The paradigm product with digital elements Art. 2(1), Art. 3(1), Art. 3(22)
The CRA applies to products with digital elements made available on the market whose intended purpose or reasonably foreseeable use includes a direct or indirect data connection to a device or network. Installed desktop software that connects, even indirectly through an update channel or an API, fits without any stretch. This is the least ambiguous scope case in the regulation.
Making available on the market covers supply for distribution or use in the course of a commercial activity, in return for payment or free of charge. A free desktop tool that is part of your commercial activity is in scope; only genuinely non-commercial supply escapes.
Default category means you can run it yourself Art. 32(1), Art. 13
For a default-category product the manufacturer chooses the conformity assessment procedure freely, including plain self-assessment under internal control (module A). That keeps compliance a matter of building to the essential requirements, documenting, and running a process, without a notified body.
Most business and consumer desktop applications are default-category. The work is real but structured: the essential cybersecurity requirements, vulnerability handling, technical documentation, and CE marking, on the CRA timeline.
When desktop software becomes an important product Art. 7(1), Art. 32(2), Annex III
Some desktop software has the core functionality of a listed important category: operating systems, anti-malware, VPN products, password managers, identity or access management, or SIEM, among others. For those the conformity route narrows, and self-assessment stays available only where harmonised standards, common specifications, or eligible certification are applied in full.
Merely including such a feature does not make the whole application an important product. Integration of a listed component does not in itself pull the integrating product into the stricter route; core functionality does. Resolve close calls against the implementing act's technical descriptions.
Judgment call: The line between core functionality and a feature has no bright-line rule in the CRA text; the technical descriptions control and close calls deserve documented reasoning.
The manufacturer programme and the dates Art. 13, Art. 14, Art. 71(2)
As the software's manufacturer you design and build it to the essential cybersecurity requirements, handle vulnerabilities during the support period (including a coordinated vulnerability disclosure policy), draw up technical documentation, run the conformity assessment, and affix the CE marking. Reporting duties start 11 September 2026 and the full obligations apply from 11 December 2027.