Does the CRA apply to browser extensions?
Yes, where there is commercial activity behind it. A browser extension is installed software that connects to a network, so it is a product with digital elements [1]. The usual monetisation test then decides scope: paid, freemium, ad-supported or data-monetised extensions are in, a genuinely non-monetised one is not [2].
The class question, which is where extensions get interesting
Being in scope and being in a higher class are two different questions. Higher-class products face a stricter conformity route, so it matters whether an extension falls in one [3].
Browsers themselves appear in the Annex III list of important products [4]. An extension is not a browser: it is software that runs inside one. The Commission's implementing regulation gives technical descriptions of each Annex III and Annex IV category, and those descriptions are what you check your product against rather than the category name alone [5].
The practical consequence is that most extensions are default-class products and can be self-assessed [3]. That is not automatic, though — an extension whose actual function is, say, a password manager or a VPN client should be checked against the descriptions rather than assumed to be default, because those functions have their own listings [5].
Applies to you if
- You publish a paid or freemium extension to the Chrome, Firefox, Edge or Safari stores [2].
- Your free extension carries advertising or supports a paid product [2].
- Your extension is the client half of a product with your own backend [6].
Extensions have a distinctive risk profile
Extensions typically hold broad permissions over pages the user visits, update silently, and are distributed through a store that can be compromised or that can be socially engineered into transferring ownership. Extension takeover — an author selling or losing control of a popular extension — is a recurring real-world incident pattern, not a hypothetical.
That shapes what your obligations will feel like in practice. The reporting duty from 11 September 2026 is about actively exploited vulnerabilities and severe incidents affecting the product's security, which is exactly the shape of an extension compromise [7].
What to do next
Three things are worth doing now, none of which requires waiting for further guidance.
Check your extension against the Annex III descriptions rather than against the category names, and record the conclusion [5]. If it is default class, you can self-assess, and knowing that removes the largest source of anxiety [3].
Secure the account that can publish updates, because that account is the product's supply chain [7].
Write down where a security researcher should send a report and who reads it. If your extension has your own backend behind it, remember that the backend is part of the product for these purposes [6].
What to do next
Run your own product through the checker — it takes under a minute and gives you a dated, citable result you can send to a customer.
Sources
- A product with digital elements is a software or hardware product and its remote data processing solutions, including components placed on the market separately, whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Art. 3(1), Art. 2(1) — EUR-Lex ↩
- The Regulation applies to products made available on the market in the course of a commercial activity; charging a price, charging for support, monetising via advertising or data, or otherwise intending to monetise are commercial activity. Art. 2(1), Art. 3(22), Recitals — EUR-Lex ↩
- Conformity routes: default products may use internal control (Module A), EU-type examination plus internal production control (Modules B+C), full quality assurance (Module H) or a European cybersecurity certification scheme; important class I must use B+C or H (or a scheme at 'substantial' level) unless harmonised standards, common specifications or such a scheme are applied in full; important class II must use B+C, H or a scheme at 'substantial' level; critical products use a European scheme where available, otherwise the class II procedures. Art. 32(1)–(4), Annex VIII — EUR-Lex ↩
- Annex III Part I — important products, class I (items 1–19). Annex III Part I; Implementing Regulation (EU) 2025/2392 — EUR-Lex ↩
- Commission Implementing Regulation (EU) 2025/2392 provides technical descriptions of the Annex III and Annex IV product categories (in force 21 December 2025); the class matcher uses those descriptions, not shorthand labels. Implementing Regulation (EU) 2025/2392; Art. 7(4) — EUR-Lex ↩
- Where a product depends on your own remote data processing (a backend or API without which it cannot perform one of its functions), that remote processing is part of the product: it is covered by the essential requirements, the technical documentation and market surveillance alongside the client software or device. Art. 3(1)–(2), Annex I, Annex VII — EUR-Lex ↩
- Article 14 (reporting obligations of manufacturers) applies from 11 September 2026. Art. 71(3) — EUR-Lex ↩
Related
- Does the CRA apply to free or ad-supported apps?
Charging nothing does not put you outside the Regulation. What matters is whether the product is supplied in the course of a commercial activity, and advertising, data and freemium funnels all count.
- Does the EU Cyber Resilience Act apply to my mobile app?
Yes, in almost every case. An installed app that connects to anything is a product with digital elements, and publishing it in an EU app store makes it available on the EU market.
- Does the CRA apply to games?
Yes for a commercially published game with any online component. The awkward parts for studios are the support period, automatic security updates for consumer products, and games that are already shipped.
- Does the CRA apply to WordPress plugins and themes?
A paid or freemium plugin is a product with digital elements and is in scope. A genuinely non-monetised free plugin is not. Agencies that ship client sites under their own name are manufacturers of what they ship.
CEMarque encodes Regulation (EU) 2024/2847 and the European Commission's published guidance as of 3 September 2026 (Facts v2026.09.2). It is not legal advice. Verify obligations for your product with qualified counsel where the stakes require it.