unsure? Let Us Help
Our free assessment walks you through the classification logic step by step and tells you exactly whether CRA applies to your product.
Check If CRA Applies to You