{
  "class_items": [
    {
      "id": "III_I.1",
      "label": "Identity management and privileged access management (incl. authentication and access-control readers, biometric readers)",
      "examples": [
        "SSO product",
        "PAM software",
        "biometric door reader"
      ]
    },
    {
      "id": "III_I.2",
      "label": "Standalone and embedded browsers",
      "examples": [
        "desktop browser",
        "in-app browser engine shipped as a product"
      ]
    },
    {
      "id": "III_I.3",
      "label": "Password managers",
      "examples": [
        "password manager app or extension"
      ]
    },
    {
      "id": "III_I.4",
      "label": "Software that searches for, removes or quarantines malicious software",
      "examples": [
        "antivirus",
        "EDR agent"
      ]
    },
    {
      "id": "III_I.5",
      "label": "Products with virtual private network (VPN) functionality",
      "examples": [
        "VPN client",
        "VPN router feature"
      ]
    },
    {
      "id": "III_I.6",
      "label": "Network management systems",
      "examples": [
        "NMS",
        "network controller"
      ]
    },
    {
      "id": "III_I.7",
      "label": "Security information and event management (SIEM) systems",
      "examples": [
        "SIEM"
      ]
    },
    {
      "id": "III_I.8",
      "label": "Boot managers",
      "examples": [
        "bootloader"
      ]
    },
    {
      "id": "III_I.9",
      "label": "Public key infrastructure and digital certificate issuance software",
      "examples": [
        "CA software",
        "certificate issuance service shipped as software"
      ]
    },
    {
      "id": "III_I.10",
      "label": "Physical and virtual network interfaces",
      "examples": [
        "NIC",
        "virtual NIC"
      ]
    },
    {
      "id": "III_I.11",
      "label": "Operating systems",
      "examples": [
        "embedded Linux distribution",
        "RTOS sold as a product"
      ]
    },
    {
      "id": "III_I.12",
      "label": "Routers, modems intended for connection to the internet, and switches",
      "examples": [
        "consumer router",
        "managed switch"
      ]
    },
    {
      "id": "III_I.13",
      "label": "Microprocessors with security-related functionalities",
      "examples": [
        "SoC with secure enclave"
      ]
    },
    {
      "id": "III_I.14",
      "label": "Microcontrollers with security-related functionalities",
      "examples": [
        "MCU with secure boot / crypto engine"
      ]
    },
    {
      "id": "III_I.15",
      "label": "ASICs and FPGAs with security-related functionalities",
      "examples": [
        "crypto accelerator FPGA"
      ]
    },
    {
      "id": "III_I.16",
      "label": "Smart home general-purpose virtual assistants",
      "examples": [
        "voice assistant speaker"
      ]
    },
    {
      "id": "III_I.17",
      "label": "Smart home products with security functionalities (smart door locks, security cameras, baby monitoring systems, alarm systems)",
      "examples": [
        "smart lock",
        "IP camera",
        "baby monitor",
        "alarm hub"
      ]
    },
    {
      "id": "III_I.18",
      "label": "Internet-connected toys with social interactive features or location-tracking features",
      "examples": [
        "talking toy with camera",
        "GPS toy"
      ]
    },
    {
      "id": "III_I.19",
      "label": "Personal wearables with a health-monitoring purpose (outside MDR/IVDR) or intended for use by and for children",
      "examples": [
        "fitness tracker with heart-rate monitoring",
        "kids' smartwatch"
      ]
    },
    {
      "id": "III_II.1",
      "label": "Hypervisors and container runtime systems supporting virtualised execution of operating systems and similar environments",
      "examples": [
        "hypervisor",
        "container runtime"
      ]
    },
    {
      "id": "III_II.2",
      "label": "Firewalls, intrusion detection and prevention systems",
      "examples": [
        "firewall appliance",
        "IDS/IPS"
      ]
    },
    {
      "id": "III_II.3",
      "label": "Tamper-resistant microprocessors",
      "examples": [
        "tamper-resistant CPU"
      ]
    },
    {
      "id": "III_II.4",
      "label": "Tamper-resistant microcontrollers",
      "examples": [
        "tamper-resistant MCU"
      ]
    },
    {
      "id": "IV.1",
      "label": "Hardware devices with security boxes",
      "examples": [
        "HSM-class device"
      ]
    },
    {
      "id": "IV.2",
      "label": "Smart meter gateways within smart metering systems and other devices for advanced security purposes, including secure cryptoprocessing",
      "examples": [
        "smart meter gateway"
      ]
    },
    {
      "id": "IV.3",
      "label": "Smartcards or similar devices, including secure elements",
      "examples": [
        "smartcard",
        "secure element"
      ]
    }
  ],
  "disclaimer": "CEMarque encodes Regulation (EU) 2024/2847 and the European Commission's published guidance as of 3 September 2026 (Facts v2026.09.2). It is not legal advice. Verify obligations for your product with qualified counsel where the stakes require it.",
  "eli": "https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng",
  "facts": [
    {
      "id": "F-001",
      "kind": "date",
      "text": "Regulation (EU) 2024/2847 entered into force on 10 December 2024.",
      "cite": "Art. 71(1)"
    },
    {
      "id": "F-002",
      "kind": "date",
      "text": "Article 14 (reporting obligations of manufacturers) applies from 11 September 2026.",
      "cite": "Art. 71(3)",
      "date": "2026-09-11"
    },
    {
      "id": "F-003",
      "kind": "date",
      "text": "The Regulation applies in full from 11 December 2027.",
      "cite": "Art. 71(2)",
      "date": "2027-12-11"
    },
    {
      "id": "F-004",
      "kind": "rule",
      "text": "Products placed on the market before 11 December 2027 are subject to the Regulation only if substantially modified after that date; Article 14 applies to them regardless.",
      "cite": "Art. 69(2)–(3)"
    },
    {
      "id": "F-005",
      "kind": "definition",
      "text": "A product with digital elements is a software or hardware product and its remote data processing solutions, including components placed on the market separately, whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network.",
      "cite": "Art. 3(1), Art. 2(1)"
    },
    {
      "id": "F-006",
      "kind": "definition",
      "text": "Remote data processing means data processing at a distance for which the software is designed and developed by the manufacturer and the absence of which would prevent the product from performing one of its functions.",
      "cite": "Art. 3(2)"
    },
    {
      "id": "F-007",
      "kind": "rule",
      "text": "The Regulation applies to products made available on the market in the course of a commercial activity; charging a price, charging for support, monetising via advertising or data, or otherwise intending to monetise are commercial activity.",
      "cite": "Art. 2(1), Art. 3(22), Recitals"
    },
    {
      "id": "F-008",
      "kind": "rule",
      "text": "Cloud services that are not part of a product are outside the Regulation (they fall under NIS2); remote data processing essential to a product is within scope as part of that product.",
      "cite": "Art. 3(1)–(2), Recitals"
    },
    {
      "id": "F-009",
      "kind": "rule",
      "text": "Free and open-source software not monetised is not considered placed on the market. Open-source software stewards (legal persons that systematically support free and open-source software intended for commercial activities) have a light regime: a documented cybersecurity policy, cooperation with authorities, and Article 14 reporting only where they are involved in development or where an incident affects their own development infrastructure; they do not affix CE marking and are not subject to fines.",
      "cite": "Art. 3(14), Art. 3(48), Art. 24, Recitals"
    },
    {
      "id": "F-010",
      "kind": "exclusion",
      "text": "Excluded: medical devices (Regulation (EU) 2017/745) and in vitro diagnostics (2017/746) and motor-vehicle type-approved products (2019/2144) (Art. 2(2)); civil aviation products certified under Regulation (EU) 2018/1139 (Art. 2(3)); marine equipment under Directive 2014/90/EU (Art. 2(4)); spare parts made to identical specifications (Art. 2(6)); products developed or modified exclusively for national security or defence, or designed exclusively to process classified information (Art. 2(7)).",
      "cite": "Art. 2(2)–(4), (6)–(7)"
    },
    {
      "id": "F-011",
      "kind": "definition",
      "text": "Manufacturer: a natural or legal person who develops or manufactures products with digital elements or has them designed, developed or manufactured, and markets them under their name or trademark, whether for payment, monetisation or free of charge.",
      "cite": "Art. 3(13)"
    },
    {
      "id": "F-012",
      "kind": "obligation",
      "text": "Importers place only compliant products on the market; verify conformity assessment, technical documentation, CE marking and manufacturer identification; indicate their own name and address; report known vulnerabilities to the manufacturer; keep the declaration of conformity; cooperate with authorities.",
      "cite": "Art. 19"
    },
    {
      "id": "F-013",
      "kind": "obligation",
      "text": "Distributors act with due care; verify CE marking, declaration of conformity and manufacturer/importer obligations; do not make non-compliant products available; report vulnerabilities to the manufacturer; cooperate with authorities.",
      "cite": "Art. 20"
    },
    {
      "id": "F-014",
      "kind": "definition",
      "text": "Substantial modification: a change after placing on the market affecting compliance with essential requirements or resulting in a modification of the intended purpose; a person who substantially modifies a product becomes its manufacturer.",
      "cite": "Art. 3(30), Art. 22"
    },
    {
      "id": "F-015",
      "kind": "obligation",
      "text": "Support period: determined by the manufacturer to reflect the expected use time; at least five years unless the product is expected to be in use for less; the end date (month and year) is stated at purchase. A security update, once issued, remains available for at least ten years or the remainder of the support period, whichever is longer.",
      "cite": "Art. 13(8), (10), (25)"
    },
    {
      "id": "F-016",
      "kind": "obligation",
      "text": "Technical documentation (Annex VII) is drawn up before placing on the market and kept, with the EU declaration of conformity, for at least ten years after placing on the market or the support period, whichever is longer.",
      "cite": "Art. 13(13), (16), Art. 31"
    },
    {
      "id": "F-017",
      "kind": "requirement",
      "text": "Annex I Part I — product properties (secure by design and default; see checklist items I.1–I.3m).",
      "cite": "Annex I Part I"
    },
    {
      "id": "F-018",
      "kind": "requirement",
      "text": "Annex I Part II — vulnerability handling requirements (checklist items II.1–II.8).",
      "cite": "Annex I Part II"
    },
    {
      "id": "F-019",
      "kind": "requirement",
      "text": "Manufacturers identify and document vulnerabilities and components, including by drawing up a software bill of materials in a commonly used machine-readable format covering at the very least the top-level dependencies.",
      "cite": "Annex I Part II(1), Art. 13(31)"
    },
    {
      "id": "F-020",
      "kind": "requirement",
      "text": "User information and instructions (Annex II): manufacturer identity and contact; single point of contact for vulnerability reporting; product identification; intended purpose and security environment; circumstances that may lead to significant cybersecurity risks; where fixed-vulnerability information is published; support period end date; update installation and opt-out; secure decommissioning; access to the SBOM where relevant.",
      "cite": "Annex II, Art. 13(19)–(24)"
    },
    {
      "id": "F-021",
      "kind": "requirement",
      "text": "EU declaration of conformity (Annex V) and simplified declaration (Annex VI).",
      "cite": "Art. 28, Art. 13(15), (27), Annex V, Annex VI"
    },
    {
      "id": "F-022",
      "kind": "requirement",
      "text": "Technical documentation contents (Annex VII).",
      "cite": "Annex VII, Art. 31"
    },
    {
      "id": "F-023",
      "kind": "class_list",
      "text": "Annex III Part I — important products, class I (items 1–19).",
      "cite": "Annex III Part I; Implementing Regulation (EU) 2025/2392"
    },
    {
      "id": "F-024",
      "kind": "class_list",
      "text": "Annex III Part II — important products, class II (items 1–4).",
      "cite": "Annex III Part II; Implementing Regulation (EU) 2025/2392"
    },
    {
      "id": "F-025",
      "kind": "class_list",
      "text": "Annex IV — critical products (items 1–3).",
      "cite": "Annex IV; Implementing Regulation (EU) 2025/2392"
    },
    {
      "id": "F-026",
      "kind": "rule",
      "text": "Conformity routes: default products may use internal control (Module A), EU-type examination plus internal production control (Modules B+C), full quality assurance (Module H) or a European cybersecurity certification scheme; important class I must use B+C or H (or a scheme at 'substantial' level) unless harmonised standards, common specifications or such a scheme are applied in full; important class II must use B+C, H or a scheme at 'substantial' level; critical products use a European scheme where available, otherwise the class II procedures.",
      "cite": "Art. 32(1)–(4), Annex VIII"
    },
    {
      "id": "F-027",
      "kind": "rule",
      "text": "CE marking is affixed visibly, legibly and indelibly to the product, or where not possible to the packaging or the declaration of conformity/accompanying documents; for software, on the declaration of conformity or the website accompanying the product.",
      "cite": "Art. 29–30"
    },
    {
      "id": "F-028",
      "kind": "timeline",
      "text": "Actively exploited vulnerability: early warning within 24 hours of awareness; notification within 72 hours; final report within 14 days after a corrective or mitigating measure is available.",
      "cite": "Art. 14(1)–(2)"
    },
    {
      "id": "F-029",
      "kind": "timeline",
      "text": "Severe incident having an impact on the security of the product: early warning within 24 hours; incident notification within 72 hours; final report within one month after the incident notification.",
      "cite": "Art. 14(3)–(4)"
    },
    {
      "id": "F-030",
      "kind": "definition",
      "text": "Actively exploited vulnerability (Art. 3(42)): reliable evidence that a malicious actor has exploited it in a system without the system owner's permission. A severe incident having an impact on the security of the product (Art. 14(5)) is one that negatively affects or is capable of negatively affecting the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or that has led or is capable of leading to the introduction or execution of malicious code.",
      "cite": "Art. 3(42), Art. 3(44), Art. 14(5)"
    },
    {
      "id": "F-031",
      "kind": "rule",
      "text": "Notifications are submitted through the ENISA single reporting platform to the CSIRT designated as coordinator in the Member State where the manufacturer has its main establishment; a manufacturer without an EU establishment uses the Member State of its authorised representative, or where the product is made available.",
      "cite": "Art. 14(7), Art. 16"
    },
    {
      "id": "F-032",
      "kind": "obligation",
      "text": "After becoming aware of an actively exploited vulnerability or severe incident, the manufacturer informs impacted users, and where appropriate all users, without undue delay, including risk-mitigating and corrective measures.",
      "cite": "Art. 14(8)"
    },
    {
      "id": "F-033",
      "kind": "penalty",
      "text": "Fines up to EUR 15,000,000 or 2.5% of total worldwide annual turnover, whichever is higher (essential requirements in Annex I; obligations in Arts. 13 and 14); up to EUR 10,000,000 or 2% (other listed obligations, incl. Arts. 18–23, 28, 30, 31, 32); up to EUR 5,000,000 or 1% (incorrect, incomplete or misleading information to notified bodies or authorities). Microenterprises and small enterprises are not fined for missing the 24-hour early-warning deadline; open-source software stewards are not subject to fines.",
      "cite": "Art. 64(1)–(3), (6)–(7)"
    },
    {
      "id": "F-034",
      "kind": "obligation",
      "text": "A manufacturer may appoint an authorised representative by written mandate; the representative keeps the declaration of conformity and technical documentation at the disposal of authorities and cooperates with them. Non-EU manufacturers: reporting is routed via the representative's Member State.",
      "cite": "Art. 18, Art. 3(15)"
    },
    {
      "id": "F-035",
      "kind": "status",
      "text": "The European Commission approved practical guidance for manufacturers and businesses on 27 July 2026; formal adoption pending translations as of the facts date.",
      "cite": "Commission"
    },
    {
      "id": "F-036",
      "kind": "status",
      "text": "No harmonised standards for the CRA have been cited in the Official Journal as of the facts date; standardisation deadlines were proposed to move by about two months (July 2026 draft amendment).",
      "cite": "Commission / CEN-CENELEC"
    },
    {
      "id": "F-037",
      "kind": "status",
      "text": "Notified bodies for the CRA are being designated; the Commission targets sufficient capacity by December 2026 (best efforts).",
      "cite": "Commission"
    },
    {
      "id": "F-038",
      "kind": "status",
      "text": "ENISA single reporting platform: onboarding of Assigned Representatives began 31 July 2026; the platform was in testing in late August 2026 and is to be operational for 11 September 2026.",
      "cite": "ENISA"
    },
    {
      "id": "F-039",
      "kind": "status",
      "text": "The EU SECURE programme co-funds micro, small and medium enterprises up to EUR 30,000 for CRA readiness activities; first call ran 28 January–29 March 2026.",
      "cite": "Digital Europe Programme"
    },
    {
      "id": "F-040",
      "kind": "rule",
      "text": "Products are made available without known exploitable vulnerabilities and with a secure-by-default configuration.",
      "cite": "Annex I Part I(2)(a)–(b)"
    },
    {
      "id": "F-041",
      "kind": "rule",
      "text": "Security updates are installed automatically by default for consumer products, with a clear and easy-to-use opt-out mechanism.",
      "cite": "Annex I Part I(2)(c)"
    },
    {
      "id": "F-042",
      "kind": "rule",
      "text": "The manufacturer provides a single point of contact for users to report vulnerabilities and to receive information about vulnerabilities.",
      "cite": "Art. 13(20)–(22), Annex I Part II(6)"
    },
    {
      "id": "F-043",
      "kind": "rule",
      "text": "Manufacturers have a coordinated vulnerability disclosure policy in place and a contact address for reporting.",
      "cite": "Annex I Part II(5)–(6)"
    },
    {
      "id": "F-044",
      "kind": "rule",
      "text": "Manufacturers publicly disclose information about fixed vulnerabilities after a security update is available, including a description, affected products, impacts, severity and remediation information.",
      "cite": "Annex I Part II(4)"
    },
    {
      "id": "F-045",
      "kind": "rule",
      "text": "Manufacturers ensure secure distribution of updates and that security updates are provided free of charge, in a timely manner, with advisory messages.",
      "cite": "Annex I Part II(7)–(8)"
    },
    {
      "id": "F-046",
      "kind": "rule",
      "text": "Where a product contains an integrated third-party component (including open source), the manufacturer exercises due diligence and reports vulnerabilities found in components to the person maintaining them.",
      "cite": "Art. 13(5)–(6)"
    },
    {
      "id": "F-047",
      "kind": "rule",
      "text": "Market surveillance authorities may require corrective action, restriction, withdrawal or recall for non-compliant products.",
      "cite": "Chapter V (Arts. 52–60)"
    },
    {
      "id": "F-101",
      "kind": "note",
      "text": "Made available on the market means supply for distribution or use on the EU market in the course of a commercial activity.",
      "cite": "Art. 3(22)"
    },
    {
      "id": "F-102",
      "kind": "note",
      "text": "Monetisation or commercial redistribution by you changes a non-commercial verdict; re-check when that happens.",
      "cite": "Recitals"
    },
    {
      "id": "F-103",
      "kind": "note",
      "text": "Cloud services may fall under NIS2 (Directive (EU) 2022/2555) rather than the CRA.",
      "cite": "NIS2"
    },
    {
      "id": "F-104",
      "kind": "note",
      "text": "A developer who integrates a component into their own product is the manufacturer of that product and responsible for its conformity, including the integrated component.",
      "cite": "Art. 13(5), Art. 3(13)"
    },
    {
      "id": "F-105",
      "kind": "note",
      "text": "For products already on the market, conformity is not required until substantial modification, but customers and distributors may ask for it; Article 14 applies regardless.",
      "cite": "Art. 69(2)–(3)"
    },
    {
      "id": "F-106",
      "kind": "note",
      "text": "Marketing a product under your own name or trademark makes you the manufacturer even if someone else developed it.",
      "cite": "Art. 3(13), Art. 22"
    },
    {
      "id": "F-107",
      "kind": "note",
      "text": "Where a product depends on your own remote data processing (a backend or API without which it cannot perform one of its functions), that remote processing is part of the product: it is covered by the essential requirements, the technical documentation and market surveillance alongside the client software or device.",
      "cite": "Art. 3(1)–(2), Annex I, Annex VII"
    },
    {
      "id": "F-048",
      "kind": "status",
      "text": "Commission Implementing Regulation (EU) 2025/2392 provides technical descriptions of the Annex III and Annex IV product categories (in force 21 December 2025); the class matcher uses those descriptions, not shorthand labels.",
      "cite": "Implementing Regulation (EU) 2025/2392; Art. 7(4)"
    },
    {
      "id": "F-049",
      "kind": "rule",
      "text": "Manufacturers keep the user information and instructions (Annex II) at the disposal of users and authorities for at least ten years after placing on the market or for the support period, whichever is longer; a notification is displayed when the support period ends where technically feasible.",
      "cite": "Art. 13(24), (26)"
    },
    {
      "id": "F-050",
      "kind": "rule",
      "text": "A manufacturer may provide a simplified EU declaration of conformity that contains the internet address at which the full declaration can be accessed.",
      "cite": "Art. 13(27), Annex VI"
    }
  ],
  "facts_version": "2026.09.2",
  "pages": [
    {
      "slug": "applies-to-mobile-apps",
      "title": "Does the EU Cyber Resilience Act apply to my mobile app?",
      "question": "Does the EU Cyber Resilience Act apply to my mobile app?",
      "summary": "Yes, in almost every case. An installed app that connects to anything is a product with digital elements, and publishing it in an EU app store makes it available on the EU market.",
      "url": "https://cemarque.com/facts/applies-to-mobile-apps",
      "facts": [
        "F-002",
        "F-003",
        "F-004",
        "F-005",
        "F-007",
        "F-010",
        "F-101",
        "F-107",
        "F-016",
        "F-021",
        "F-028"
      ],
      "last_verified": "2026-09-03"
    },
    {
      "slug": "browser-extensions",
      "title": "Does the CRA apply to browser extensions?",
      "question": "Does the CRA apply to browser extensions?",
      "summary": "Yes, if it is monetised. An extension is installed software that connects to a network. The class question matters here: browsers are listed as important products, and extensions are not the browser.",
      "url": "https://cemarque.com/facts/browser-extensions",
      "facts": [
        "F-005",
        "F-023",
        "F-048",
        "F-007",
        "F-002",
        "F-026",
        "F-107"
      ],
      "last_verified": "2026-09-03"
    },
    {
      "slug": "by-11-december-2027",
      "title": "What must I do by 11 December 2027?",
      "question": "What must I do by 11 December 2027?",
      "summary": "Everything else. From full application a product placed on the EU market needs a completed technical file, an EU declaration of conformity you sign, CE marking, a stated support period and a software bill of materials.",
      "url": "https://cemarque.com/facts/by-11-december-2027",
      "facts": [
        "F-003",
        "F-016",
        "F-021",
        "F-022",
        "F-027",
        "F-015",
        "F-019",
        "F-020",
        "F-026",
        "F-004"
      ],
      "last_verified": "2026-09-03"
    },
    {
      "slug": "by-11-september-2026",
      "title": "What must I do by 11 September 2026?",
      "question": "What must I do by 11 September 2026?",
      "summary": "Be able to report. From that date manufacturers must notify actively exploited vulnerabilities and severe incidents through the ENISA platform, with an early warning within 24 hours of becoming aware.",
      "url": "https://cemarque.com/facts/by-11-september-2026",
      "facts": [
        "F-002",
        "F-028",
        "F-029",
        "F-030",
        "F-031",
        "F-032",
        "F-038",
        "F-042",
        "F-043",
        "F-033"
      ],
      "last_verified": "2026-09-03"
    },
    {
      "slug": "free-and-ad-supported-apps",
      "title": "Does the CRA apply to free or ad-supported apps?",
      "question": "Does the CRA apply to free or ad-supported apps?",
      "summary": "Charging nothing does not put you outside the Regulation. What matters is whether the product is supplied in the course of a commercial activity, and advertising, data and freemium funnels all count.",
      "url": "https://cemarque.com/facts/free-and-ad-supported-apps",
      "facts": [
        "F-007",
        "F-009",
        "F-101",
        "F-102",
        "F-005",
        "F-002"
      ],
      "last_verified": "2026-09-03"
    },
    {
      "slug": "games",
      "title": "Does the Cyber Resilience Act apply to games?",
      "question": "Does the CRA apply to games?",
      "summary": "Yes for a commercially published game with any online component. The awkward parts for studios are the support period, automatic security updates for consumer products, and games that are already shipped.",
      "url": "https://cemarque.com/facts/games",
      "facts": [
        "F-005",
        "F-007",
        "F-107",
        "F-002",
        "F-003",
        "F-015",
        "F-041",
        "F-004"
      ],
      "last_verified": "2026-09-03"
    },
    {
      "slug": "open-source",
      "title": "Does the CRA apply to open-source software I maintain?",
      "question": "Does the CRA apply to open-source software I maintain?",
      "summary": "Unmonetised open source is not placed on the market and is outside the Regulation. Stewards who systematically support commercial-use projects have a lighter regime. Companies that integrate your code are manufacturers of their products.",
      "url": "https://cemarque.com/facts/open-source",
      "facts": [
        "F-009",
        "F-102",
        "F-104",
        "F-007",
        "F-043",
        "F-002",
        "F-046"
      ],
      "last_verified": "2026-09-03"
    },
    {
      "slug": "product-with-digital-elements",
      "title": "What is a \"product with digital elements\"?",
      "question": "What is a product with digital elements under the CRA?",
      "summary": "A software or hardware product and its remote data processing solutions, including components placed on the market separately. The phrase is broad on purpose and the remote-processing half is the part people miss.",
      "url": "https://cemarque.com/facts/product-with-digital-elements",
      "facts": [
        "F-005",
        "F-006",
        "F-008",
        "F-107",
        "F-101",
        "F-104",
        "F-103"
      ],
      "last_verified": "2026-09-03"
    },
    {
      "slug": "saas-in-scope",
      "title": "Is SaaS in scope of the Cyber Resilience Act?",
      "question": "Is SaaS in scope of the CRA?",
      "summary": "A pure cloud service is generally outside the CRA and falls under NIS2 instead. But a backend your own installed product cannot function without is part of that product, and is in scope with it.",
      "url": "https://cemarque.com/facts/saas-in-scope",
      "facts": [
        "F-005",
        "F-006",
        "F-008",
        "F-103",
        "F-107",
        "F-003",
        "F-016"
      ],
      "last_verified": "2026-09-03"
    },
    {
      "slug": "wordpress-plugins-and-themes",
      "title": "Does the CRA apply to WordPress plugins and themes?",
      "question": "Does the CRA apply to WordPress plugins and themes?",
      "summary": "A paid or freemium plugin is a product with digital elements and is in scope. A genuinely non-monetised free plugin is not. Agencies that ship client sites under their own name are manufacturers of what they ship.",
      "url": "https://cemarque.com/facts/wordpress-plugins-and-themes",
      "facts": [
        "F-005",
        "F-007",
        "F-009",
        "F-102",
        "F-104",
        "F-106",
        "F-002",
        "F-003"
      ],
      "last_verified": "2026-09-03"
    }
  ],
  "regulation": "Regulation (EU) 2024/2847 (Cyber Resilience Act)",
  "released_at": "2026-09-03",
  "verified_at": "",
  "verified_by": ""
}
