Is your SaaS even in scope for the CRA?
- scope
- saas
- article-3
"We're SaaS, so the CRA doesn't apply to us" is the single most common thing we hear from companies who haven't actually run the assessment. It's not wrong exactly — it's incomplete in a way that matters as soon as your hosted service is anything more than a website.
The short answer
A purely hosted service — nothing installed, nothing shipped, nothing a customer runs on their own infrastructure — generally sits outside the Cyber Resilience Act's product scope. But the exemption is for the service being purely hosted, not for the word "SaaS" on your homepage. The moment your offering has a component that is placed on the market — an agent, an SDK, a CLI, a mobile app, a container image a customer deploys themselves — that component is a product with digital elements, and your hosted backend can be the "remote data processing" part of that same product.Art. 3(1)
Remote data processing
Article 3(1) defines a product with digital elements to include software or hardware "and its remote data processing solutions" where those are part of the product's design. A backend you operate is not automatically outside the Regulation just because it runs on your servers instead of the customer's — if it's the data-processing half of something you ship, it's part of the same product.
Where "we're SaaS" actually holds up
The exemption is real for what it's designed for: a genuinely hosted service with no installed counterpart. A web application your customers use entirely through a browser, with nothing distributed to their environment, is the case the Regulation is describing when it treats "product" as something placed on the market — a service isn't placed on the market the way a binary or a device is. If that's a complete and accurate description of what you sell, "unlikely in scope" is the right answer, and it's the answer our own scope check gives for exactly that shape of business.
Where it stops holding up
It stops holding up the moment any part of what you sell is installed rather than merely accessed. A monitoring agent that runs on a customer's servers, a browser extension, a mobile app that talks to your API, a Terraform module or Helm chart a customer deploys into their own environment — each of these is a product with digital elements in its own right, made available on the EU market, regardless of how central or peripheral it is to your actual business model. If your primary product is a web dashboard but you ship a lightweight agent so customers can send data to it, the agent is what puts you in scope, and your hosted service is very likely the remote data processing solution the agent depends on — which brings it in scope too, as part of the same product rather than as a separate exemption case.
Why this misconception is expensive both ways
Getting this wrong costs you in either direction. Assume you're exempt when you actually ship an installed component, and you've skipped the reporting duty entirely — not a paperwork gap, a compliance failure with fines reaching €15 million or 2.5% of worldwide turnover.Art. 64(2) Assume you're in scope when you're genuinely a pure hosted service, and you've built process and tooling around a duty that was never yours, which is its own kind of expensive.
This is exactly why we built the five-question scope check as a standalone, no-signup tool rather than folding the question into a sales conversation: it takes what you actually ship, not what your marketing site calls your business model, and gives you a verdict with the article it rests on. If the answer is "it depends on the agent," it says that plainly rather than defaulting to whichever answer is easier to hear.
Not sure whether this applies to you?
This produces evidence, timelines and drafts. It is not legal advice, and you remain the party responsible for reporting.