A web page hears the keyboard only while its tab has focus. A Windows program can claim a shortcut for the whole system with one call, RegisterHotKey, and answer it while somebody works in another window. Whether Windows desktop app development is worth its extra cost comes down to gaps like that one.
When is a Windows desktop app better than a web app?
A Windows desktop app is the better choice when the job needs a hotkey that works over any window, direct access to the PC's screen, files and devices, dependable offline work, or heavy processing of big local files. A web app reaches the screen and files only through prompts, and a device driver not at all.
The browser is strictest about the screen, files and devices. It must ask the user's permission to capture the screen every time, the API that lets a web app open a file and save it back in place has limited availability across browsers, and a scanner or label printer whose maker supplies only a Windows driver is out of a web page's reach. Offline work and big files explain themselves: a warehouse PC with no signal, hours of video, a year of machine logs.
SnapQio, a screenshot and screen-recording program we made for Windows, needs the first three. You press a hotkey over whatever is on screen, drag across the part you want, then annotate it, blur anything private, copy text out with OCR, stitch a long page into one image or record the area as 60 FPS video. It runs offline. There is nothing to sign in to.
Hotkeys are first come, first served. RegisterHotKey fails if another program already holds the combination, so the settings screen needs a way to pick another.
When none of the four applies, a web app is cheaper to own: one copy on a server, updated for everyone at once, with no installer to sign. A progressive web app installs from the browser, works offline and can be listed in the Microsoft Store, and for an internal form-and-database tool I would start there. Whether to build at all is worked through in custom software or off-the-shelf; if the users are on their phones, start with what a mobile app costs.
WinUI 3, WPF, Electron, Tauri or Qt?
For a program that runs only on Windows, I would pick C# on .NET 10 with WinUI 3, Microsoft's recommended framework for new native apps; for Windows and Mac from one codebase, Tauri or Electron; and Qt when embedded devices come into it. They differ in size, licence cost, how Windows-like they look and who can maintain them.
.NET first. Microsoft's guidance is to start new native apps on WinUI 3, and it says an existing WPF or Windows Forms app does not need a rewrite. I still choose WPF for dense data-entry screens, where most of the problems you will meet were solved years ago. Pick the runtime by its dates: .NET 10 is supported until 14 November 2028, while .NET 8 and .NET 9 lose support on 10 November 2026. A quote proposing .NET 8 this month buys two months of security patches.
Electron and Tauri draw the interface with web technology, which suits a team that already builds in React or Vue. Electron puts its own Chromium and Node.js inside every app, and its documentation admits that most Electron apps are over 100 MB. Tauri borrows the webview already on the machine, WebView2 on Windows 11, so a minimal app can be under 600 KB. Its back end is Rust. In Stack Overflow's 2025 survey, 14.5% of professional developers had done extensive work in Rust over the past year, against 29.9% in C#: that is the pool you hire from when the original developer moves on. I would take Tauri for a small tool and Electron when the app leans on Node libraries. Neither looks like Windows unless your designer makes it; WinUI 3 starts with the design language of Windows' own built-in apps.
Qt is a C++ framework for Windows, macOS, Linux and embedded devices, licensed under the LGPL or commercially. The commercial licence for application development costs €546 ($618) per developer a year at small-business rates, which apply to companies with annual revenue or funding of up to €1 million, at most three licences each. I reach for it when the code must also run on embedded hardware.
Do you need an ARM64 build?
You need an ARM64 build if the program will run on Arm laptops, such as Copilot+ PCs with Snapdragon X chips. Windows 11 emulates x64 programs there, but Microsoft's Arm documentation says users need Arm-native apps for the best performance and battery life. Drivers are the exception: they work only if designed for an Arm-based PC.
So a program that talks to a scanner waits on the scanner's maker. SnapQio ships both builds. For any program that does, every release means two builds to test and, for a public download, two files to sign. In the Microsoft Store the choice disappears: Windows 11 installs the Arm64 package automatically when you have submitted one.
Why does Windows say “Windows protected your PC”?
“Windows protected your PC” is Microsoft Defender SmartScreen reacting to a file it has no reputation for. On an unsigned installer the user must click through to “Run anyway”, and company policy can remove that button. On a signed one the warning still appears while the file is new, but it names you as the verified publisher.
SmartScreen weighs two reputations, the publisher's certificate and that exact file, and a first installer from a new company has neither, which is why a correctly signed program from a business nobody has heard of still meets the warning. Reputation passes to the next version only under the same publisher identity, so every public release I sign goes out under one identity: the client's company. Windows 11 adds Smart App Control, which, where it is switched on, blocks unsigned files without positive reputation whether they were downloaded or not.
For SmartScreen, skip EV. Microsoft now says "EV certificates no longer bypass SmartScreen", and at DigiCert that premium is $972 a year against $696 for standard OV (about €834 and €597).
Since 1 June 2023 the CA/Browser Forum's requirements have kept the private key in hardware: a USB token, a smart card or a cloud signing service. Certificates issued since 1 March 2026 last at most 460 days (Ballot CSC-31), so a multi-year purchase means a new certificate at least every fifteen months.
For a company in the EU, the UK or the US, I would rent Microsoft's Artifact Signing, formerly Trusted Signing: from $9.99 a month (about €8.60) it is the cheapest certificate route in the table below, it has no token to lose, and it signs from an automated build. Organisations in the EU, the UK, the US, Canada and eight other countries qualify. Individual developers qualify only in the US or Canada, so one based anywhere else buys from a certificate authority instead. Identity validation takes 1 to 20 business days, and the service needs a paid Azure subscription (FAQ).
| Route | List price, 10 September 2026 | Where the signing key lives |
|---|---|---|
| Artifact Signing, Basic | $9.99 a month (about €8.60), 5,000 signatures a month | Microsoft's cloud |
| Certum Standard Code Signing | from €169 with a smart card, from €209 in the cloud | Card, or Certum's cloud |
| SSL.com OV | $129 a year (about €111), plus $379 (about €325) for a YubiKey | YubiKey, or SSL.com's eSigner cloud at extra cost |
| DigiCert OV | $696 a year (about €597) | DigiCert's KeyLocker cloud, included in the price |
| Microsoft Store, MSIX package | No registration fee; 15% of sales through Microsoft's checkout, 0% through your own | Microsoft signs the package |
Microsoft does not publish a fixed reputation threshold. Its SmartScreen guidance says reputation can take several weeks and hundreds of clean installs to build. Include this uncertainty in the release plan and explain relevant warnings on the download page.
Installer, Microsoft Store or winget
I would ship a public Windows program three ways at once: a signed installer on its own website, a Microsoft Store listing, and a winget manifest for people who install by typing a command. The website gives you the page and the price; the Store installs an MSIX package without a SmartScreen warning, because Microsoft signs it.
MSIX packages can update themselves, but MSIX does not support Windows drivers, so a program that installs one needs a classic MSI or EXE installer.
Microsoft has waived the Store's registration fees, $99 for a company and $19 for an individual. It takes 15% of sales through its own checkout and nothing from non-game apps that use their own, and it certifies an MSI or EXE in up to three business days. That installer must meet Store policy 10.2.9: signed with a certificate from an authority in Microsoft's Trusted Root Program, served from a versioned HTTPS address whose file never changes, a full installer rather than a downloader, and installing silently, with no installer screens. It keeps your signature; Microsoft's own is for MSIX packages.
A winget listing is a YAML manifest for each version, sent as a pull request to the winget-pkgs repository following Microsoft's guide, and any GitHub user can submit one. The installer itself still downloads from your website, or wherever the manifest points.
Internal software is easier. IT installs it from a trusted intranet location, and Microsoft says files from those locations are not subject to SmartScreen review.
How does a Windows app update itself?
A Windows app updates itself in one of three ways: the Microsoft Store delivers a new MSIX package, an MSIX package checks an App Installer file on your server, or a library inside the app downloads a signed installer and runs it. Windows checks the signature on the first two; on the third, the app has to.
An MSI or EXE listed in the Store belongs to the third group: the Store gives new customers the latest version but does not update existing installs.
App Installer checks at launch, at most once a day by default, or every 8 hours in the background whether the app was opened or not; the second setting suits a tray tool nobody restarts. Installers outside MSIX use a library such as Velopack or the framework's own updater. Tauri's updater requires a signature that “cannot be disabled”, and if you lose its private key, existing installs can no longer receive updates.
That key is the client's. It belongs with the code signing account, on the handover list that who owns the code sets out. And since every release starts with no file reputation, in the first months I batch small fixes into one release every few weeks.
What does Windows desktop app development cost?
In US dollars, published estimates put a simple Windows desktop app at $20,000 to $50,000 (about €17,000 to €43,000) and a complex one from $50,000 to well past $200,000 (€43,000 to €172,000 and up). Code signing adds about $120 to $700 a year (€100 to €600), and upkeep 15 to 25% of the build cost every year.
The build and upkeep figures come from cost guides published by companies that sell app development: one supplies the build ranges, two others put a simple app at about $40,000 (about €34,000), and three put upkeep at 15 to 20%, 25% and 15 to 25% a year. I read them on 10 September 2026 and converted at the ECB reference rate for 9 September.
I check such ranges in developer days. A focused utility with a tray icon, a hotkey, one main window, settings, an installer and an updater, in x64 and ARM64, is about 60 developer days. At the UK contract median of £550 a day for a C# developer (IT Jobs Watch, six months to 10 September 2026), that is £33,000, about €38,400. Developers in a 2026 survey of more than 5,000 IT freelancers in Germany, Austria and Switzerland reported €91 an hour, which over 60 eight-hour days is about €43,700. Both sit at the top of the published range for a simple app, the German figure slightly past it. A business program with a local database, server sync, user roles, reports and one connected device is nearer 150 to 250 days, or £82,500 to £137,500 at the UK rate (about €96,000 to €160,000).
How we scope and quote a build like this is on the software development page.
Two checks need no finished code: the identity check for signing, and the Store's verification of a company account, which goes to a manual review of 2 to 5 business days when it cannot clear automatically. Both start in week one.
Will a Windows app run on a Mac?
Only if it was built for both. WinUI 3 and WPF are Windows-only; Tauri, Electron and Qt build for macOS from the same code, which is the main reason to pick one when a Mac version is likely within two years.
Does it still need to run on Windows 10?
Microsoft ended support for Windows 10 Home and Pro on 14 October 2025, with 22H2 as the last version (Microsoft Lifecycle). In August 2026, 27.15% of the page views StatCounter recorded from Windows desktops in Europe still came from Windows 10 (StatCounter). If your office PCs are among them, I would support 22H2 and drop it with the program's next major version.
Whose name goes on the code signing certificate?
Your company's. A public code signing certificate carries the organisation's validated legal name (Artifact Signing FAQ), so the signing account belongs in your name from the start, with the developer given rights to sign. Changing the signing identity later affects the publisher reputation SmartScreen has built.