New Commission guidance on CRA implementation

3 Aug, 2026
CRA guidanance new issue by EU

Last week the European Commission has published a practical guidance to help manufacturers, developers, and businesses of all sizes meet their obligations under the Cyber Resilience Act – timely news for everyone in our community preparing for compliance.

The guidance clarifies some of the questions manufacturers ask us most often, including:

  • When products fall in scope – including remote data processing solutions and free and open source software
  • What counts as a “substantial modification”
  • How to interpret support periods
  • Reporting obligations and risk assessment requirements

Good news for SMEs in particular: the guidance includes 67 practical examples, use cases, flowcharts, and graphs to make the path to compliance clearer and more proportionate.

Good to keep in mind:

  • Reporting obligations already apply from 11 September 2026
  • Main CRA obligations apply from 11 December 2027

This is exactly the kind of regulatory clarity CRACoWi is built to help manufacturers translate into action.

Read more and download the guidance here: Commission publishes new guidance to support timely Cyber Resilience Act implementation

You may also like

Event: Building Cyber Resilience in the Digital EraΒ Β Β 

Event: Building Cyber Resilience in the Digital Era

A joint workshop on NIS2 compliance, CRA enforcement, and cross-border cybersecurity incident response. πŸ“… Friday, 2 October 2026 πŸ•˜ 09:00 – 16:00 πŸ“ Electra Palace Athens - 18-20 N. Nikodimou str, 10557 Athens, Greece 🌐 Language: EnglishThe EU cybersecurity regulatory...