CRA Compliance for Mobile Apps: A 2027 Guide for EU Businesses
CRA Compliance for Mobile Apps: A 2027 Guide for EU Businesses
Why the Cyber Resilience Act changes mobile app developmentFor years, cybersecurity in software was treated as a technical nicety: something you bolte...
Why the Cyber Resilience Act changes mobile app development
For years, cybersecurity in software was treated as a technical nicety: something you bolted on once the product worked. That era is ending. With Regulation (EU) 2024/2847, the Cyber Resilience Act (CRA), the European Union has introduced a single legal framework of mandatory cybersecurity requirements for any software placed on its market. If your company already publishes a mobile app, or is planning to launch one, the way you design, build and maintain that product will change substantially.

The CRA is not a niche rule aimed at hardware manufacturers. It applies across the whole digital lifecycle, from the first line of code to the updates you ship years later. For businesses in Catalonia and across Spain, from Barcelona to Lleida, Tarragona and Girona, this is a strategic question rather than a purely legal one: compliance will influence who can sell, who can tender for public contracts and who retains user trust.
Which mobile apps fall under the CRA?
The regulation covers any application distributed commercially in the EU market that connects, directly or indirectly, to a network or another device. In practice, that is almost every app on the App Store and Google Play. It includes:
- Paid apps and freemium models with in-app purchases.
- Free apps that monetise user data or display advertising.
- Corporate applications, both B2B and B2C, that link to commercial services or act as local clients connecting to SaaS platforms and cloud APIs.
Some categories sit outside the scope. Software developed exclusively for national defence or public security is excluded, as are medical devices and aviation products that already follow sector-specific cybersecurity rules. Free and open-source software developed or supplied outside a commercial activity also benefits from specific exemptions, though the picture becomes more nuanced as soon as that software is monetised.
The CRA timeline: dates to mark in your calendar
The law follows a gradual transition, giving development teams and app owners time to adapt their technical and legal processes. Three milestones matter most:
- 10 December 2024: the regulation entered into force following its publication in the Official Journal of the EU.
- 11 June 2026: criteria for designating Notified Bodies, the independent audit organisations, begin to apply.
- 11 September 2026: the obligation to manage and report serious incidents becomes enforceable. From this date, any actively exploited vulnerability in an app must be reported to the competent authorities within 24 to 72 hours.
- 11 December 2027: full application. No commercial mobile app or software may be placed on the European market without a risk assessment, a technical file, a software bill of materials, a EU Declaration of Conformity and the CE marking.
One important nuance for existing products: apps published before December 2027 only need to undergo the full assessment if they receive a substantial modification to their design or functionality after that date. In practice, however, most active apps are updated regularly, so the exemption is narrower than it first appears.
Five duties that now shape every app project
To be sold legally and to withstand real-world threats, the development process must integrate five activities from the outset.
1. Risk assessment and secure design. From the architecture phase, a formal and documented cybersecurity risk assessment is required, ideally using recognised methodologies such as the OWASP Mobile Top 10. Apps must ship with a secure-by-default configuration: robust encryption in transit (TLS 1.3) and at rest, minimal permission requests and protection against reverse engineering.
2. A software bill of materials (SBOM). You must produce and maintain an up-to-date inventory of third-party components in machine-readable formats such as SPDX or CycloneDX. That means auditing every library you rely on, from analytics and payments to maps, alongside your framework choices such as Flutter, React Native or the native iOS and Android SDKs. Supply-chain failures are one of the main risks the CRA targets.
3. A minimum five-year support period. The manufacturer must guarantee and communicate a cybersecurity support window of at least five years, or the product's expected lifetime. During that period, free security updates must be distributed, independently of feature releases, whenever technically feasible.
4. A single point of contact and coordinated vulnerability disclosure. Companies need a clear channel for reporting vulnerabilities and a defined process for handling them, including timelines for fixes and communication with users.
5. Technical documentation and conformity. The technical file, the Declaration of Conformity and the CE marking are not paperwork added at the end: they are the evidence that the previous four duties are genuinely in place.
What this means for businesses and startups in Spain
For a startup preparing its first launch, the CRA is an opportunity to build compliance into the product from day one rather than retrofitting it later. For established companies with an existing app, the priority is an honest gap analysis: which third-party libraries are unmaintained, how vulnerabilities are tracked, whether the support commitment is realistic and documented.
Custom mobile app development for iOS and Android now has to be delivered with these obligations in mind. Teams that treat security as a design constraint, not a final checklist, will find the 2027 deadline far less disruptive. Those that leave it until the last quarter risk delays, rework and, in the worst case, being unable to place their app on the European market at all.
Related
- 10 Mobile App Ideas to Transform Your Business in 2025
- The Mobile App Boom: Why Your Business Needs a Custom App in 2025
- Monetising Mobile Apps: Key Business Models for 2025
- Chatbot IA
Put these ideas into practice
Talk to ALMC about a solution for your business. Explore your options or contact our team.
