Cyber Resilience Act: the fine line between SaaS and digital products
Summary
The article explains how the EU Cyber Resilience Act (CRA) targets products with digital elements and draws a critical distinction between software made available as a product and cloud-hosted SaaS. It clarifies that pure cloud-native SaaS is generally excluded unless remote processing is essential to a product's core functionality, meaning architecture, packaging and commercial presentation determine CRA scope. The CRA requires secure-by-design/default practices, risk assessments, technical documentation, vulnerability handling, incident reporting and conformity assessments, with key dates (in force 10 Dec 2024; full application 11 Dec 2027; some obligations from 11 Sep 2026). The piece advises software vendors to map offerings, document SaaS vs product decisions early, and recognise that compliance choices may shift exposure to other EU laws like NIS2 and DORA.