Cyber Resilience Act for Desktop Software
Essential compliance strategies for standalone, client-side, and on-premise desktop applications under EU Regulation 2024/2847.

The Cyber Resilience Act (CRA) applies to all commercial desktop software distributed within the EU that utilizes network connectivity. Vendors are now legally responsible for implementing security-by-design, maintaining a comprehensive Software Bill of Materials (SBOM), managing the full product lifecycle, and adhering to mandatory incident reporting protocols for ENISA. Because desktop binaries bundle third-party dependencies and execute directly on user hardware, vendors must ensure the integrity of their entire distribution chain under EU Regulation 2024/2847.
Regulatory Scope for Desktop Applications
Unlike centralized SaaS platforms, desktop software operates in fragmented client environments across Windows, macOS, and Linux. The CRA categorizes these programs as 'products with digital elements' if they possess any network capabilities, shifting the burden of security onto the vendor regardless of the user's local environment.
Whether you distribute native binaries (C++, Rust, Go), managed runtimes (.NET, Java), or hybrid wrappers (Electron, Tauri), any commercial software placed on the EU market must align with these rigorous cybersecurity standards.
Key Compliance Pillars for Desktop Vendors
Proactive alignment with these requirements is critical to maintaining market access and engineering velocity before enforcement begins.
Comprehensive Desktop SBOMs
Maintain a precise, machine-readable inventory of every library, DLL, and native dependency compiled into your desktop installers.
Mandatory Vulnerability Disclosure
Adhere to statutory timelines for notifying ENISA and end-users within 24 hours of discovering an actively exploited vulnerability.
Secure Update Lifecycle
Implement documented, integrity-checked update mechanisms to deliver security patches throughout the product's support lifecycle.
Annex VII Technical Documentation
Consolidate threat assessments and EU declarations of conformity into a centralized file accessible to market surveillance authorities.
Modernizing Desktop Supply Chain Governance
Traditional desktop distribution prioritized release cadence and installer integrity. The CRA mandates a transition toward systematic supply chain transparency and reproducible compliance audit trails.
- Managing complex dependency trees across native and managed runtimes like .NET, Rust, Go, or C++.
- Executing end-of-life security maintenance and versioning strategies across multiple supported desktop releases.
- Providing users with transparent security advisories and verifiable, automated patch delivery systems.

Navigating Product Classification
EU Regulation 2024/2847 classifies products into default, important (Classes I and II), and critical categories. Most general-purpose desktop productivity tools and developer utilities fall under the default category, permitting internal self-assessment.
However, security-critical software—such as password managers, VPN clients, firewalls, or system utilities with administrative access—often falls into Class I or II. These designations may necessitate independent third-party audits to verify security standards.
Enforcement Timelines and Penalties
The regulation entered into force on 10 December 2024, with two critical milestones for desktop vendors:
- 11 September 2026: Mandatory reporting for actively exploited vulnerabilities and severe security incidents becomes effective.
- 11 December 2027: Full compliance required, including essential security requirements, SBOM availability, and formal declarations of conformity.
Non-compliance risks administrative fines up to EUR 15,000,000 or 2.5% of annual global turnover, and potential exclusion from the EU market.
Building a Robust Vulnerability Strategy
Decentralized client-side installations require a proactive response strategy. Vendors must maintain public disclosure policies, generate machine-readable SBOMs (e.g., CycloneDX) for every release, and ensure rapid notification capabilities to mitigate risks in legacy versions.
Evaluate Your Desktop Software Repositories
Connect your repository to automate CycloneDX SBOM generation, identify dependency vulnerabilities, and track your CRA compliance readiness.
Preparing Your Desktop Software for the CRA
- 1
1. Inventory Bundled Components
Generate a machine-readable SBOM for every release, mapping all open-source libraries and native packages.
- 2
2. Establish ENISA Reporting Workflows
Define internal escalation paths to meet the 24h early-warning, 72h notification, and 14-day final reporting requirements.
- 3
3. Compile Technical Documentation
Draft Annex VII documentation covering threat modeling, risk assessments, and secure build verification logs.
- 4
4. Execute Declaration of Conformity
Complete self-assessment files or coordinate third-party audits to obtain the CE marking required for EU distribution.
Accelerate Compliance with CRAcheck
CRAcheck is an automated self-assessment platform designed to streamline compliance for desktop software vendors. By integrating with your GitHub workflow, it reduces the manual burden of regulatory documentation.
- Automated SBOM Generation: Instantly create CycloneDX-compliant manifests across 9 ecosystems, including .NET, Go, Rust, and Java.
- Compliance Scoring & Monitoring: Track your compliance progress with real-time vulnerability alerts and objective readiness scores.
- Regulatory Templates: Export pre-filled templates for EU declarations of conformity, Annex VII documentation, and SECURITY.md policies.
- Incident Response Frameworks: Utilize built-in checklists mapped to ENISA’s mandatory disclosure milestones.
Note: CRAcheck is a documentation and preparation support tool and does not constitute official legal advice or certification.
Frequently Asked Questions
Does the CRA apply to desktop software distributed outside the EU?+
Yes, if your software is made available to users or commercial entities within the European Union, the CRA applies regardless of your company's headquarters.
Are open-source desktop applications subject to the CRA?+
Non-commercial open-source software is generally exempt. However, if the software is monetized, provided under a commercial license, or bundled with paid services, it must comply with CRA obligations.
What is the timeline for desktop software incident reporting?+
Vendors must provide an early warning to ENISA within 24 hours of discovering an exploited vulnerability, followed by a formal notification within 72 hours and a final report within 14 days.
Can desktop software vendors rely on self-assessment?+
For default-category software, vendors may use internal conformity assessments. Products classified under Annex III (Important Classes I and II) may require mandatory third-party evaluations.
Prepare Your Desktop Software for EU Regulation 2024/2847
Scan your repositories, generate verified CycloneDX SBOMs, and assemble the documentation required for Cyber Resilience Act compliance.
Same topic — Par type de produit
New to the Cyber Resilience Act? Start with the complete guide.
The CRA guideFrom the blog
Check your CRA compliance in 1 minute
Free, no sign-up. Scan your repo and get your compliance score + pre-filled documents.