Every CRA question starts with one prior question: does it apply to me at all? The regulation answers with a single phrase, and it's written to be inclusive rather than narrow — which means most software and connected-hardware makers are in, and the interesting work is spotting the exceptions.
The definition
A product with digital elements is any software or hardware product — and its remote data-processing solutions — whose intended purpose includes a direct or indirect data connection to a device or network. Three things are doing the work there: it covers software as well as hardware; it reaches the cloud-side components a product needs to function; and the connectivity can be indirect, so "it doesn't talk to the internet directly" isn't an escape.
What's in scope
In everyday terms, that captures:
- Connected software applications and their components.
- IoT, embedded and connected hardware — see CRA for IoT & embedded.
- Operating systems, libraries, firmware and development tools placed on the market.
- The remote data-processing solutions a product relies on to do its job.
What's carved out
To avoid double regulation, products already governed by sector-specific EU rules are excluded — notably medical devices (MDR/IVDR), motor vehicles (type-approval), civil aviation, and marine equipment. If your product is comprehensively covered by one of those regimes, the CRA generally steps back. Everything else with digital elements is in.
The edges: SaaS and open source
Two boundaries are worth checking against your own architecture:
- SaaS. Software delivered purely as a service is generally outside the CRA's product scope (it may fall under NIS2 instead). But a remote data-processing solution that's necessary for a product's function is pulled back in — so a device or app that depends on your cloud is usually covered as a whole. Pure SaaS: often out. Product-plus-cloud: usually in.
- Open source. Non-commercial open-source development is largely out of scope, and open-source software stewards have a lighter, tailored regime. The line is commercial activity — monetised or shipped as part of a commercial offering, and the manufacturer obligations attach.
A quick test
Ask three questions: does the product have software in it or is it software; does its intended use involve a data connection (directly or indirectly); and is it placed on the EU market commercially, outside the carved-out sectors? Three yeses and you're almost certainly in scope — at which point the manufacturer's guide is where to go next.
Frequently asked
What is a "product with digital elements"?
Any software or hardware product, and its remote data-processing solutions, whose intended purpose includes a direct or indirect data connection to a device or network. It deliberately spans software, connected hardware, and the cloud-side components a product depends on to function.
Does the CRA apply to SaaS?
Software delivered purely as a service generally falls outside the CRA’s product scope, and may instead sit under rules like NIS2. But remote data-processing solutions that are necessary for a product’s functions are pulled back into scope, so a product-plus-cloud architecture usually is covered.
Does the CRA apply to open source?
Non-commercial open-source development is largely out of scope, and open-source software stewards get a lighter, tailored regime. Commercial activity is the dividing line — once open source is monetised or shipped as part of a commercial product, the manufacturer obligations attach.