FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
856of856items
Across 40 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
Mar 10, 2026
Updated
Jul 24, 2026
CRA Remote Data Processing Solutions

What tests decide whether remote software is CRA RDPS?

The Commission's March 2026 draft CRA guidance frames the Article 3(2) definition around three checks: the processing is at a distance, the product cannot perform one of its functions without that processing, and the relevant software was designed and developed by the manufacturer or under its responsibility.

All three checks matter. A cloud-hosted function can be outside RDPS if the manufacturer did not design or commission the relevant software, and remote telemetry can be outside RDPS if the product still performs its functions without that processing.

Citations
CRA Remote Data Processing Solutions

Does CRA RDPS cover only the product's core function?

No. The draft guidance says the function test is not limited to the product's core functionality or narrow intended purpose. It can include functions that directly serve users and functions that support the product's overall performance.

Examples can include remote configuration, synchronisation, remote commands, onboarding, authentication, identity and access management, or updates if the product offers those as functions and the other RDPS criteria are met.

Citations
CRA Remote Data Processing Solutions

Does remote processing have to run in public cloud to be CRA RDPS?

No. The location and hosting model do not decide the outcome by themselves. The draft guidance says remote processing can happen over wired or wireless connections and can run in public cloud, private cloud, edge environments, or on local servers on the manufacturer's premises.

The practical question is whether the relevant software part performs data processing at a distance for a product function and falls under the manufacturer-design or manufacturer-responsibility test.

Citations
Cyber Resilience Act

Recital 11 explains that processing or storage at a distance is in scope only where necessary for product functions.

CRA Remote Data Processing Solutions

Does CRA RDPS include the whole backend or all cloud infrastructure behind a product?

No. Recital 11 says RDPS requirements do not turn the manufacturer's network and information systems as a whole into the CRA product. The draft guidance also treats RDPS as the software elements of remote data processing, not the underlying hardware infrastructure.

For conformity assessment, the draft guidance points to the parts of the system where data needed for product functions is stored or processed. Other backend systems can still create risks that the manufacturer must assess, but they are not automatically part of the product scope as RDPS.

Citations
Cyber Resilience Act

Recital 11 limits RDPS scope and excludes measures for the manufacturer's network and information systems as a whole.

CRA Remote Data Processing Solutions

Are ordinary websites, documentation pages, or portals CRA remote data processing solutions?

Usually not if they only provide information and do not support product functionality. Recital 12 says websites that do not support the functionality of a product with digital elements do not fall within CRA scope as products with digital elements.

A website or portal can be different if it actually supports a product function and meets Article 3(2). For example, a manufacturer-controlled authentication portal, command interface, or configuration portal may need RDPS analysis, while a static instruction page normally does not.

Citations
Cyber Resilience Act

Recital 12 distinguishes websites that do not support product functionality from remote processing that meets the CRA definition.

European Commission CRA FAQs

Section 1.2 explains that websites supporting product functionality may fall in scope to the extent they meet the RDPS definition.

CRA Remote Data Processing Solutions

What does under the responsibility of the manufacturer mean for CRA RDPS?

The draft guidance treats this as broader than in-house development but narrower than buying or licensing a standard third-party service. It covers remote processing software built for the manufacturer based on the manufacturer's designs and specifications.

Outsourced development can therefore remain under the manufacturer's responsibility. By contrast, the March 2026 Commission guidance is still a draft and indicates that a general-purpose SaaS product is not RDPS merely because the manufacturer configures or integrates it. The final classification still depends on the Article 3(2) facts and any later adopted Commission guidance.

Citations
Draft Commission guidance on the CRA

Points 179 and 180 explain tailor-made software, outsourced development, licensing, and the distinction between design responsibility and day-to-day operation.

CRA Remote Data Processing Solutions

How should CRA manufacturers treat IaaS, PaaS, and SaaS in RDPS analysis?

The cloud service model helps identify which software the manufacturer designed or controls, but it is not a substitute for the Article 3(2) test.

In the draft guidance, the manufacturer's own software running on third-party IaaS may qualify as RDPS if the other criteria are met. On third-party PaaS, the manufacturer's application layer may qualify, while provider platform functions may not. A third-party SaaS application that the manufacturer did not design or commission is generally not RDPS, even if the product depends on it.

Citations
Cyber Resilience Act

Recital 12 names SaaS, PaaS, and IaaS as cloud service models while keeping RDPS tied to the CRA definition.

CRA Remote Data Processing Solutions

If a product depends on third-party SaaS, is that SaaS automatically CRA RDPS?

No. If the product needs the service for a function but the relevant software was not designed and developed by the manufacturer or under its responsibility, the draft guidance says the service should be handled similarly to a third-party component rather than classified as RDPS.

That does not make the dependency irrelevant. The manufacturer still needs to assess the risks created by integrating or relying on that service and apply due diligence or product-level mitigations where needed.

Citations
European Commission CRA FAQs

Section 1.2 distinguishes standalone SaaS or cloud solutions developed outside the manufacturer's responsibility from RDPS.

CRA Remote Data Processing Solutions

Are analytics, telemetry, or internal business systems usually CRA RDPS?

Usually not, where the product can still perform its functions without that remote processing. The draft guidance gives remote analysis of telemetry for statistical purposes or future product development as an example of processing that is not RDPS when it is not needed for a product function.

Internal organisational systems such as HR, payroll, CRM, CI/CD, threat-hunting, penetration-testing, or red-team tooling are also not normally RDPS for the product. They may still matter to security posture and risk assessment, but they are not automatically part of the product with digital elements.

Citations
CRA Remote Data Processing Solutions

Is a cellular network or general connectivity provider itself CRA RDPS?

No, not merely because the product uses connectivity. The draft guidance's cellular-network use case treats the network as a communication channel in that scenario, not as remote data processing whose absence prevents the product from performing a function in the Article 3(2) sense.

The manufacturer still has to consider network-related risks in the product risk assessment and mitigate them through product-level controls where relevant.

Citations
Cyber Resilience Act

Article 13(2)-(3) requires cybersecurity risk assessment for the product, including its conditions of use and operational environment.

CRA Remote Data Processing Solutions

What does RDPS status change for CRA risk assessment and conformity assessment?

When remote processing qualifies as RDPS, it is part of the product with digital elements for CRA assessment. The manufacturer's cybersecurity risk assessment must cover the whole product, including in-scope RDPS and supporting functions.

The manufacturer should still avoid over-scoping. The draft guidance says conformity assessment should focus on the parts of the remote system where data necessary for product functions is stored or processed, while risks from surrounding infrastructure and third-party cloud services should be assessed and mitigated at product level.

Citations
Cyber Resilience Act

Article 13(2)-(4), Article 31, and Annex VII ground the risk-assessment and technical-documentation obligations.

European Commission CRA FAQs

Section 4.1.2 states that the cybersecurity risk assessment covers the entire product, including remote data processing when in scope.

CRA Remote Data Processing Solutions

What should CRA technical documentation say about RDPS and third-party cloud dependencies?

Where relevant, the technical documentation should identify whether the product has RDPS or relies on third-party cloud solutions and describe those solutions. If the same RDPS supports multiple products, it should still be declared in each product's documentation.

The documentation should connect the remote solution to the product function, explain whether it is manufacturer-designed or a third-party dependency, identify the parts of the system assessed for conformity, and record the risk assessment and mitigations for RDPS, third-party cloud reliance, and surrounding infrastructure.

Citations
Cyber Resilience Act

Article 31 and Annex VII require technical documentation with the data needed to assess product conformity and vulnerability-handling processes.

CRA Remote Data Processing Solutions

What should users be told when CRA RDPS or cloud dependencies affect secure use?

Article 13(18) requires products to be accompanied by Annex II information and instructions that are clear, understandable, intelligible, legible, and sufficient for secure installation, operation, and use. If RDPS, cloud connectivity, account services, or backend assumptions are needed for secure use, the user information should make those conditions understandable.

Annex II is especially relevant where remote dependencies affect intended purpose, essential functions, security properties, significant cybersecurity risks, secure commissioning and use, security updates, support-period information, decommissioning, or secure removal of user data.

Citations
Cyber Resilience Act

Article 13(18) and Annex II set the user-information and instruction duties relevant to remote functions, support, updates, and secure use.

European Commission CRA FAQs

Sections 4.1.3-4.1.5 explain that risk-assessment assumptions and significant cybersecurity risks can need to be reflected in user information.

CRA Remote Data Processing Solutions

Can contracts or SLAs with cloud providers transfer CRA responsibility away from the manufacturer?

No. Contracts, SLAs, and provider assurances can support risk mitigation and due diligence, but the CRA product obligation remains with the manufacturer placing the product with digital elements on the market.

The draft guidance says manufacturers should combine product-level security controls with verification of provider security measures. SLAs can help when they include security guarantees such as vulnerability-handling assurances and change-notification commitments from third-party cloud providers.

Citations
Cyber Resilience Act

Article 13(1), Article 13(2), Article 13(5), and Article 13(8) place design, risk, due-diligence, and vulnerability-handling obligations on manufacturers.

CRA Remote Data Processing Solutions

If a third-party cloud provider changes its service, is that automatically a CRA substantial modification of the product?

Not automatically. The draft guidance says major changes in third-party cloud solutions should not by themselves qualify as substantial modification of the product where those solutions are not under the manufacturer's responsibility.

The manufacturer still has to manage resulting risk. Change notice, reassessment, updated mitigations, and documentation may be needed where the provider change affects product security, product functions, or assumptions recorded in the risk assessment.

Citations
Draft Commission guidance on the CRA

Point 192 explains that third-party cloud changes are not automatically substantial modifications but still require due-diligence and risk-management attention.

Cyber Resilience Act

Article 13(3), Article 13(14), and Recitals 38-40 ground continuing risk-assessment updates, production conformity, and substantial-modification context.

Page 39 of 58