Frequently asked questions

Scope

Is SaaS in scope? Standalone SaaS falls under NIS 2, not the CRA. A back end inseparable from a connected product is in scope as a remote data processing solution. → Scope

Is software sold by subscription in scope? Yes. The billing model is irrelevant: it is a software product.

Is a library you sell on its own in scope? Yes, as a component placed on the market separately. It has its own technical documentation and its own CE marking.

You make medical devices — are you excluded? Your medical devices fall under the MDR and are excluded from the CRA. Your other products are not. → Exclusions

You are established outside the Union — are you in scope? Yes, as soon as the product is made available on the Union market. An authorised representative established in the Union must be appointed. → Economic operators

You resell a third-party product under your brand — what is your status? Manufacturer. Every obligation falls on you.

Is an internal tool, not commercialised, in scope? No, absent placing on the market. It is still worth applying the same practices to it.

Timeline

Is a product sold in 2025 in scope? For CE marking: no, unless substantially modified. For reporting: yes, since 11 September 2026. → Timeline

Can you expect the deadlines to slip? No. The Regulation is in force and provides no deferral mechanism.

What is a substantial modification? A change that alters the product’s intended purpose or affects its compliance with the essential requirements. A security update alone is not one.

What is the first thing to do? Classify the portfolio, then engage notified bodies for class II and Critical products. → Roadmap

Classification

Does a firewall need a notified body? Yes: firewalls fall under Annex III, Part II, where self-assessment is excluded. → Class II

Your product performs several listed functions — which class? The highest applicable.

Does “self-assessment” mean fewer obligations? No. Only third-party verification disappears. The substance is identical. → Default category

Can a class I product self-assess? Only by applying in full harmonised standards covering all relevant requirements. Until they are cited in the Official Journal, that route is closed in practice.

SBOM

Can a spreadsheet be used as an SBOM? No. The Regulation requires a commonly used and machine-readable format.

Is a PDF enough? No, for the same reason.

Are transitive dependencies mandatory? The legal minimum is top level. That is a floor, not a target: incidents travel mostly through transitive dependencies. → What the CRA requires

Must you publish your SBOM? No. It must be in the technical documentation, held at the disposal of authorities. Sharing it with customers is a commercial decision. → Distribution

CycloneDX or SPDX? Both are acceptable. Your pivot format is CycloneDX, with SPDX export on request. → Formats

How long must you retain SBOMs? Ten years after placing on the market, or the support period if longer. → Retention

Two tools give two different SBOMs — which one is right? Both, within their scope. Pin the toolchain per product family and document the choice. → Generating SBOMs

One SBOM per version? Per publishable build. An SBOM with no version reference has no value.

Vulnerabilities and reporting

What happens if you miss the 24-hour deadline? It is a breach of Article 14, falling under the highest penalty ceiling — without prejudice to non-financial measures. → Penalties

Does a public exploit trigger the reporting obligation? No, not on its own. Reliable evidence of exploitation in a real system is required.

Is exploitation at a single customer enough? Yes. → Reporting

Who decides to report? Legal, on the PSIRT’s qualification, with a written delegation and a deputy. → Reporting duties

Must you fix every vulnerability your tools detect? No. They must be addressed. A vulnerability analysed and declared non-exploitable, with a standardised justification in a VEX, has been addressed. → VEX

Can a scanner alert be disabled? It can be set aside through a reasoned VEX, or muted on a dated basis. It cannot be erased. → False positives

Does CRA reporting replace GDPR notification? No. Three distinct regimes may apply to the same event. → Interplay

Open source

Is a free library you publish at no charge in scope? No, if the supply is outside a commercial activity. → Individual developer

Does accepting donations make the activity commercial? No, not on its own.

Are you responsible for the free components you embed? Yes, fully. Upstream is not responsible on your behalf. → Integrating open source

What is an open-source software steward? A legal person, other than a manufacturer, providing systematic and sustained support to the development of free software intended for commercial activities and ensuring its viability. A lightened regime, with no fines. → Steward

Must you report fixes upstream? Yes: report the vulnerability to the maintainer and, where relevant, share the fix.

Documentation and evidence

Who signs the EU declaration of conformity? A person authorised to bind the company. The declaration is issued under the sole responsibility of the manufacturer. → Declaration

Must the SBOM be in the technical documentation? Yes, under the vulnerability handling processes. → Technical documentation

What if an authority asks for your file? Apply the response card: acknowledge, qualify, freeze the evidence, answer within the deadline, log everything. → Market surveillance

Can you charge for access to security fixes? No, during the support period, except where otherwise agreed for tailor-made products between businesses. → Support period

Is the support period commercially negotiable? Its duration must be justified, at minimum five years unless the expected lifetime is shorter. It is not a free commercial variable.


A question missing from this list? See Contact — the FAQ is driven by the questions people actually ask.