Skip to main content

Guides to the Cyber Resilience Act, by kind of product

Six short guides, each answering the same four questions for one kind of product: does the Act apply, what happens when, what to do first, and where Permenta fits.

Pick your product

Each guide takes about five minutes to read and cites the article, annex or FAQ entry every statement rests on.

  • WordPress plugins

    A plugin is software supplied separately from WordPress, so the Cyber Resilience Act treats it as a product in its own right, whether you sell it or give it away as part of a commercial activity.

    Updated .

  • Electron and desktop apps

    A desktop application is software placed on the market; the Act reaches it through the operating system it runs on, and the auto-update mechanism you already ship is where most of its requirements land.

    Updated .

  • Mobile apps

    Apps distributed through the stores are products with digital elements; the free tier, the backend and the store listing each raise a question the Act answers.

    Updated .

  • Self-hosted software

    Software your customers install on their own infrastructure is the clearest case of a product with digital elements; open-core licensing, long-lived versions and update channels are where the details sit.

    Updated .

  • Firmware and connected devices

    Hardware with software inside is the Act’s original target: the device, its firmware and the cloud features it depends on are assessed together, and the CE marking goes on the product.

    Updated .

  • npm libraries and SDKs

    A package on a registry is a component placed on the market separately and so a product in its own right, but only when supplied commercially: for open source, monetisation is the test and the steward regime is the alternative.

    Updated .

How these guides are written

From the text, not from hearsay. Every guide draws on the same versioned catalogues the workspace uses.

The guides paraphrase Regulation (EU) 2024/2847, Implementing Regulation (EU) 2025/2392 and the Commission’s FAQ (version 1.4), using the obligations catalogue (version 1.0.0, sources retrieved 23 September 2026) and the scope rules (version 1.0.0, retrieved 23 September 2026). When a source is refreshed, the catalogue version changes and the guides are reviewed.

Not legal advice

The guides explain the Regulation as Permenta reads it. Whether a particular product is in scope, which class it is in and what it must do is your assessment, or your adviser’s. Permenta provides tooling and record-keeping; it does not certify compliance.