Scope: products with digital elements

This is the first question, and it conditions everything else: are you in scope, and for which products?

The definition

A product with digital elements (PDE) is a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately (Art. 3, point 1).

Three elements, to be examined separately.

Hardware

Computers, servers, connected objects, network equipment, sensors, boards, chips, industrial controllers, payment terminals, medical-adjacent equipment not covered by the sectoral regulation, connected toys.

Software

Operating systems, applications, firmware, libraries, middleware, drivers — including components placed on the market separately. That last point is structural: a library you sell on its own is itself a PDE, with its own technical documentation and its own CE marking.

Remote data processing solutions

Remote data processing designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the product with digital elements from performing one of its functions (Art. 3, point 2).

This is how the cloud enters the CRA. The criterion is functional dependency: if the connected object stops performing one of its functions when the back end goes down, that back end is within the product’s scope.

SaaS: in or out?

The most frequently asked question, and the answer comes in two parts.

Case Regime
Standalone SaaS application, sold as a service, with no associated product Out of CRA scope. Falls, where applicable, under NIS 2 as a service of the entity.
Back end inseparable from a connected product you sell In scope, as the product’s remote data processing solution.
Downloadable software installed at the customer’s site, even sold by subscription In scope: it is a software product; the billing model is irrelevant.
Optional administration portal whose absence deprives the product of no function To qualify case by case; the absence of functional dependency argues for exclusion.

The business model is never the criterion. The criterion is what is made available and its functional dependency on the product.

The cumulative triggering criteria

A product falls under the Regulation when all three conditions are met:

  1. it is made available on the Union market, wherever the manufacturer is established;
  2. in the course of a commercial activity;
  3. it has a direct or indirect logical or physical data connection to a device or network.

“Indirect” is broad: a product that connects to nothing itself but exchanges data with another product that is connected satisfies the criterion.

Three terms not to confuse

  • Placing on the market — the first making available of a product on the Union market. That is the moment at which conformity is assessed.
  • Making available on the market — any subsequent supply in the course of a commercial activity, whether for payment or free of charge.
  • Putting into service — the first use in accordance with its intended purpose.

The pivot is this: conformity with the essential requirements is assessed at the time of placing on the market, but vulnerability handling and the supply of updates run for the whole support period.

Substantial modification

A modification is substantial where it changes the intended purpose of the product or affects its compliance with the essential requirements. It brings the product back into scope and triggers a new conformity assessment, updated technical documentation and, where applicable, a fresh involvement of the notified body.

This notion carries the entire transitional regime:

Products placed on the market before 11 December 2027 are subject to the Regulation only if they are subsequently substantially modified — except for the Article 14 reporting obligations, which apply to all products within scope, including those already on the market.

In other words: your legacy portfolio escapes CE marking, but not the 24-hour reporting obligation, which has applied since 11 September 2026. This is the point most often missed.

A security update that fixes a vulnerability, with no other change, is not a substantial modification.

What to produce

A qualification sheet per product, filed with the technical documentation and signed, which decides explicitly: nature of the product, presence of a connection, presence of an associated remote data processing solution, commercial character, PDE status, date and signatory. A consolidated portfolio table follows from it.

Products qualified as PDEs then go through Exclusions and Criticality classes.