Updated 6 October 2026 · Scope depends on your actual use case.
Which products are in scope?
The Cyber Resilience Act addresses products with digital elements placed on the EU market. Applicability depends on the product, its connectivity and your economic-operator role. A cloud or SaaS label alone is not enough to decide scope: integral remote data processing can matter.
Reporting is already a current obligation
The Commission lists CRA reporting obligations as applying from 11 September 2026, with the main requirements applying from 11 December 2027. Manufacturers should assess their reporting process for actively exploited vulnerabilities and severe incidents affecting product security. European Commission: Cyber Resilience Act.
Make security a product workstream
- Identify products, components and responsible owners.
- Review secure defaults, access and update mechanisms.
- Prepare vulnerability handling and incident reporting.
- Document support periods, dependencies and technical evidence.
NIS2 has a different scope: assess the entity, sector, size and national law rather than treating CRA and NIS2 as interchangeable.
Discuss cyber readinessFor more EU regulatory guides, visit regulations.md.