On July 27, 2026, the European Commission published its first formal guidance on the Cyber Resilience Act (CRA), giving manufacturers of products with digital elements the practical interpretation they need before vulnerability and incident reporting duties apply on September 11, 2026. The Communication C(2026) 5252, adopted under Article 26 of Regulation (EU) 2024/2847, replaces the March 2026 draft and settles the questions stakeholders raised most on scope, substantial modification, support periods and reporting. The Commission released the Communication together with its detailed annex, and announced the publication on its digital strategy library page.
Although non-binding, the guidance is the reference text CE conformity and product security teams will be measured against as enforcement approaches. It carries 67 practical examples, use cases, flowcharts and graphs, and is explicit that further guidance may follow as implementation exposes new questions.
Who has to act, and by when?
The CRA binds every manufacturer placing products with digital elements on the EU market, from baby monitors and smartwatches to industrial control software. Two deadlines drive the urgency. Article 14 vulnerability and incident reporting obligations apply from September 11, 2026, roughly six weeks from publication. The core security-by-design, CE marking and lifecycle duties apply from December 11, 2027. The Commission's decision to publish now, rather than closer to the 2027 deadline, is a clear signal to finalise conformity preparations before the September reporting window opens.
| Date | What applies |
|---|---|
| December 10, 2024 | CRA (Regulation (EU) 2024/2847) enters into force |
| July 27, 2026 | Commission publishes first Article 26 guidance, C(2026) 5252 |
| September 11, 2026 | Article 14 vulnerability and incident reporting obligations apply |
| December 11, 2027 | Main security-by-design, CE marking and lifecycle obligations apply |
What the guidance clarifies on scope, FOSS and remote data processing
The annex tackles the four questions the March 2026 draft left most open. On scope, it draws the line for remote data processing solutions and free and open source software, the two categories where manufacturers most often misjudged whether the CRA applied to them at all. On substantial modification, it explains when a post-market change to a product pulls it back into conformity assessment. On support periods, it sets expectations for how long security updates must keep flowing after a device ships. On reporting and risk assessment, it operationalises Article 14 so a security team can build a workable vulnerability-handling process instead of guessing at thresholds.
For product security leads, the practical consequence is that scope decisions taken on the basis of the March draft should now be rechecked against the final text, particularly for any product that relies on a remote data processing component or bundles third-party open source code.
How the guidance treats microenterprises and SMEs
The Commission built the document around smaller companies, with 67 practical examples, use cases, flowcharts and graphs concentrated on microenterprises and SMEs. The intent is proportionality: a microenterprise shipping a connected device should not carry the same administrative load as a large industrial OEM, but it still owes the same essential cybersecurity outcomes. Product security leads at SMEs should treat the examples as a self-assessment route, working through the flowcharts against their own product portfolio before September 11, 2026.
How this fits with the Digital Omnibus and what comes next
The guidance is one piece of a broader simplification push that includes the Digital Omnibus proposal published in November 2025, which adjusts several digital regulations including the CRA. The Commission states plainly that, under Article 26, it will consider issuing further guidance as implementation exposes new questions. Manufacturers should therefore treat this as version one of a living reference, not a closed text, and set up internal tracking for any follow-up Communication.
Continuous, per-jurisdiction real-time monitoring surfaces this kind of guidance the moment it publishes, rather than when a quarterly review catches it.
Take advantage of this real-time watch
What to do next
Verify applicability across your product portfolio, map each product against the scope and substantial-modification flowcharts, confirm your support-period commitments meet the guidance, and brief your vulnerability-handling team before the September 11, 2026 reporting deadline. The CRA's obligations are now fixed in law; the Commission has now told you how it expects you to meet them.


