CEMarque

Does the EU Cyber Resilience Act apply to my mobile app?

Last verified 3 September 2026 · Facts v2026.09.2

Yes, in almost every case. An app you publish for iOS or Android is installed software that connects to a network, which makes it a product with digital elements [1]. Publishing it in an app store that serves the EU makes it available on the EU market, wherever your company is [2].

The three things that would take your app out of scope are narrow. It is not made available in the EU at all — a genuine geographic restriction, not merely a lack of translation [2]. It is not provided in the course of a commercial activity, which excludes non-monetised hobby projects but not free apps that carry advertising or that feed a paid product [3]. Or it falls under a sector regime that displaces this one, such as a regulated medical device [4].

Your backend counts too

This is the part people miss. If your app talks to a backend you built, and the app cannot do one of its functions without it, that backend is part of the product [5]. It is covered by the same essential requirements and appears in the same technical documentation as the app itself [5]. A pure cloud service with no installed component is a different matter and generally falls outside this Regulation [1].

So "we are just an app, the API is separate infrastructure" is not a scoping argument. If the app is a shell around your API, the API is in scope with it [5].

Applies to you if

  • You publish an app to the App Store, Google Play, or any channel EU users can buy or download from [2].
  • The app is monetised in any way: paid, subscription, advertising, in-app purchases, data, or paid support [3].
  • The app connects to a network, another device, or your own backend [1].

Two dates, not one

There are two separate clocks and they are frequently collapsed into one, which produces wrong answers in both directions.

The first is reporting. From 11 September 2026 a manufacturer must report an actively exploited vulnerability in its product, and a severe incident affecting the product's security, through the ENISA single reporting platform: an early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report later [6] [7].

The second is CE marking. The Regulation applies in full from 11 December 2027, and from that date an app placed on the EU market needs technical documentation, an EU declaration of conformity and the CE marking [8] [9] [10].

If your app was already on the market before full application, it does not need CE marking until you substantially modify it — but the reporting duty applies to it regardless [11].

What this means in practice for a small team

Reporting readiness is the near-term work, and it is mostly process rather than paperwork. You need a contact address that a security researcher can find and that a human actually monitors. You need to know, in advance, who decides that something is an actively exploited vulnerability, because the 24-hour early warning starts when you become aware, not when you finish investigating [7]. And you need somewhere to send it, which means registering with the reporting platform rather than discovering it during an incident [6].

The CE marking work is larger but later: a technical file describing the product and how it meets the essential requirements, a bill of materials for the components you ship, a support period you have committed to, and a declaration you sign yourself [9] [10].

Most mobile apps are default-class products, which means you can self-assess: no notified body, no external audit, no certificate to buy [10]. The obligation is to do the work and to be able to show it.

What to do next

Run your own product through the checker — it takes under a minute and gives you a dated, citable result you can send to a customer.

Check my product

Sources

  1. A product with digital elements is a software or hardware product and its remote data processing solutions, including components placed on the market separately, whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Art. 3(1), Art. 2(1)EUR-Lex
  2. Made available on the market means supply for distribution or use on the EU market in the course of a commercial activity. Art. 3(22)EUR-Lex
  3. The Regulation applies to products made available on the market in the course of a commercial activity; charging a price, charging for support, monetising via advertising or data, or otherwise intending to monetise are commercial activity. Art. 2(1), Art. 3(22), RecitalsEUR-Lex
  4. Excluded: medical devices (Regulation (EU) 2017/745) and in vitro diagnostics (2017/746) and motor-vehicle type-approved products (2019/2144) (Art. 2(2)); civil aviation products certified under Regulation (EU) 2018/1139 (Art. 2(3)); marine equipment under Directive 2014/90/EU (Art. 2(4)); spare parts made to identical specifications (Art. 2(6)); products developed or modified exclusively for national security or defence, or designed exclusively to process classified information (Art. 2(7)). Art. 2(2)–(4), (6)–(7)EUR-Lex
  5. Where a product depends on your own remote data processing (a backend or API without which it cannot perform one of its functions), that remote processing is part of the product: it is covered by the essential requirements, the technical documentation and market surveillance alongside the client software or device. Art. 3(1)–(2), Annex I, Annex VIIEUR-Lex
  6. Article 14 (reporting obligations of manufacturers) applies from 11 September 2026. Art. 71(3)EUR-Lex
  7. Actively exploited vulnerability: early warning within 24 hours of awareness; notification within 72 hours; final report within 14 days after a corrective or mitigating measure is available. Art. 14(1)–(2)EUR-Lex
  8. The Regulation applies in full from 11 December 2027. Art. 71(2)EUR-Lex
  9. Technical documentation (Annex VII) is drawn up before placing on the market and kept, with the EU declaration of conformity, for at least ten years after placing on the market or the support period, whichever is longer. Art. 13(13), (16), Art. 31EUR-Lex
  10. EU declaration of conformity (Annex V) and simplified declaration (Annex VI). Art. 28, Art. 13(15), (27), Annex V, Annex VIEUR-Lex
  11. Products placed on the market before 11 December 2027 are subject to the Regulation only if substantially modified after that date; Article 14 applies to them regardless. Art. 69(2)–(3)EUR-Lex

Related

  • Does the CRA apply to free or ad-supported apps?

    Charging nothing does not put you outside the Regulation. What matters is whether the product is supplied in the course of a commercial activity, and advertising, data and freemium funnels all count.

  • Does the CRA apply to games?

    Yes for a commercially published game with any online component. The awkward parts for studios are the support period, automatic security updates for consumer products, and games that are already shipped.

  • Does the CRA apply to browser extensions?

    Yes, if it is monetised. An extension is installed software that connects to a network. The class question matters here: browsers are listed as important products, and extensions are not the browser.

  • What must I do by 11 December 2027?

    Everything else. From full application a product placed on the EU market needs a completed technical file, an EU declaration of conformity you sign, CE marking, a stated support period and a software bill of materials.

CEMarque encodes Regulation (EU) 2024/2847 and the European Commission's published guidance as of 3 September 2026 (Facts v2026.09.2). It is not legal advice. Verify obligations for your product with qualified counsel where the stakes require it.