Skip to main content
🎤 Speaking at KubeCon EU 2026 Lessons Learned Orchestrating Multi-Tenant GPUs on OpenShift AI View Session
🎤 Speaking at Red Hat Summit 2026 GPUs take flight: Safety-first multi-tenant Platform Engineering with NVIDIA and OpenShift AI Learn More
Does the CRA Apply to SaaS? Cloud Services and the CRA Boundary
DevOps

CRA and SaaS: Cloud Services Boundary

The CRA targets products with digital elements, not pure services. But the boundary between product and service is blurry.

LB
Luca Berton
· 1 min read

CRA and SaaS: Where’s the Boundary?

The CRA applies to products with digital elements placed on the EU market. Pure services are excluded. But the line between “product” and “service” is blurry.

What’s Covered

Software sold or distributed (even freely) to users ✅ Firmware embedded in hardware products ✅ Desktop/mobile applications available for download ✅ On-premises software deployed in customer environments ✅ Open source used commercially

What’s NOT Covered

Pure SaaS where the software runs entirely in the provider’s infrastructure ❌ Custom development (bespoke software built for one customer) ❌ Services regulated under NIS2 instead

The Grey Areas

SaaS with Client Components

If your SaaS requires a desktop agent, browser extension, or mobile app, those client components are products under the CRA:

Your SaaS Platform
├── Cloud backend (NOT CRA — it's a service → NIS2 applies)
├── Desktop agent (CRA product)
├── Mobile app (CRA product)
├── Browser extension (CRA product)
└── API SDK/library (CRA product if distributed)

PaaS/IaaS with Downloadable Tools

CLI tools, SDKs, and agents distributed to customers are CRA products even if the main platform is SaaS.

Open Source Libraries Published by SaaS Companies

If you publish open source libraries that others use in their products, the downstream manufacturer (not you) bears CRA obligations. But if you commercialize the library, you may be an Open Source Steward.

Practical Advice

  1. Audit your distribution — anything you give to users to install is likely a CRA product
  2. Client components need SBOMs — even if they’re thin clients
  3. Security updates for client software — 5-year obligation applies
  4. NIS2 for the service — your cloud infrastructure falls under NIS2, not CRA
  5. Document the boundary — clearly define what’s product vs. service

Navigating the CRA/NIS2 boundary for your cloud services? I help organizations clarify their compliance obligations. Get in touch.

Luca Berton Ansible Pilot Ansible by Example Open Empower K8s Recipes Terraform Pilot CopyPasteLearn ProteinLens TechMeOut