Independent information resource Product security · EU CRA
CRA scope / 08

Does the CRA Apply to Desktop Software?

Understand when desktop applications can fall within the Cyber Resilience Act, including local software, downloads, network connections, update services, licensing servers, remote functions and commercial distribution.

IN BRIEF

Locally installed desktop software is not automatically outside CRA scope. Downloaded applications, commercial programs and other installed software can qualify as products with digital elements, particularly where they interact with devices, networks, update systems or other connected functions.

01 / 09

Desktop Software Can Be a Product With Digital Elements

The CRA expressly includes software products within the definition of products with digital elements. A desktop application therefore does not need to be embedded in hardware, delivered through a browser or hosted primarily in the cloud in order to require scope analysis. Commercially distributed software installed on laptops, workstations or other computers can potentially be covered when the remaining CRA scope conditions are met.

02 / 09

Local Execution Does Not Automatically Put Software Outside the CRA

A desktop program may perform most of its processing locally while still interacting logically with the host computer, other devices or networks. Article 2 does not state that a product must be a cloud service or continuously connected to the public internet. The relevant test concerns intended purpose or reasonably foreseeable use involving a direct or indirect logical or physical data connection to a device or network.

03 / 09

Internet Connectivity Is Not the Only Relevant Connection

Desktop applications can communicate with local devices, network shares, databases, peripherals, operating-system services, local servers or other software. A direct public internet connection is therefore not the only possible connection relevant to CRA scope. Teams should document the software's normal operating environment and the connections users are reasonably expected to make rather than relying on an online-versus-offline marketing label.

04 / 09

Digital Downloads Can Be Relevant to Making Available on the Market

Desktop software can be distributed through vendor websites, software marketplaces, enterprise download portals, package managers or other digital channels. CRA concepts of making available and placing on the market are not limited to physical distribution. Manufacturers should document how the software reaches EU users, who markets the product and the commercial context in which it is supplied.

05 / 09

Update Services Are Part of the Product Architecture

Many desktop applications connect to manufacturer infrastructure for update checks, security patches or package downloads. Those connections are relevant to the product's architecture and cybersecurity lifecycle. Whether a particular update service also qualifies as a remote data processing solution depends on the Article 3 definition, including whether remote processing is necessary for a product function. Regardless of that boundary question, secure updating is an important part of CRA vulnerability handling for covered products.

06 / 09

Licensing and Authentication Services Need Functional Analysis

Commercial desktop software can depend on remote licensing, account authentication or entitlement services. If the manufacturer's remote software is necessary for the product to perform one of its functions, the remote data processing definition may become relevant. A one-time licence validation that does not support a continuing product function can present different facts from an application that cannot operate without an ongoing manufacturer service. Teams should document the architecture rather than applying one conclusion to every licensing model.

07 / 09

Desktop Software and SaaS Should Not Be Treated as the Same Model

A desktop application is typically supplied as software that executes on the user's electronic information system, while SaaS can involve substantial remote execution or browser-based delivery. The CRA can be relevant to either model, but the product-boundary analysis differs. Desktop teams should identify installed code, local functionality, update infrastructure and necessary remote functions instead of assuming that the SaaS analysis automatically applies.

08 / 09

Purely Internal Desktop Tools Raise a Different Scope Question

A desktop application developed and used only inside one organisation can require a different analysis from software commercially supplied to customers. CRA market concepts focus on making products available on the Union market in the course of a commercial activity. This cluster contains a dedicated article on internally developed software because distribution and market availability can materially affect the conclusion.

09 / 09

Create a Versioned Desktop Product Record

For each commercial desktop product, record the installer or package, supported operating systems, network and device connections, update services, licensing functions, remote processing, components, distribution channels and supported versions. That product record should remain connected to cybersecurity risk assessment, vulnerability handling and technical documentation as the application evolves.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.