view all news & events
07/27/2026

European Commission Publishes Guidance on the Cyber Resilience Act

The European Commission has published guidance on the implementation of the Cyber Resilience Act (CRA). The guidance is intended to support companies in the practical application of the regulation and provides clarification on a wide range of interpretative questions.

Among other topics, it addresses the scope of the Cyber Resilience Act, the classification of remote data processing solutions and open source software, substantial modifications to products, the determination of support periods, cybersecurity risk assessments, and the new reporting obligations. In addition, it includes numerous practical examples and decision-making aids, particularly for small and medium-sized enterprises (SMEs). The guidance therefore provides valuable support for the practical implementation of the new regulatory requirements.

The guidance is not legally binding. Nevertheless, it is expected to play a significant role in the interpretation and application of the Cyber Resilience Act in practice and provides companies with important guidance as they prepare for the new regulatory requirements.

The publication comes at an important point in time. As of 11 September 2026, the reporting obligations under the Cyber Resilience Act will apply. The product-specific requirements will apply to products placed on the market from 11 December 2027 onwards. Companies should use the remaining time to align their products, processes, and compliance structures with the new requirements at an early stage.

Further Information:

  • The European Commission's guidance is available here.
  • More information about our CRA Compliance Suite is available here.

    Share

  • LinkedIn
  • XING