Last week the European Commission has published a practical guidance to help manufacturers, developers, and businesses of all sizes meet their obligations under the Cyber Resilience Act – timely news for everyone in our community preparing for compliance.
The guidance clarifies some of the questions manufacturers ask us most often, including:
- When products fall in scope – including remote data processing solutions and free and open source software
- What counts as a “substantial modification”
- How to interpret support periods
- Reporting obligations and risk assessment requirements
Good news for SMEs in particular: the guidance includes 67 practical examples, use cases, flowcharts, and graphs to make the path to compliance clearer and more proportionate.
Good to keep in mind:
- Reporting obligations already apply from 11 September 2026
- Main CRA obligations apply from 11 December 2027
This is exactly the kind of regulatory clarity CRACoWi is built to help manufacturers translate into action.
Read more and download the guidance here: Commission publishes new guidance to support timely Cyber Resilience Act implementation




