Mobile apps with EU users
If your app is available to users in the EU, some changes may be required on your side.
Due to regulatory changes in the EU, wdms will no longer publish apps under its own developer accounts on behalf of clients. This is a direct consequence of the EU Cyber Resilience Act (CRA).
If you want your app published to EU users, you will need your own DUNS number, under which you create your own Google and Apple developer accounts. Apple requires a 99 USD fee annually and Google has a one time fee of 25 USD. Both Apple and Google require a DUNS number to register as an organisation.
Getting a DUNS number
Getting a DUNS number is free, although the process takes some time and is
slightly bureaucratic. You can get your DUNS number via
CIALDNB. You only need to provide basic details,
their intake form is designed to upsell their financial services.
You can safely ignore their offering on plans. It’s not needed for DUNS.
For more information about DUNS visit Dun & Bradstreet.
Publishing under your own accounts
Publishing under your own developer accounts also means you can freely work with other developers going forward, since the apps are already under your own organisation, and there is no paperwork needed to use your own branding. It simplifies the app publication process overall. Vendors and sponsors will still need to supply approval to use their branding in your apps, regardless of who publishes.
If you currently have apps published under wdms developer accounts, those will be moved to your own organisation once you have both developer accounts set up.
EU Cyber Resilience Act
The CRA requires manufacturers — which, in most cases, means whoever publishes the app under their own developer account — to submit documentation to the EU. This requires an EU representative and technical documentation to be submitted to that representative. You can learn more about the CRA via The Linux Foundation
Under the CRA, these obligations fall on whoever places the product on the EU market — the manufacturer of record. If the app is published under your own developer accounts, that’s you, not wdms.
wdms is happy to produce the required documentation on your behalf, but doing so is optional, not mandatory, on our part.
What documentation is needed?
Every app needs technical documentation explaining how security is handled, how the app was built, and what was done to prevent vulnerabilities in the code. This is required to obtain a CE mark on the app, and to meet the ongoing vulnerability-monitoring obligations that come with it.
wdms offers CRA documentation and release artifacts as a service. Get in touch for pricing details.
Sidestepping the CRA
There are two ways to avoid CRA obligations entirely.
No app store presence in the EU
This is technically possible by excluding all 27 EU member states in App Store and Play Store distribution settings. However, app availability is determined by the account’s registered region, not the user’s physical location. So a user physically outside the EU, but with a Google or Apple account registered to an EU country, would still be unable to install the app. Given how common this is, it makes this the least viable option in practice.
For clients who only wish to target non-EU citizens this may be a valid option. wdms would allow clients to publish app under wdms’ accounts.
A progressive web app (PWA)
A browser-based, offline-capable application with no presence in either app store. This removes the need for an EU representative, technical documentation, and SBOM requirements entirely.
A PWA has a different user experience. Some native features, such as push notifications, may be missing or work differently. It does, however, avoid app store review delays entirely: updates can be pushed instantly, the same as any other website, rather than waiting one to two days for app store approval.