European Union: Cyber Resilience Act Implementation Guidance
European Union: European Commission Publishes Cyber Resilience Act (CRA) Implementation Guidance Ahead of the September 2026 Reporting Deadline
The European Commission has published practical guidance to help manufacturers, software developers, and other economic operators apply the Cyber Resilience Act (CRA), the EU's horizontal cybersecurity regulation for products with digital elements. The publication follows a public consultation held earlier in 2026 and arrives at a critical moment in the CRA's phased rollout, just weeks ahead of the regulation's first binding compliance milestone.
Regulatory Background
The Cyber Resilience Act, Regulation (EU) 2024/2847, entered into force on December 10, 2024. It establishes mandatory cybersecurity requirements covering the design, development, production, and maintenance of hardware and software products placed on the EU market, and requires manufacturers to manage vulnerabilities throughout the product lifecycle. Certain products of particular cybersecurity relevance must undergo third-party conformity assessment by a notified body before they can bear the CE marking and enter the EU market.
Article 26 of the CRA specifically directs the Commission to issue guidance supporting economic operators with particular attention to small and medium-sized enterprises (SMEs) in applying the Regulation consistently across Member States.

Overview of the Cyber Resilience Act Implementation Guidance
The Commission approved the guidance on July 27, 2026, as the annex to Commission Decision C(2026) 5252. The document is non-binding only the Court of Justice of the European Union can issue an authoritative interpretation of the Regulation but it represents the Commission's most substantial interpretive statement on the CRA to date and reflects revisions made in response to stakeholder feedback gathered during the public consultation.
The guidance addresses four of the most contested interpretive questions raised by industry:
Scope of the CRA, including the treatment of free and open-source software (FOSS) and the boundaries around remote data processing solutions connected to covered products
The meaning of "substantial modification," which determines when a product change resets a manufacturer's compliance obligations
Support periods, covering how long manufacturers must provide security updates and how that period should be calculated and disclosed
Interplay with other EU legislation, clarifying how the CRA interacts with adjacent frameworks such as the NIS2 Directive
Certification Impact Summary
Area of Impact | What Changes for Certification | Practical Effect |
Conformity assessment scope | Clearer criteria for determining whether a product with digital elements falls within CRA scope | Fewer ambiguous "in scope / out of scope" determinations for manufacturers and notified bodies |
Open-source components | Defined treatment of FOSS integrated into commercial products | Reduces uncertainty on when open-source use triggers manufacturer obligations |
Substantial modification | Testable criteria for what constitutes a modification requiring re-assessment | Helps manufacturers decide when a product update or patch requires renewed conformity assessment |
Support period documentation | Guidance on calculating and disclosing support periods | Informs technical documentation and CE marking declarations going forward |
Notified body coordination | No change to notified body designation process itself | Member States continue designating notifying authorities in parallel with this guidance |
What This Means for Manufacturers
For manufacturers, developers, and importers placing connected hardware or software on the EU market, the guidance does not change any legal obligation or compliance date but it materially reduces the ambiguity that has stalled internal CRA compliance projects. Companies that were uncertain whether a product qualifies as "in scope," whether an update counts as a "substantial modification," or how to calculate a support period now have an official reference point to apply consistently across their EU product lines.
Practically, this means:
Compliance and product security teams should revisit CRA scoping assessments using the Commission's clarified criteria, particularly for products incorporating open-source components
Documentation practices around support periods should be reviewed and updated to reflect the Commission's expected disclosure approach
Change-management and patch-release processes should be evaluated against the "substantial modification" criteria to determine when renewed conformity assessment is triggered
SMEs, who were a specific focus of the guidance, should treat this as a starting point for building or refining a CRA compliance program, rather than waiting for further clarification
The guidance is explicitly framed as part of the Commission's broader simplification agenda, and the Commission has indicated further Article 26 guidance may follow as additional interpretive questions arise meaning this is likely the first of several such publications rather than a final word on open questions.
Timeline and Required Actions
Date | Milestone | Required Action for Manufacturers |
December 10, 2024 | CRA enters into force | Begin building CRA compliance roadmap |
June 11, 2026 | Notified body notification provisions take effect | Confirm conformity assessment pathway and notified body availability for in-scope products |
July 27, 2026 | Commission publishes CRA Implementation Guidance | Review guidance; update scoping, documentation, and change-management processes |
September 11, 2026 | Reporting obligations become mandatory | Establish processes to report actively exploited vulnerabilities and severe incidents to CSIRTs and ENISA |
December 11, 2026 | Deadline for Member States to notify sufficient conformity assessment bodies | Monitor notified body capacity in relevant Member States |
December 11, 2027 | Full application of the CRA | Complete conformity assessment, technical documentation, CE marking, and full lifecycle vulnerability management for all in-scope products |
Conclusion
With the CRA's first hard compliance deadline now imminent, the Commission's Implementation Guidance gives manufacturers, developers, and importers a clearer, more testable framework for interpreting scope, modification, and support-period obligations. While non-binding, it is expected to shape how national market surveillance authorities and notified bodies approach enforcement in practice. Companies with products with digital elements destined for the EU market should treat this guidance as a working reference for their compliance programs ahead of the September 2026 reporting deadline and the full application date in December 2027.

