In scope, default category ยท Regulation (EU) 2024/2847

Is desktop software in scope of the EU CRA?

Verified against the Official Journal text on

In scope, default category (usually) (Art. 2(1), Art. 3(1))

Yes, this is the plain case the CRA was written for. A desktop application is software the user installs, so it is a product with digital elements, and supplying it to EU users in the course of business is making it available on the market, whether you charge for it or not. Most desktop software sits in the default category and can self-assess under internal control, so compliance is a documentation and process exercise. The exception is software whose core functionality matches a listed important category, such as an operating system, anti-malware, or a VPN, where the conformity route narrows.

Basis: Art. 2(1), Art. 3(1), Art. 3(22)

Judgment call: Whether desktop software "has the core functionality of" a listed Annex III category is a classification judgment; the technical descriptions in Implementing Regulation (EU) 2025/2392 control.

The paradigm product with digital elements Art. 2(1), Art. 3(1), Art. 3(22)

The CRA applies to products with digital elements made available on the market whose intended purpose or reasonably foreseeable use includes a direct or indirect data connection to a device or network. Installed desktop software that connects, even indirectly through an update channel or an API, fits without any stretch. This is the least ambiguous scope case in the regulation.

Making available on the market covers supply for distribution or use in the course of a commercial activity, in return for payment or free of charge. A free desktop tool that is part of your commercial activity is in scope; only genuinely non-commercial supply escapes.

Default category means you can run it yourself Art. 32(1), Art. 13

For a default-category product the manufacturer chooses the conformity assessment procedure freely, including plain self-assessment under internal control (module A). That keeps compliance a matter of building to the essential requirements, documenting, and running a process, without a notified body.

Most business and consumer desktop applications are default-category. The work is real but structured: the essential cybersecurity requirements, vulnerability handling, technical documentation, and CE marking, on the CRA timeline.

When desktop software becomes an important product Art. 7(1), Art. 32(2), Annex III

Some desktop software has the core functionality of a listed important category: operating systems, anti-malware, VPN products, password managers, identity or access management, or SIEM, among others. For those the conformity route narrows, and self-assessment stays available only where harmonised standards, common specifications, or eligible certification are applied in full.

Merely including such a feature does not make the whole application an important product. Integration of a listed component does not in itself pull the integrating product into the stricter route; core functionality does. Resolve close calls against the implementing act's technical descriptions.

Judgment call: The line between core functionality and a feature has no bright-line rule in the CRA text; the technical descriptions control and close calls deserve documented reasoning.

The manufacturer programme and the dates Art. 13, Art. 14, Art. 71(2)

As the software's manufacturer you design and build it to the essential cybersecurity requirements, handle vulnerabilities during the support period (including a coordinated vulnerability disclosure policy), draw up technical documentation, run the conformity assessment, and affix the CE marking. Reporting duties start 11 September 2026 and the full obligations apply from 11 December 2027.

What you must do

  • Design, develop, and produce the software in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities during the support period, including a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Draw up technical documentation, carry out conformity assessment, and affix the CE marking. (Art. 13(12), Art. 32)
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

Our desktop app is offline most of the time. Is it still in scope?

Almost certainly. Scope needs a direct or indirect data connection in the intended purpose or reasonably foreseeable use, and indirect counts, including update channels and APIs. Very few modern desktop applications have no connection at all. (Art. 2(1))

We give the software away for free. Does the CRA apply?

Free of charge does not take you out of scope. Making available on the market covers supply in the course of a commercial activity whether paid or free, so a free tool that is part of your commercial activity is in scope. (Art. 3(22), Recital 15)

How do we know if our software is an important product?

Check whether its core functionality matches a listed category such as operating systems, anti-malware, VPN, password managers, or SIEM. If it does, a stricter conformity route applies, and the match is decided by the implementing act's technical descriptions. (Art. 7(1), Annex III)

Confirm your category in three minutes

The Vexwatch Scope Checker walks the same cited decision tree: whether your software is in scope, whether it is a default or important product, and which obligations hit on which date.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.