top of page

European Union: Cyber Resilience Act Implementation Guidance

2 days ago
4 min read

European Union: European Commission Publishes Cyber Resilience Act (CRA) Implementation Guidance Ahead of the September 2026 Reporting Deadline


The European Commission has published practical guidance to help manufacturers, software developers, and other economic operators apply the Cyber Resilience Act (CRA), the EU's horizontal cybersecurity regulation for products with digital elements. The publication follows a public consultation held earlier in 2026 and arrives at a critical moment in the CRA's phased rollout, just weeks ahead of the regulation's first binding compliance milestone.


Regulatory Background


The Cyber Resilience Act, Regulation (EU) 2024/2847, entered into force on December 10, 2024. It establishes mandatory cybersecurity requirements covering the design, development, production, and maintenance of hardware and software products placed on the EU market, and requires manufacturers to manage vulnerabilities throughout the product lifecycle. Certain products of particular cybersecurity relevance must undergo third-party conformity assessment by a notified body before they can bear the CE marking and enter the EU market.

Article 26 of the CRA specifically directs the Commission to issue guidance supporting economic operators with particular attention to small and medium-sized enterprises (SMEs) in applying the Regulation consistently across Member States.


An infographic titled "Navigating the Cyber Resilience Act (CRA)" outlining the September 2026 reporting deadline, key Commission implementation guidance areas, and benefits for manufacturers.

Overview of the Cyber Resilience Act Implementation Guidance


The Commission approved the guidance on July 27, 2026, as the annex to Commission Decision C(2026) 5252. The document is non-binding only the Court of Justice of the European Union can issue an authoritative interpretation of the Regulation but it represents the Commission's most substantial interpretive statement on the CRA to date and reflects revisions made in response to stakeholder feedback gathered during the public consultation.

The guidance addresses four of the most contested interpretive questions raised by industry:


  • Scope of the CRA, including the treatment of free and open-source software (FOSS) and the boundaries around remote data processing solutions connected to covered products

  • The meaning of "substantial modification," which determines when a product change resets a manufacturer's compliance obligations

  • Support periods, covering how long manufacturers must provide security updates and how that period should be calculated and disclosed

  • Interplay with other EU legislation, clarifying how the CRA interacts with adjacent frameworks such as the NIS2 Directive


Certification Impact Summary


Area of Impact

What Changes for Certification

Practical Effect

Conformity assessment scope

Clearer criteria for determining whether a product with digital elements falls within CRA scope

Fewer ambiguous "in scope / out of scope" determinations for manufacturers and notified bodies

Open-source components

Defined treatment of FOSS integrated into commercial products

Reduces uncertainty on when open-source use triggers manufacturer obligations

Substantial modification

Testable criteria for what constitutes a modification requiring re-assessment

Helps manufacturers decide when a product update or patch requires renewed conformity assessment

Support period documentation

Guidance on calculating and disclosing support periods

Informs technical documentation and CE marking declarations going forward

Notified body coordination

No change to notified body designation process itself

Member States continue designating notifying authorities in parallel with this guidance


What This Means for Manufacturers


For manufacturers, developers, and importers placing connected hardware or software on the EU market, the guidance does not change any legal obligation or compliance date but it materially reduces the ambiguity that has stalled internal CRA compliance projects. Companies that were uncertain whether a product qualifies as "in scope," whether an update counts as a "substantial modification," or how to calculate a support period now have an official reference point to apply consistently across their EU product lines.

Practically, this means:


  • Compliance and product security teams should revisit CRA scoping assessments using the Commission's clarified criteria, particularly for products incorporating open-source components

  • Documentation practices around support periods should be reviewed and updated to reflect the Commission's expected disclosure approach

  • Change-management and patch-release processes should be evaluated against the "substantial modification" criteria to determine when renewed conformity assessment is triggered

  • SMEs, who were a specific focus of the guidance, should treat this as a starting point for building or refining a CRA compliance program, rather than waiting for further clarification


The guidance is explicitly framed as part of the Commission's broader simplification agenda, and the Commission has indicated further Article 26 guidance may follow as additional interpretive questions arise meaning this is likely the first of several such publications rather than a final word on open questions.


Timeline and Required Actions


Date

Milestone

Required Action for Manufacturers

December 10, 2024

CRA enters into force

Begin building CRA compliance roadmap

June 11, 2026

Notified body notification provisions take effect

Confirm conformity assessment pathway and notified body availability for in-scope products

July 27, 2026

Commission publishes CRA Implementation Guidance

Review guidance; update scoping, documentation, and change-management processes

September 11, 2026

Reporting obligations become mandatory

Establish processes to report actively exploited vulnerabilities and severe incidents to CSIRTs and ENISA

December 11, 2026

Deadline for Member States to notify sufficient conformity assessment bodies

Monitor notified body capacity in relevant Member States

December 11, 2027

Full application of the CRA

Complete conformity assessment, technical documentation, CE marking, and full lifecycle vulnerability management for all in-scope products


Conclusion


With the CRA's first hard compliance deadline now imminent, the Commission's Implementation Guidance gives manufacturers, developers, and importers a clearer, more testable framework for interpreting scope, modification, and support-period obligations. While non-binding, it is expected to shape how national market surveillance authorities and notified bodies approach enforcement in practice. Companies with products with digital elements destined for the EU market should treat this guidance as a working reference for their compliance programs ahead of the September 2026 reporting deadline and the full application date in December 2027.

bottom of page