Share This Article
The Cyber Resilience Act reaches the gambling sector more widely than most operators assume. Downloadable casino and sportsbook clients, mobile applications, gaming cabinets, self-service betting terminals, kiosks and the software supplied with them all qualify as products with digital elements, and the guidance approved by the European Commission on 27 July 2026 removes much of the uncertainty as to where the perimeter runs.
The general reading of that guidance, covering scope, obligations and deadlines across all sectors, is set out in the previous article on this blog. The analysis below applies the same framework to online and land-based gambling operators and to their suppliers.
Three dates govern the planning. The reporting obligations under Article 14 apply from 11 September 2026, including in respect of products already on the market. The Regulation applies in its entirety from 11 December 2027. EU type-examination certificates issued under other Union legislation may be relied upon until 11 June 2028.
1) Which gambling products fall within the scope of the CRA?
The test under Article 2(1) covers any product with digital elements whose intended purpose or reasonably foreseeable use includes a direct or indirect data connection to a device or network. Applied to the sector, the outcome is the following.
| Product | Within the scope |
|---|---|
| Downloadable casino, poker or sportsbook client for desktop | Yes |
| Mobile application distributed through an application store | Yes |
| Instant-play casino accessed exclusively through a browser | No, unless it supports the functionality of a product with digital elements |
| Informational or affiliate website with no product function | No |
| Gaming cabinet, VLT, AWP or electronic table game connected to a network | Yes |
| Self-service betting terminal, cashier kiosk, ticket redemption unit | Yes |
| Player account management platform licensed to an operator as software | Yes |
| Jackpot controller, cashless payment terminal, card reader, access control unit | Yes |
| Remote game server accessed by the operator through an interface | Assessed as a third-party component or as remote data processing, depending on who developed it |
The distinction between a downloadable client and a browser-only title is the single most consequential one for online operators. An operator whose product is played exclusively through a browser does not, on that basis alone, place a product with digital elements on the market. The same operator distributing a native mobile application does.
2) The cabinet and its software constitute one product
The channel through which software reaches the user is not decisive. Where software is necessary to operate, configure, control or use hardware according to its intended purpose, the two elements together constitute a single product with digital elements, and both are placed on the market at the same moment.
The consequence for land-based estates is direct. A cabinet, its firmware, the game software installed on it and the configuration utility supplied by the manufacturer form one product for the purposes of the Regulation, even where the game software is delivered later through a download or an update channel. The same conclusion applies to a betting terminal supplied with a separate management application, and to a mobile application that a player must install in order to use a connected loyalty card or a cashless wallet.
For standalone software, one rule deserves particular attention. Once a version is first supplied for distribution, every copy of that version is placed on the market at that same moment, whatever date each player downloads it. Builds that differ in included components or enabled functionalities, such as separate builds for different operating systems or market-specific bundles, are treated as distinct products and require their own assessment.
3) Remote game servers, player account platforms and SaaS: three different treatments
Remote data processing solutions form part of the product and must be covered by the risk assessment, the technical documentation and the conformity assessment. Their identification rests on three cumulative questions, namely whether the processing takes place at a distance, whether the absence of that processing would prevent the product from performing one of its functions, and whether the software was designed and developed by the manufacturer or under its responsibility.
Applied to a typical online gambling architecture, the classification runs as follows.
| Element | Treatment under the CRA |
|---|---|
| Back-end developed by the operator, without which the app cannot authenticate a player or place a bet | Remote data processing solution and part of the product |
| Software deployed by the operator on third-party IaaS or PaaS infrastructure | Ordinarily a remote data processing solution, since the software is developed under the operator’s responsibility |
| Third-party SaaS integrated into the product, such as a support chat, a KYC provider or an analytics tool | Third-party component, subject to due diligence and product-level mitigation |
| Back-end systems with which the product does not directly interact, such as settlement or reporting layers | External dependency to be assessed and mitigated at product level |
| Network connectivity, routers, cabling and wireless signals | Enabler of connectivity, outside the perimeter, with no due diligence obligation towards the provider |
A remote game server operated by a game studio and reached by the operator through an interface will normally fall in the third row, since the operator neither designed nor developed it. That does not remove the exposure. The operator remains required to identify the risks arising from the integration and to mitigate them within its own product, through authentication of the interface, verification of the integrity of the data received and controls that prevent the product from entering an insecure state when the service becomes unavailable.
4) Who is the manufacturer, the supplier or the operator?
The allocation of roles follows the same logic that the sector has become familiar with under the AI Act, and it produces comparable surprises.
- A supplier that builds a cabinet, a platform or a client and places it on the market under its own name is the manufacturer and carries the full set of obligations.
- An operator that distributes an application under its own brand is the manufacturer of that application, whatever development arrangement sits behind it.
- An operator or integrator that assembles components into a new product places a new product on the market and is its manufacturer for all purposes.
- A person who substantially modifies a product already placed on the market and makes it available becomes its manufacturer, in respect of the modified part alone where the cybersecurity of the product as a whole is unaffected, and in respect of the entire product where it is not.
The last point carries real consequences for operators that take a supplier’s platform and customise it heavily, which is common practice in this market. Customisation that alters the level of cybersecurity risk in a way the original risk assessment did not consider transfers the obligations, and the operator that believed itself to be a customer becomes the manufacturer of the modified product.
5) Conformity assessment: gaming certification does not replace CE marking
A product may have only one core functionality for the purposes of the applicable conformity assessment regime, and functions ancillary to it leave the classification unaffected.
For most gambling products the outcome is the default regime, which permits internal control based on module A. A gaming cabinet does not acquire the core functionality of an operating system merely because it integrates one, nor that of a firewall because it contains one. Attention is nonetheless required where a product’s core functionality corresponds to a category listed in Annex III or Annex IV, which may occur with access control units, biometric readers and certain payment or card-reading devices, and where third-party assessment then becomes mandatory or conditional.
Two consequences deserve to be recorded.
- Certification obtained under gaming technical standards, whether from a testing laboratory or under the technical rules of a national regulator, does not discharge the obligations under the CRA. The two regimes pursue different objectives, and the CE marking, the EU declaration of conformity and the technical documentation remain due in addition to any gaming approval.
- Where a harmonised standard covering the core functionality is applied, the presumption of conformity extends only to the risks that the standard actually covers. Ancillary functionalities outside its scope carry no presumption and the measures adopted in respect of them require separate documentation.
Where variants of a cabinet or of a client share the same architecture, security-relevant design and intended purpose, a single risk assessment, a single technical file and a single declaration of conformity may cover the whole family, provided that the declaration identifies the variants concerned.
6) Support periods and the length of a cabinet’s life
The minimum of five years operates as a safeguard and not as a default, since the support period must reflect the period during which the product is expected to be in use. Gaming cabinets, terminals and kiosks routinely remain in operation for seven to ten years, and a support period declared at five years will be difficult to defend for equipment of that kind. The end date must be communicated to the purchaser at the time of purchase, specifying at least the month and the year.
For iteratively developed software, Article 13(10) allows remediation to be limited to the version last placed on the market, provided that users of earlier versions can upgrade free of charge and without additional costs. Personnel time, routine testing and configuration adjustments count as ordinary maintenance effort. Mandatory purchases of new hardware and fundamental changes to the operating environment do not, which matters for operators running estates of older cabinets that cannot accept the latest build.
A substantial modification does not automatically reset the support period. The question is whether the change affects the factors that originally determined the expected use time. A software update adding new game modes leaves the durability of the cabinet untouched and the original period continues to run, whereas the replacement of the embedded computing platform with longer-lived components requires the period to be recalculated.
7) Legacy protocols in land-based estates
Casino management systems and machine communication protocols in widespread use were designed decades ago and offer limited security by modern standards. The guidance addresses this situation without granting an exemption.
Where an essential requirement cannot be met because the intended purpose of the product requires interoperability with existing infrastructure, the manufacturer is expected to document the constraint, to assess the associated risks and to implement compensatory measures. Where the product can technically support both a secure protocol and a legacy one, the secure protocol is to be implemented and enabled by default, with the legacy protocol available only where interoperability requires it. The constraint must be reassessed periodically and the product updated once it can be lifted.
8) Spare parts across an installed estate
Spare parts intended to replace identical components and manufactured to the same specifications are exempt under Article 2(6). Identity is assessed by reference to the functional role of the component and to characteristics relevant to cybersecurity, such as cryptographic mechanisms, protocols and access control features. A replacement bill validator, printer or display that performs the same function with the same security characteristics remains exempt, whereas a newer board with a different cryptographic implementation does not and constitutes a product with digital elements in its own right.
The exemption carries an evidentiary condition. The repair purpose must be apparent from the context of supply, through identification of the product or product family in the order or through supply via after-sales channels, and the evidence must remain available to market surveillance authorities. The same component offered through general retail channels loses the benefit.
9) Reporting from 11 September 2026, alongside every other notification duty
Actively exploited vulnerabilities and severe incidents affecting the security of the product must be notified simultaneously to ENISA and to the CSIRT designated as coordinator.
| Stage | Deadline |
|---|---|
| Early warning notification | Within 24 hours of becoming aware |
| Notification containing further information | Within 72 hours of becoming aware |
| Final report on an actively exploited vulnerability | Within 14 days of a corrective or mitigating measure becoming available |
| Final report on a severe incident | Within one month of the 72-hour notification |
Awareness arises when, after an initial assessment conducted promptly, the manufacturer holds a reasonable degree of certainty that a vulnerability in its product is being actively exploited or that a severe incident has compromised the security of that product.
The practical difficulty for gambling companies lies in the accumulation of parallel duties. A single incident affecting a player-facing application may trigger the CRA notification to ENISA and the coordinating CSIRT, a personal data breach notification under the GDPR, an incident report to the gambling regulator under national licence conditions, and, for entities within their scope, obligations under NIS 2 or DORA. The deadlines differ, the recipients differ and the thresholds differ. A single incident response procedure mapping all of them against one timeline is the only workable answer, and building it after the first incident is considerably more expensive.
10) What should be done now
- Inventory every product with digital elements placed on the market, distinguishing downloadable clients, mobile applications, cabinets, terminals, kiosks and licensed software.
- Determine, for each of them, whether the company acts as manufacturer, importer, distributor or integrator, paying particular attention to customised platforms.
- Classify the remote components as remote data processing solutions, third-party components or external dependencies, and record the reasoning.
- Verify whether any product has a core functionality falling within Annex III or Annex IV, since the conformity assessment route changes accordingly.
- Review declared support periods against the realistic operating life of the equipment.
- Document legacy protocol constraints together with the compensatory measures adopted.
- Establish the reporting procedure before 11 September 2026 and align it with the gambling, data protection and financial notification duties already applicable.
The work is largely documentary, and it is the documentation that market surveillance authorities will ask to see.
The DLA Piper technology and gaming teams assist online and land-based operators, platform providers and equipment manufacturers with CRA readiness assessments, product classification, technical documentation, supplier contracts and incident reporting procedures. Enquiries concerning a specific product portfolio are welcome at giulio.coraggio@dlapiper.com.
On a similar topic, the full schematic analysis of the Commission guidance is available in the previous article, and the position under the AI Act is covered in the article on the EU AI Act for gambling operators, suppliers and affiliates.

