CEMarque

Does the CRA apply to WordPress plugins and themes?

Last verified 3 September 2026 · Facts v2026.09.2

It depends entirely on monetisation. A plugin or theme is installed software that a site owner adds to their own installation, which makes it a product with digital elements [1]. Whether it is in scope then turns on whether it is supplied in the course of a commercial activity [2].

The three common cases

Paid or freemium. In scope. A licence fee, a pro tier, a support subscription or an upsell inside a free plugin all make it commercial [2].

Free, published by a company. Usually in scope. If the plugin exists to support a commercial product or business, that is commercial activity even when nobody pays for the plugin itself [2].

Free, non-monetised, published by an individual or a community. Not placed on the market, and so outside the Regulation [3]. Note how easily this changes: adding a paid add-on, or being adopted into a commercial distribution, moves you across the line [4].

Applies to you if

  • You sell a plugin or theme, or a pro version of one [2].
  • You publish a free plugin that advertises or feeds a paid product [2].
  • You bundle third-party plugins into a product you sell under your own name [5].

Agencies: the case worth reading twice

If you build client sites from components and deliver them under your own name or trademark, you are the manufacturer of what you deliver [5]. Marketing a product under your own name makes you the manufacturer even when someone else developed it [5].

More generally, a developer who integrates a component into their own product is the manufacturer of that product and is responsible for its conformity, including the integrated parts [6]. That is uncomfortable but it is the design of the whole regime: the person who puts the finished thing in front of the customer is the person accountable for it.

Practically, this means an agency needs to know what is inside what it ships, and needs a route for handling a vulnerability in a component it did not write [6].

What the obligations actually look like

For a plugin author the near-term work is reporting readiness: from 11 September 2026 an actively exploited vulnerability in your plugin has to be reported, starting with an early warning within 24 hours of you becoming aware [7]. Plugins are an attractive target precisely because one vulnerability reaches thousands of sites, so this is not a theoretical duty.

The later work is conformity: from 11 December 2027 a plugin placed on the market needs technical documentation, a declaration of conformity and CE marking [8]. Plugins are default-class products in the ordinary case, so this is self-assessment rather than external certification [1].

The uncomfortable practical question

Many plugin businesses are one or two people with a marketplace listing and a support inbox. The honest answer is that the reporting duty is achievable at that size — it is a policy, a monitored address, and a decision you have made in advance — and the documentation duty is a weekend of work once, then maintenance [7]. What is not achievable at that size is discovering both obligations during an incident.

What to do next

Run your own product through the checker — it takes under a minute and gives you a dated, citable result you can send to a customer.

Check my product

Sources

  1. A product with digital elements is a software or hardware product and its remote data processing solutions, including components placed on the market separately, whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Art. 3(1), Art. 2(1)EUR-Lex
  2. The Regulation applies to products made available on the market in the course of a commercial activity; charging a price, charging for support, monetising via advertising or data, or otherwise intending to monetise are commercial activity. Art. 2(1), Art. 3(22), RecitalsEUR-Lex
  3. Free and open-source software not monetised is not considered placed on the market. Open-source software stewards (legal persons that systematically support free and open-source software intended for commercial activities) have a light regime: a documented cybersecurity policy, cooperation with authorities, and Article 14 reporting only where they are involved in development or where an incident affects their own development infrastructure; they do not affix CE marking and are not subject to fines. Art. 3(14), Art. 3(48), Art. 24, RecitalsEUR-Lex
  4. Monetisation or commercial redistribution by you changes a non-commercial verdict; re-check when that happens. RecitalsEUR-Lex
  5. Marketing a product under your own name or trademark makes you the manufacturer even if someone else developed it. Art. 3(13), Art. 22EUR-Lex
  6. A developer who integrates a component into their own product is the manufacturer of that product and responsible for its conformity, including the integrated component. Art. 13(5), Art. 3(13)EUR-Lex
  7. Article 14 (reporting obligations of manufacturers) applies from 11 September 2026. Art. 71(3)EUR-Lex
  8. The Regulation applies in full from 11 December 2027. Art. 71(2)EUR-Lex

Related

  • Does the CRA apply to open-source software I maintain?

    Unmonetised open source is not placed on the market and is outside the Regulation. Stewards who systematically support commercial-use projects have a lighter regime. Companies that integrate your code are manufacturers of their products.

  • Does the CRA apply to free or ad-supported apps?

    Charging nothing does not put you outside the Regulation. What matters is whether the product is supplied in the course of a commercial activity, and advertising, data and freemium funnels all count.

  • Does the EU Cyber Resilience Act apply to my mobile app?

    Yes, in almost every case. An installed app that connects to anything is a product with digital elements, and publishing it in an EU app store makes it available on the EU market.

  • Does the CRA apply to games?

    Yes for a commercially published game with any online component. The awkward parts for studios are the support period, automatic security updates for consumer products, and games that are already shipped.

CEMarque encodes Regulation (EU) 2024/2847 and the European Commission's published guidance as of 3 September 2026 (Facts v2026.09.2). It is not legal advice. Verify obligations for your product with qualified counsel where the stakes require it.