You run a SaaS and ship an app? The CRA looks at the app
A browser-only SaaS is outside the Cyber Resilience Act. Add a mobile app, a desktop client or a device that needs your servers, and the picture changes. Here is where the line is, with the article references.
The question comes back every day since the scope test went live: "We are a SaaS, so we are not concerned, right?" Half right. Here is the other half.
A browser-only SaaS is outside
The Cyber Resilience Act applies to "products with digital elements" that are placed on the EU market. A service you run on your own servers, used through a browser, is not a product that is placed on the market. Recital 12 says it plainly: pure SaaS is not covered. NIS2 may apply to it instead, but only above its sector and size thresholds, which most small companies never reach.
So if your customers log in on a web page and nothing else runs on their side, you can stop reading. Keep your security practices, but the CRA paperwork is not for you.
The app changes everything
Now add one of these to the same service: an iOS or Android app, a desktop client, a browser extension, a command-line tool, an agent installed on a server, a device with firmware. Each of them is software that you put on the market. Each of them is a product with digital elements. The CRA applies to it.
And the regulation does not stop at the app. Article 3(2) defines "remote data processing": data processing at a distance, designed and developed by the manufacturer, without which the product could not perform one of its functions. Your back end, when the app depends on it, is exactly that. It comes with the product. The SBOM, the vulnerability handling and the security-by-design duties of Annex I cover the app and the parts of the back end the app cannot live without.
The practical reading: the CRA does not regulate your SaaS. It regulates your app, and it drags your back end in through the app.
What that means this week
Since 11 September 2026, Article 14 applies. If you learn that a vulnerability in your app is actively exploited, the early warning to your CSIRT and ENISA is due within 24 hours, the notification within 72 hours. That clock runs for the app, and for the back end functions it relies on.
Three things to have in place, in this order. A security contact that is monitored, published in a security.txt file. A software bill of materials for the app, regenerated at each release. A one-page procedure that says who decides, who notifies, and where the templates are. None of this requires a lawyer.
Two edge cases people ask about
An open-source client maintained without commercial activity stays outside (recital 18). The moment a company sells support for it, or ships it inside a paid product, the carve-out stops.
A device sold with a companion app: the device is the product, the app and the back end are its remote data processing. One product, one declaration, one SBOM per component.
If you are not sure which side of the line you are on, the free scope test asks eight questions and gives you a written result with the article references.
This is not legal advice.