Industry Guide Updated: August 2026

Does the Cyber Resilience Act Apply to Cloud Storage Providers?

Learn if the EU CRA applies to Cloud Storage Providers, what the core compliance requirements are, and how to start preparing your engineering teams automatically.

Core Definition

Yes. The EU Cyber Resilience Act applies directly to Cloud Storage Providers as they fall under the definition of "products with digital elements." A file-sync service needs to document its encryption-at-rest and in-transit approach explicitly to satisfy the CRA's data-confidentiality requirement, not just claim 'we use HTTPS.' This means your software must meet mandatory cybersecurity requirements to be distributed in the EU market.

Key Compliance Steps for Cloud Storage Providers

  1. Determine Classification: Check if your Cloud Storage Providers falls under the default category or Class I/Class II, which dictate stricter conformity assessment paths.
  2. Perform Risk Assessment: Map out the attack surface for your software and document the mitigations for the "secure by design" requirement.
  3. Implement Vulnerability Reporting: Provide a 24-hour reporting mechanism to ENISA for actively exploited vulnerabilities.
  4. Generate an SBOM: Ensure all dependencies used in your Cloud Storage Providers are documented in a machine-readable Software Bill of Materials.
  5. Avoid the Common Pitfall: Conflating cloud provider (AWS/Azure) security responsibilities with the storage product's own CRA obligations — shared responsibility doesn't remove your duty.

How This Plays Out in Practice

A file-sync service needs to document its encryption-at-rest and in-transit approach explicitly to satisfy the CRA's data-confidentiality requirement, not just claim 'we use HTTPS.'

What to Watch For

Conflating cloud provider (AWS/Azure) security responsibilities with the storage product's own CRA obligations — shared responsibility doesn't remove your duty.

Assess Your CRA Readiness

Evaluate your product's Cyber Resilience Act readiness using our interactive tool. Find exactly which of the 22 security requirements apply directly to Cloud Storage Providers.

Need help with CRA? Ask the assistant.
Need help with CRA? Ask the assistant.