EU Commission Clarifies CRA Compliance Requirements

New guidance explains how manufacturers should apply the Cyber Resilience Act, while CRA reporting obligations have already applied since 11 September 2026.

At a glance

·       The European Commission has published practical guidance on applying the Cyber Resilience Act (CRA).

·       The guidance covers product scope, substantial modifications, support periods, risk assessments and reporting obligations.

·       CRA reporting obligations apply from 11 September 2026, while the Regulation becomes fully applicable on 11 December 2027.

What does the new CRA guidance clarify?

The European Commission published its practical guidance on the Cyber Resilience Act on 27 July 2026 to help manufacturers, developers and other businesses understand how the Regulation should be applied in practice.

The guidance addresses several areas that are particularly relevant when preparing products with digital elements for the EU market, including:

·       which products and remote data processing solutions fall within the CRA scope;

·       when a product change constitutes a substantial modification;

·       how manufacturers should determine and apply the support period;

·       cybersecurity risk assessment requirements; and

·       vulnerability and incident reporting obligations.

The Commission has also included 67 practical examples, together with use cases, flowcharts and supporting explanations. The guidance is non-binding but provides the Commission’s interpretation of how the CRA should be implemented.

Which CRA obligations already apply?

The first significant manufacturer obligations are already in effect.

Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements.

According to the Commission’s CRA reporting guidance, manufacturers generally need to submit:

·       an early warning within 24 hours of becoming aware of the issue; and

·       a full notification within 72 hours.

Notifications are submitted through the CRA Single Reporting Platform established by ENISA.

These reporting requirements can also apply to products that were placed on the EU market before the CRA becomes fully applicable in December 2027.

When do the main CRA requirements become mandatory?

The Cyber Resilience Act — Regulation (EU) 2024/2847 becomes fully applicable on 11 December 2027.

From that date, manufacturers of products with digital elements will need to meet the CRA’s broader cybersecurity requirements, including secure product design, vulnerability handling, cybersecurity risk assessment, technical documentation and applicable conformity assessment obligations.

Manufacturers will also need to define a support period during which vulnerabilities are handled effectively and provide users with information about that support period.

What should manufacturers do now?

Manufacturers should not treat the CRA as a requirement that starts only in December 2027.

Companies supplying connected hardware or software in the EU should already review:

·       whether their products fall within the CRA scope;

·       how vulnerabilities and security incidents are detected and reported;

·       whether an internal 24-hour / 72-hour reporting process is in place;

·       how cybersecurity risk assessments will be documented;

·       how product support periods will be determined; and

·       whether product development and technical documentation processes need to be updated ahead of December 2027.

The Commission guidance gives manufacturers a more practical basis for making these preparations before the CRA becomes fully applicable.