On July 27, 2026, the European Commission published its first formal guidance on the Cyber Resilience Act (CRA), giving manufacturers of products with digital elements the practical interpretation they need before vulnerability and incident reporting duties apply on September 11, 2026. The Communication C(2026) 5252, adopted under Article 26 of Regulation (EU) 2024/2847, replaces the March 2026 draft and settles the questions stakeholders raised most on scope, substantial modification, support periods and reporting. The Commission released the Communication together with its detailed annex, and announced the publication on its digital strategy library page.

Although non-binding, the guidance is the reference text CE conformity and product security teams will be measured against as enforcement approaches. It carries 67 practical examples, use cases, flowcharts and graphs, and is explicit that further guidance may follow as implementation exposes new questions.

Who has to act, and by when?

The CRA binds every manufacturer placing products with digital elements on the EU market, from baby monitors and smartwatches to industrial control software. Two deadlines drive the urgency. Article 14 vulnerability and incident reporting obligations apply from September 11, 2026, roughly six weeks from publication. The core security-by-design, CE marking and lifecycle duties apply from December 11, 2027. The Commission's decision to publish now, rather than closer to the 2027 deadline, is a clear signal to finalise conformity preparations before the September reporting window opens.

DateWhat applies
December 10, 2024CRA (Regulation (EU) 2024/2847) enters into force
July 27, 2026Commission publishes first Article 26 guidance, C(2026) 5252
September 11, 2026Article 14 vulnerability and incident reporting obligations apply
December 11, 2027Main security-by-design, CE marking and lifecycle obligations apply

What the guidance clarifies on scope, FOSS and remote data processing

The annex tackles the four questions the March 2026 draft left most open. On scope, it draws the line for remote data processing solutions and free and open source software, the two categories where manufacturers most often misjudged whether the CRA applied to them at all. On substantial modification, it explains when a post-market change to a product pulls it back into conformity assessment. On support periods, it sets expectations for how long security updates must keep flowing after a device ships. On reporting and risk assessment, it operationalises Article 14 so a security team can build a workable vulnerability-handling process instead of guessing at thresholds.

For product security leads, the practical consequence is that scope decisions taken on the basis of the March draft should now be rechecked against the final text, particularly for any product that relies on a remote data processing component or bundles third-party open source code.

How the guidance treats microenterprises and SMEs

The Commission built the document around smaller companies, with 67 practical examples, use cases, flowcharts and graphs concentrated on microenterprises and SMEs. The intent is proportionality: a microenterprise shipping a connected device should not carry the same administrative load as a large industrial OEM, but it still owes the same essential cybersecurity outcomes. Product security leads at SMEs should treat the examples as a self-assessment route, working through the flowcharts against their own product portfolio before September 11, 2026.

How this fits with the Digital Omnibus and what comes next

The guidance is one piece of a broader simplification push that includes the Digital Omnibus proposal published in November 2025, which adjusts several digital regulations including the CRA. The Commission states plainly that, under Article 26, it will consider issuing further guidance as implementation exposes new questions. Manufacturers should therefore treat this as version one of a living reference, not a closed text, and set up internal tracking for any follow-up Communication.

Continuous, per-jurisdiction real-time monitoring surfaces this kind of guidance the moment it publishes, rather than when a quarterly review catches it.

Take advantage of this real-time watch

EU electrical and electronic equipment: RoHS, RED, EMC and low-voltage conformityLive
Monitor EU product-conformity rules for electrical and electronic equipment for the radio, telecom and electrical equipment industry.
Hourly Email 10+ news
This live monitoring job detected the news you are reading.
Activate this watch free now

What to do next

Verify applicability across your product portfolio, map each product against the scope and substantial-modification flowcharts, confirm your support-period commitments meet the guidance, and brief your vulnerability-handling team before the September 11, 2026 reporting deadline. The CRA's obligations are now fixed in law; the Commission has now told you how it expects you to meet them.