What is a "product with digital elements"?
A product with digital elements is a software or hardware product and its remote data processing solutions, including components placed on the market separately [1]. That single sentence carries most of the scoping work in the Regulation, and it is worth taking apart.
"Software or hardware product"
Both, and either alone. A mobile app with no hardware qualifies. A sensor with firmware qualifies. The phrase deliberately avoids drawing a line between the two, because the same security failure can live on either side of it [1].
"And its remote data processing solutions"
This is the clause that surprises people. Remote data processing means processing at a distance for which the software is designed and developed by the manufacturer, and the absence of which would prevent the product from performing one of its functions [2].
So a backend is not automatically part of the product, and it is not automatically outside it either. Two conditions have to hold: you designed and developed it as part of this product, and without it a function stops working [2]. Where both hold, the backend is covered by the same essential requirements and technical documentation as the thing the customer installed [3].
A cloud service that is not part of a product remains outside this Regulation, and may fall under the NIS2 Directive instead [4] [5].
"Including components placed on the market separately"
A library, an SDK, a module, a firmware image sold to integrators — these are products in their own right when they are placed on the market separately [1]. Their author is a manufacturer of that component.
At the same time, a developer who integrates a component into their own product is the manufacturer of that product, and is responsible for its conformity including the integrated parts [6]. Responsibility is not transferred up or down the chain; it attaches at each point where something is placed on the market [6].
What is not covered by this definition
Three things fall outside, and it is as useful to know these as the inclusions.
Something that is never made available on the EU market — supply for distribution or use on the EU market in the course of a commercial activity is what "made available" means [7].
A pure service with no product: no installed software, no device, no separately distributed component [4].
A product with genuinely no data connection of any kind, direct or indirect [1].
Why the definition is drawn this way
The regime is built around the observation that a security failure reaches users through whatever they actually run, regardless of how the vendor has organised its architecture or its billing. Defining the product to include the backend it depends on, and the components shipped inside it, closes the two gaps a narrower definition would leave: "the vulnerability was in our API, not the product", and "the vulnerability was in a dependency, not our code" [3] [6].
What to do next
Write down the boundary of your product in one paragraph: what the customer installs or receives, which of your services it cannot work without, and which third-party components ship inside it. That paragraph is the first section of your technical documentation, and it determines everything downstream of it [1].
What to do next
Run your own product through the checker — it takes under a minute and gives you a dated, citable result you can send to a customer.
Sources
- A product with digital elements is a software or hardware product and its remote data processing solutions, including components placed on the market separately, whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Art. 3(1), Art. 2(1) — EUR-Lex ↩
- Remote data processing means data processing at a distance for which the software is designed and developed by the manufacturer and the absence of which would prevent the product from performing one of its functions. Art. 3(2) — EUR-Lex ↩
- Where a product depends on your own remote data processing (a backend or API without which it cannot perform one of its functions), that remote processing is part of the product: it is covered by the essential requirements, the technical documentation and market surveillance alongside the client software or device. Art. 3(1)–(2), Annex I, Annex VII — EUR-Lex ↩
- Cloud services that are not part of a product are outside the Regulation (they fall under NIS2); remote data processing essential to a product is within scope as part of that product. Art. 3(1)–(2), Recitals — EUR-Lex ↩
- Cloud services may fall under NIS2 (Directive (EU) 2022/2555) rather than the CRA. NIS2 — EUR-Lex ↩
- A developer who integrates a component into their own product is the manufacturer of that product and responsible for its conformity, including the integrated component. Art. 13(5), Art. 3(13) — EUR-Lex ↩
- Made available on the market means supply for distribution or use on the EU market in the course of a commercial activity. Art. 3(22) — EUR-Lex ↩
Related
- Is SaaS in scope of the CRA?
A pure cloud service is generally outside the CRA and falls under NIS2 instead. But a backend your own installed product cannot function without is part of that product, and is in scope with it.
- Does the CRA apply to free or ad-supported apps?
Charging nothing does not put you outside the Regulation. What matters is whether the product is supplied in the course of a commercial activity, and advertising, data and freemium funnels all count.
- Does the EU Cyber Resilience Act apply to my mobile app?
Yes, in almost every case. An installed app that connects to anything is a product with digital elements, and publishing it in an EU app store makes it available on the EU market.
- Does the CRA apply to open-source software I maintain?
Unmonetised open source is not placed on the market and is outside the Regulation. Stewards who systematically support commercial-use projects have a lighter regime. Companies that integrate your code are manufacturers of their products.
CEMarque encodes Regulation (EU) 2024/2847 and the European Commission's published guidance as of 3 September 2026 (Facts v2026.09.2). It is not legal advice. Verify obligations for your product with qualified counsel where the stakes require it.