Independent information resource Product security · EU CRA
CRA scope / 07

Does the CRA Apply to Mobile Apps?

Learn when mobile applications fall within the Cyber Resilience Act, including app distribution, device and network connections, APIs, remote databases, backend services and open-source considerations.

IN BRIEF

A mobile app can be a CRA product in its own right. Scope depends on how the app is supplied, its device or network connections, the commercial context and applicable exclusions. Necessary manufacturer-controlled backend services can extend the CRA product boundary beyond the code installed on the phone or tablet.

01 / 08

Mobile Apps Can Be Software Products Under the CRA

The CRA definition of a product with digital elements expressly includes software. A mobile application therefore does not need to be bundled with hardware to enter the CRA analysis. An app distributed for installation on smartphones, tablets or other devices can potentially be a software product with digital elements when the Regulation's scope conditions are satisfied.

02 / 08

App Store Distribution Can Be Relevant to Market Availability

CRA scope is connected to making products available on the Union market in the course of a commercial activity. Software distribution can occur digitally rather than through a physical supply chain. App marketplaces, direct downloads and other distribution channels can therefore be relevant when assessing whether a mobile application is made available on the Union market. Price alone is not decisive because commercial supply can occur free of charge.

03 / 08

Mobile Apps Commonly Meet the Data-Connection Element

Article 2 refers to intended purpose or reasonably foreseeable use involving a direct or indirect logical or physical data connection to a device or network. Mobile apps commonly exchange data with the host device, operating-system services, local peripherals, mobile networks, Wi-Fi networks, APIs or other systems. The analysis should still be based on the actual application rather than assuming every piece of mobile code has the same CRA position.

04 / 08

The CRA Specifically Discusses Mobile Apps and APIs

Recital 11 expressly describes a mobile application that requires access to an application programming interface or database provided through a service developed by the manufacturer. Where the absence of that remote processing would prevent the app from performing one of its functions, the service can be a remote data processing solution within the CRA product boundary. This example makes remote backend architecture particularly important for mobile-app scope assessments.

05 / 08

The Product Boundary Can Include Client and Backend Software

For some mobile products, analysing only the application package installed on the device produces an incomplete CRA boundary. Authentication services, manufacturer APIs, remote databases or server-side processing can be necessary for core app functions. Product teams should determine which remote elements meet the CRA definition and include those elements when assessing product cybersecurity risk and relevant controls.

06 / 08

Not Every Third-Party Service Used by an App Is Part of the Product

A mobile app may use advertising platforms, analytics tools, crash-reporting services, generic cloud infrastructure and other external systems. Those integrations do not automatically become remote data processing solutions belonging to the product. The statutory test focuses on manufacturer-controlled software and processing necessary for one of the product's functions. Third-party dependencies can still create cybersecurity risks even where they are outside that specific product-boundary definition.

07 / 08

Free Mobile Apps Can Still Require CRA Analysis

An app being available without a purchase price does not by itself remove it from the CRA. Making available on the market can occur free of charge where the supply takes place in the course of a commercial activity. The business model, commercial context, open-source status and specific CRA rules therefore matter more than whether the user pays to download the app.

08 / 08

Mobile App Compliance Continues After Release

Where a mobile app falls within CRA scope, the analysis is not limited to its first publication in an app marketplace. Manufacturers need to consider vulnerability handling, security updates, supported versions, product changes and relevant post-market responsibilities. Mobile release processes should connect version management and backend changes to the product cybersecurity risk assessment and technical evidence.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.