CRA: mandatory reporting of actively exploited vulnerabilities and severe incidents to ENISA/CSIRT
Manufacturers that place a 'product with digital elements' on the EU market as a distinct product — connected/embedded hardware, distributable/installable software, firmware, and apps a manufacturer ships with a device — including small vendors and commercially-run open source. A pure browser-delivered SaaS with no distributed installable product is generally OUT of CRA scope per Recitals 11-12 (standalone remote data-processing solutions are excluded); the flags below can only approximate this distinction, so read this note rather than relying on the tags alone if you sell software purely as a hosted service.