In brief: The CRA guidance clarifies open questions on scope of application, material product changes, support periods, and reporting obligations ahead of the September 2026 deadline.
The EU Commission has published a guidance document with 67 practical examples on the Cyber Resilience Act to help manufacturers and developers implement the regulation ahead of the first compliance deadlines.
The Cyber Resilience Act (CRA) has been in effect since December 2024 and requires providers of connected products – from baby monitors and smartwatches to apps and conventional software – to comply with mandatory cybersecurity requirements throughout the entire product lifecycle. The EU Commission has now published guidance that addresses specific uncertainties in practice that have been raised by companies and associations since the regulation came into force.
The guidance addresses central questions on the interpretation of the CRA: when products fall within its scope of application (such as in the case of remote data processing or open-source software), what constitutes a “material change” to a product, which support periods are required, and how reporting and risk assessment obligations must be fulfilled in practice. With 67 practical examples, use cases, flowcharts and graphics, the document is particularly aimed at micro-enterprises and SMEs to ensure proportionate implementation and avoid unnecessary administrative burden.
The first central deadline of the CRA is 11 September 2026: from this date, manufacturers must fulfil reporting obligations, for example in the event of actively exploited vulnerabilities or serious security incidents. The main obligations of the regulation – conformity assessment and CE marking – become effective from 11 December 2027. The guidance itself is not legally binding but is intended to provide guidance ahead of these deadlines.
The Commission emphasises that the guidance is part of its broader simplification strategy, which also includes the Digital Omnibus Package (November 2025), which aims to reduce duplicate regulation in the EU digital landscape (DSA, GDPR, AI Act, CRA). The guidance was developed in collaboration with the expert group on cybersecurity of products with digital elements and on the basis of a public consultation in early 2026. The Commission signals its willingness to provide further guidance under Article 26 of the CRA if needed.
Source: www.it-daily.net · Published 29 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.