Frequently asked questions
Scope
Is SaaS in scope? Standalone SaaS falls under NIS 2, not the CRA. A back end inseparable from a connected product is in scope as a remote data processing solution. → Scope
Is software sold by subscription in scope? Yes. The billing model is irrelevant: it is a software product.
Is a library you sell on its own in scope? Yes, as a component placed on the market separately. It has its own technical documentation and its own CE marking.
You make medical devices — are you excluded? Your medical devices fall under the MDR and are excluded from the CRA. Your other products are not. → Exclusions
You are established outside the Union — are you in scope? Yes, as soon as the product is made available on the Union market. An authorised representative established in the Union must be appointed. → Economic operators
You resell a third-party product under your brand — what is your status? Manufacturer. Every obligation falls on you.
Is an internal tool, not commercialised, in scope? No, absent placing on the market. It is still worth applying the same practices to it.
Timeline
Is a product sold in 2025 in scope? For CE marking: no, unless substantially modified. For reporting: yes, since 11 September 2026. → Timeline
Can you expect the deadlines to slip? No. The Regulation is in force and provides no deferral mechanism.
What is a substantial modification? A change that alters the product’s intended purpose or affects its compliance with the essential requirements. A security update alone is not one.
What is the first thing to do? Classify the portfolio, then engage notified bodies for class II and Critical products. → Roadmap
Classification
Does a firewall need a notified body? Yes: firewalls fall under Annex III, Part II, where self-assessment is excluded. → Class II
Your product performs several listed functions — which class? The highest applicable.
Does “self-assessment” mean fewer obligations? No. Only third-party verification disappears. The substance is identical. → Default category
Can a class I product self-assess? Only by applying in full harmonised standards covering all relevant requirements. Until they are cited in the Official Journal, that route is closed in practice.
SBOM
Can a spreadsheet be used as an SBOM? No. The Regulation requires a commonly used and machine-readable format.
Is a PDF enough? No, for the same reason.
Are transitive dependencies mandatory? The legal minimum is top level. That is a floor, not a target: incidents travel mostly through transitive dependencies. → What the CRA requires
Must you publish your SBOM? No. It must be in the technical documentation, held at the disposal of authorities. Sharing it with customers is a commercial decision. → Distribution
CycloneDX or SPDX? Both are acceptable. Your pivot format is CycloneDX, with SPDX export on request. → Formats
How long must you retain SBOMs? Ten years after placing on the market, or the support period if longer. → Retention
Two tools give two different SBOMs — which one is right? Both, within their scope. Pin the toolchain per product family and document the choice. → Generating SBOMs
One SBOM per version? Per publishable build. An SBOM with no version reference has no value.
Vulnerabilities and reporting
What happens if you miss the 24-hour deadline? It is a breach of Article 14, falling under the highest penalty ceiling — without prejudice to non-financial measures. → Penalties
Does a public exploit trigger the reporting obligation? No, not on its own. Reliable evidence of exploitation in a real system is required.
Is exploitation at a single customer enough? Yes. → Reporting
Who decides to report? Legal, on the PSIRT’s qualification, with a written delegation and a deputy. → Reporting duties
Must you fix every vulnerability your tools detect? No. They must be addressed. A vulnerability analysed and declared non-exploitable, with a standardised justification in a VEX, has been addressed. → VEX
Can a scanner alert be disabled? It can be set aside through a reasoned VEX, or muted on a dated basis. It cannot be erased. → False positives
Does CRA reporting replace GDPR notification? No. Three distinct regimes may apply to the same event. → Interplay
Open source
Is a free library you publish at no charge in scope? No, if the supply is outside a commercial activity. → Individual developer
Does accepting donations make the activity commercial? No, not on its own.
Are you responsible for the free components you embed? Yes, fully. Upstream is not responsible on your behalf. → Integrating open source
What is an open-source software steward? A legal person, other than a manufacturer, providing systematic and sustained support to the development of free software intended for commercial activities and ensuring its viability. A lightened regime, with no fines. → Steward
Must you report fixes upstream? Yes: report the vulnerability to the maintainer and, where relevant, share the fix.
Documentation and evidence
Who signs the EU declaration of conformity? A person authorised to bind the company. The declaration is issued under the sole responsibility of the manufacturer. → Declaration
Must the SBOM be in the technical documentation? Yes, under the vulnerability handling processes. → Technical documentation
What if an authority asks for your file? Apply the response card: acknowledge, qualify, freeze the evidence, answer within the deadline, log everything. → Market surveillance
Can you charge for access to security fixes? No, during the support period, except where otherwise agreed for tailor-made products between businesses. → Support period
Is the support period commercially negotiable? Its duration must be justified, at minimum five years unless the expected lifetime is shorter. It is not a free commercial variable.
A question missing from this list? See Contact — the FAQ is driven by the questions people actually ask.