Under the EU Cyber Resilience Act, online banking splits in two: the mobile app your customers install is a product with digital elements and fully in scope, while online banking used purely through a web browser is not itself a product. That line was drawn by the European Commission’s adopted CRA guidance (C(2026) 5252 final, 27 July 2026), which also retains the mobile banking worked example we analysed in our earlier article. Here is where the boundary falls, and what it means for banks running both channels.
The adopted guidance answers the question we hear most often as a follow-up to that article. Most banks run two digital channels, an app customers install and a web portal they simply visit. The new Section 2.2 of the guidance draws the line between the two, and it is worth understanding exactly where it falls.
Installed software is a product. Browser-only services are not.
The adopted guidance clarifies that software falls within the scope of the CRA where it is supplied to the user and executes on the user’s side, on or as part of their device or electronic information system. That covers the mobile banking app your customers download from an app store, a desktop application, a browser extension, and even an application built with web technologies but packaged for local installation.
By contrast, software that executes remotely and is merely accessed by the user is not, on that basis alone, a product with digital elements. Web applications, including progressive web apps, accessed exclusively through a web browser are the guidance’s own example. The same goes for websites: they are not themselves products with digital elements, and they fall within the CRA’s scope only where they support the functionality of a product with digital elements, that is, where they qualify as remote data processing.
Is online banking through a browser in scope of the Cyber Resilience Act?
Not as a product in its own right. But that is not the end of the analysis for a bank running both channels:
- Your mobile banking app: a product with digital elements. Everything from our earlier article applies, including the essential requirements, technical documentation, the risk assessment, and the reporting obligations, extending to back-end software that qualifies as remote data processing (such as the banking API layer).
- Your browser-only web portal: not itself a product with digital elements. It is not CE-marked and does not carry its own CRA conformity obligations.
- The overlap: where the same back-end also serves the app, that back-end is assessed through the app’s product boundary. A shared API layer that the app cannot function without remains remote data processing, part of the app as a product, regardless of the fact that the web portal uses it too.
- The reporting consequence: an actively exploited vulnerability in the app or in its remote data processing is reportable under Article 14. The adopted guidance also confirms the reporting obligations apply from 11 September 2026 to products already on the market, meaning your existing app and not just the next release, and continue to apply even after a product’s support period ends.
Why this distinction is not a loophole
It may be tempting to read Section 2.2 as an incentive to push customers toward the browser. That would miss the wider regulatory picture. A bank’s web services sit under DORA’s operational-resilience regime and, where relevant, NIS2. The CRA is the product law in that stack, not the only law. And wherever the installed app remains a channel, the CRA follows it in full. The practical takeaway is not that the browser channel escapes security regulation; it is that the CRA’s product boundary is now precise enough to map your architecture against with confidence.
What to do now
- Re-run your product-boundary mapping against the adopted guidance: which software do you supply for execution on the customer’s side (in scope), and which is browser-only (in scope only via remote data processing)?
- Update your CRA documentation references from the draft guidance to the adopted Communication (C(2026) 5252 final, 27 July 2026).
- Confirm your reporting readiness covers the app and its remote data processing from 11 September 2026, including versions already on the market.
Frequently asked questions
Q: Does the Cyber Resilience Act apply to web applications?
A: No, not as products. The Commission’s adopted guidance (Section 2.2) states that web applications and progressive web apps accessed exclusively through a browser are not products with digital elements. They fall in scope only where they qualify as remote data processing for a product, such as a back end that an installed app cannot function without.
Q: Does the CRA apply to free banking apps?
A: Yes. Under Article 3(13), a manufacturer includes anyone marketing software under their name whether for payment, monetisation or free of charge. A free app that is the gateway to paid banking services is a commercial product, and the bank is its manufacturer.
Q: When do the CRA reporting obligations start for banking apps?
A: 11 September 2026. From that date, actively exploited vulnerabilities and severe incidents must be reported, and the adopted guidance confirms this applies to apps already on the market and continues even after a product’s support period ends.
Working through CRA scoping for your products?
We help manufacturers of digital products in the financial services sector map their architecture to the CRA, from product-boundary and RDPS analysis to reporting readiness. Get in touch, or start with our free Step By Step Guide to Navigating the CRA
Sources
- Commission guidance on the application of Regulation (EU) 2024/2847 (Cyber Resilience Act), C(2026) 5252 final, 27 July 2026: Section 2.2 (software as a product with digital elements), Section 8 (remote data processing), Section 9.1 (reporting obligations) – https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation
- Regulation (EU) 2024/2847 (the CRA): Articles 3(1), 3(2), 14, 69(3), 71(2).
- Our earlier article: Banking Apps Under the EU Cyber Resilience Act: Scope, Remote Data Processing and the New Reporting Obligations