On July 27, 2026, the European Commission published practical guidance to help manufacturers, developers, and businesses of all sizes meet their obligations under the Cyber Resilience Act (“CRA”). The Cyber Resilience Act, which builds on the 2020 EU Cybersecurity Strategy and EU Security Union Strategy, entered into force on December 10, 2024, with reporting obligations to apply as of September 11, 2026. It was issued to safeguard consumers and businesses by addressing the inadequate level of cybersecurity in digital products and the lack of timely security updates. The CRA imposes mandatory cybersecurity requirements for manufacturers that cover the planning, design, development, and maintenance of products with digital elements, with obligations that must be met at every stage of the value chain. National market surveillance authorities will be responsible for the enforcement of the rules, and CE markings will eventually be applied to products that comply with the CRA.
The new guidance addresses the most frequently asked questions from stakeholders, including clarification on what products fall within the scope of the CRA, what constitutes a “substantial modification,” how support periods should be applied, and how to meet reporting obligations and risk assessment requirements. The Commission also pays particular attention to microenterprises and SMEs, and provides the public with practical examples, a range of use cases, flowcharts, and graphs to ensure that compliance with the CRA is clear and proportionate. While the guidance is non-binding, it is intended to help companies prepare now for the CRA’s main obligations that take effect on December 11, 2027.
European Commission Policy and Legislation Notice | European Commission – Introduction to the CRA