Cyber Resilience Act (CRA) Compliance for Mobile Apps
Essential guide for iOS and Android publishers on SBOM obligations, technical documentation, and mandatory vulnerability reporting for the EU market.

The Cyber Resilience Act (CRA) applies to all mobile software products with digital elements made available on the EU market. Publishers must maintain a Software Bill of Materials (SBOM), implement secure update mechanisms, compile Annex VII technical documentation, and adhere to strict ENISA vulnerability notification windows.
Does the CRA apply to mobile application publishers?
Yes. EU Regulation 2024/2847 encompasses products with digital elements that connect to a device or network. Mobile apps distributed via the Apple App Store, Google Play, or direct APK channels in the EU fall under this scope, unless classified strictly as cloud services regulated by NIS2.
Publishers are legally responsible for the entire mobile lifecycle, including third-party SDKs, open-source dependencies, and backend API communication channels.
Core CRA requirements for mobile app publishers
The CRA establishes binding cybersecurity baselines governing the development, distribution, and maintenance of mobile applications.
Automated SBOM generation
Track all dependencies, cross-platform frameworks, and embedded SDKs across npm, CocoaPods, and Gradle using the standardized CycloneDX format.
Annex VII technical files
Maintain mandatory technical documentation, cybersecurity risk assessments, and EU declarations of conformity to ensure seamless audit readiness.
ENISA reporting workflows
Establish structured incident response procedures to meet the statutory 24-hour, 72-hour, and 14-day vulnerability notification deadlines.
Continuous vulnerability monitoring
Monitor upstream vulnerabilities in third-party libraries and receive proactive alerts before security disclosures impact your user base.
Managing mobile SDKs and release cycles under CRA scrutiny
Mobile teams manage complex dependency chains, from analytics to payment gateways. The CRA mandates rigorous controls over every component integrated into your binary.
- Cataloging transitive dependencies within third-party advertising, crash reporting, and analytics SDKs.
- Drafting explicit SECURITY.md policies visible to external researchers and store reviewers.
- Implementing secure update channels that bypass reliance on store review turnaround times.
- Maintaining an auditable trail of known vulnerabilities and remediation actions for every release.

Classification of mobile applications under EU Regulation 2024/2847
The CRA divides products with digital elements into three primary risk categories: default products, Important products (Annex III, classes I & II), and Critical products (Annex IV). Most consumer, productivity, and e-commerce mobile apps fall into the default category, allowing internal control-based conformity self-assessment.
However, mobile applications providing critical functionality—such as identity management, biometric authentication, VPN connectivity, or smart home control—may fall into Important Class I or II. These higher classifications trigger harmonized standards compliance or mandatory third-party conformity assessments by a notified body.
The third-party SDK dilemma in mobile architectures
Mobile software heavily leverages third-party binary artifacts and open-source packages. Under the CRA, the entity placing the mobile app on the market assumes legal responsibility for the security of all integrated code, regardless of whether an upstream library is maintained internally or by an external vendor.
A compliant software supply chain requires publishers to:
- Generate machine-readable Software Bills of Materials (SBOMs) identifying direct and indirect dependencies.
- Validate that upstream components receive security maintenance throughout the application's stated support period.
- Document remediation processes when an unpatched vulnerability is discovered within an external SDK.
Strict statutory timelines and non-compliance penalties
The regulation entered into force on 10 December 2024. Mobile publishers must prioritize two enforcement thresholds:
- 11 September 2026: Mandatory reporting obligations take effect for actively exploited vulnerabilities and severe incidents to ENISA and national CSIRTs within 24 hours of awareness.
- 11 December 2027: Full compliance obligations apply across all products, including complete technical documentation, SBOMs, and CE marking rules.
Failing to comply can result in administrative fines reaching up to EUR 15,000,000 or 2.5% of total worldwide annual turnover for the preceding financial year, whichever is higher, alongside market withdrawal orders across EU app stores.
Analyze your mobile codebase for CRA readiness
Scan your repositories, generate CycloneDX SBOMs, and identify security gaps before regulatory deadlines.
How to structure mobile app CRA compliance
- 1
1. Map dependencies & generate SBOMs
Inspect build manifests across your tech stack to maintain an accurate inventory of every integrated library.
- 2
2. Benchmark against technical requirements
Evaluate encryption, data handling, and update delivery against essential CRA cybersecurity standards.
- 3
3. Establish vulnerability reporting paths
Create a SECURITY.md file and integrate operational workflows to notify ENISA within 24 hours of exploit discovery.
- 4
4. Assemble Annex VII technical documentation
Maintain architecture records and risk assessments ready for review by EU market surveillance authorities.
How CRAcheck streamlines compliance for mobile publishers
CRAcheck is a self-assessment platform designed to help mobile publishers prepare for EU Regulation 2024/2847. While not a substitute for legal counsel, it automates the technical preparation required by law.
By connecting to your GitHub repositories, CRAcheck scans dependency trees across 9 ecosystems. It evaluates your security posture against CRA criteria, providing an objective compliance score.
The platform generates pre-filled compliance assets, including EU declarations of conformity, Annex VII templates, SECURITY.md files, and ENISA notification workflow guides.
Frequently Asked Questions
Does the Cyber Resilience Act apply to free mobile apps?+
Yes, if the app is part of a commercial activity. Monetization through ads, analytics, or premium tiers brings the software within the CRA's commercial scope.
Can mobile publishers rely entirely on App Store and Google Play security reviews?+
No. Store reviews verify marketplace guidelines but do not fulfill your legal obligations for documentation, SBOM maintenance, and incident reporting under the CRA.
What is the deadline for mobile app compliance under the CRA?+
Reporting obligations for exploited vulnerabilities begin 11 September 2026. Full compliance with security requirements and Annex VII documentation is required by 11 December 2027.
Does CRAcheck guarantee that my mobile application is officially certified?+
No. CRAcheck is a self-assessment tool. It assists with technical file generation and dependency tracking, but does not constitute an official government audit.
Which dependency ecosystems does CRAcheck support for mobile SBOMs?+
CRAcheck supports 9 ecosystems: npm, PyPI, Go, Rust, .NET, PHP, Ruby, Java, and standard CycloneDX SBOM uploads.
Prepare your mobile applications for CRA enforcement
Connect your GitHub repository to automate SBOM generation and assemble your Annex VII documentation today.
Same topic — Par type de produit
New to the Cyber Resilience Act? Start with the complete guide.
The CRA guideFrom the blog
Check your CRA compliance in 1 minute
Free, no sign-up. Scan your repo and get your compliance score + pre-filled documents.