An app is a product, the store is the market Art. 2(1), Art. 3(1), Art. 3(22)
The CRA applies to products with digital elements made available on the market whose intended purpose or reasonably foreseeable use includes a data connection to a device or network. A mobile app is installed software and almost always connects, so it fits squarely. Publishing to an app store where EU users can obtain it is supply on the Union market.
Making available on the market covers supply for distribution or use in the course of a commercial activity, whether in return for payment or free of charge. A free app that supports your business, or that funnels users to paid services, is therefore in scope. Truly non-commercial supply is the narrow exception.
Default category, unless the core functionality is listed Art. 7(1), Art. 32(1), Annex III
Most apps are default-category products with digital elements. That is the lighter route: the manufacturer can choose self-assessment under internal control, so compliance is a documentation and process exercise you can run yourself. Nothing about being a phone app changes that.
The exception is an app whose core functionality matches a listed important category, such as a password manager, an identity or access management tool, a VPN, or anti-malware. Then the conformity route narrows and the classification needs resolving against the technical descriptions in Implementing Regulation (EU) 2025/2392.
Judgment call: Core-functionality classification has no bright-line rule in the CRA text; the implementing act's technical descriptions decide it, and close calls deserve documented reasoning.
Your backend often comes with the app Art. 3(2), Recital 11
Apps rarely work alone. Where your app needs an API or database provided by a service you developed, or that is developed under your responsibility, that backend is in scope as a remote data processing solution together with the app. The recitals use exactly this mobile-app-plus-API example.
So scope your compliance around the whole product, not just the binary in the store. A genuinely third-party backend outside your responsibility is treated differently, but your own backend is part of the product.
The manufacturer programme and the dates Art. 13, Art. 14, Art. 71(2)
As the app's manufacturer you design and build it to the essential cybersecurity requirements, handle vulnerabilities during the support period (including a coordinated vulnerability disclosure policy), draw up technical documentation, run the conformity assessment, and affix the CE marking. Reporting duties start 11 September 2026 and the full obligations apply from 11 December 2027.