In scope, default category ยท Regulation (EU) 2024/2847

Is a mobile app in scope of the EU CRA?

Verified against the Official Journal text on

In scope, default category (usually) (Art. 2(1), Art. 3(1))

Yes, in almost all cases. A mobile app is software the user installs, so it is a product with digital elements. Distributing it to EU users through an app store is making it available on the market, which covers supply in the course of a commercial activity whether the app is paid or free. So a free app that is part of your commercial offering is in scope just as a paid one is. Most apps land in the default category and can self-assess, unless the app's core functionality matches a listed important category (for instance a password manager or a VPN app), which restricts the conformity route.

Basis: Art. 2(1), Art. 3(1), Art. 3(22)

Judgment call: Whether an app "has the core functionality of" a listed Annex III category is a classification judgment; the technical descriptions in Implementing Regulation (EU) 2025/2392 control the match.

An app is a product, the store is the market Art. 2(1), Art. 3(1), Art. 3(22)

The CRA applies to products with digital elements made available on the market whose intended purpose or reasonably foreseeable use includes a data connection to a device or network. A mobile app is installed software and almost always connects, so it fits squarely. Publishing to an app store where EU users can obtain it is supply on the Union market.

Making available on the market covers supply for distribution or use in the course of a commercial activity, whether in return for payment or free of charge. A free app that supports your business, or that funnels users to paid services, is therefore in scope. Truly non-commercial supply is the narrow exception.

Default category, unless the core functionality is listed Art. 7(1), Art. 32(1), Annex III

Most apps are default-category products with digital elements. That is the lighter route: the manufacturer can choose self-assessment under internal control, so compliance is a documentation and process exercise you can run yourself. Nothing about being a phone app changes that.

The exception is an app whose core functionality matches a listed important category, such as a password manager, an identity or access management tool, a VPN, or anti-malware. Then the conformity route narrows and the classification needs resolving against the technical descriptions in Implementing Regulation (EU) 2025/2392.

Judgment call: Core-functionality classification has no bright-line rule in the CRA text; the implementing act's technical descriptions decide it, and close calls deserve documented reasoning.

Your backend often comes with the app Art. 3(2), Recital 11

Apps rarely work alone. Where your app needs an API or database provided by a service you developed, or that is developed under your responsibility, that backend is in scope as a remote data processing solution together with the app. The recitals use exactly this mobile-app-plus-API example.

So scope your compliance around the whole product, not just the binary in the store. A genuinely third-party backend outside your responsibility is treated differently, but your own backend is part of the product.

The manufacturer programme and the dates Art. 13, Art. 14, Art. 71(2)

As the app's manufacturer you design and build it to the essential cybersecurity requirements, handle vulnerabilities during the support period (including a coordinated vulnerability disclosure policy), draw up technical documentation, run the conformity assessment, and affix the CE marking. Reporting duties start 11 September 2026 and the full obligations apply from 11 December 2027.

What you must do

  • Design, develop, and produce the app in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities during the support period, including putting in place and enforcing a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Draw up technical documentation, carry out conformity assessment, and affix the CE marking. (Art. 13(12), Art. 32)
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

Our app is free. Does the CRA still apply?

Free of charge does not take you out of scope. Making available on the market covers supply in the course of a commercial activity whether paid or free, so a free app that is part of your commercial offering is in scope. (Art. 3(22), Recital 15)

The app store handles distribution. Are we still the manufacturer?

Yes. If you developed the app and supply it under your own name, you are the manufacturer and carry the obligations. The store is a distribution channel, not a substitute for the manufacturer's responsibilities. (Art. 3(13), Art. 13)

When could our app be an important product?

When its core functionality matches a listed category, for example a password manager, an identity or access management tool, a VPN, or anti-malware. Then a stricter conformity route applies and the match is decided by the implementing act's technical descriptions. (Art. 7(1), Annex III)

Check your app in about three minutes

The Vexwatch Scope Checker walks the same cited decision tree: whether your app is in scope, in which category, whether your backend comes with it, and which obligations hit on which date.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.