Alessandro Del Ninno
News
EU Commission: operational guidance for businesses on the Cyber Resilience Act published.
INFORMATION TECHNOLOGY
27/07/2026

On 27 July 2026, the European Commission published new guidance on the application of the Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, which introduces mandatory cybersecurity requirements for hardware and software products containing digital components. The non-binding guidance is aimed in particular at micro-enterprises and SMEs and clarifies certain key aspects of the Regulation: scope of application, open-source software, substantial modifications to products, support periods, cybersecurity risk assessment and reporting obligations.

Particular attention is paid to security management throughout the entire product lifecycle. Manufacturers will be required to incorporate the principles of ‘security by design’ and ‘security by default’, document the risks assessed, manage vulnerabilities and provide security updates for a period commensurate with the product’s expected useful life.

The nearest deadline is 11 September 2026. From that date, manufacturers will be required to notify ENISA of actively exploited vulnerabilities and serious incidents affecting product security. The first notification must be submitted within 24 hours of becoming aware of the incident, followed by further updates as required by the Regulation.

Most of the CRA’s obligations, however, will apply from 11 December 2027.

Manufacturers, developers, importers and distributors should:

1. carry out a census of the hardware and software products placed on the European market;

2. assess their role and the applicable obligations within the supply chain;

3. carry out documented cybersecurity risk assessments;

4. define support periods and update management procedures;

5. organise, by 11 September 2026, internal processes for detecting and reporting vulnerabilities and incidents;

6. update contracts with suppliers and developers, setting out arrangements for cooperation, access to information and vulnerability management;

7. check whether any changes, additions or customisations may require a new compliance assessment;

8. coordinate CRA obligations with NIS2, the GDPR, DORA and sector-specific regulations.

The publication of the guidance marks an important operational step: the CRA will not only require products to be secure at the time of placing on the market, but also continuous, documented and verifiable cyber risk management processes.