|

New CRA Guidance Aims to Help Companies Prepare for September 2026

The Commission Steps In With Practical Support

On 27 July 2026, the European Commission published new, non-binding guidance to help manufacturers, developers, and businesses of all sizes understand their obligations under the Cyber Resilience Act (CRA). The timing is significant. With the first reporting duties starting on 11 September 2026, many companies have been asking the same questions: does this apply to us, and what exactly do we need to do? This new guidance is a direct response to that uncertainty.

Cyber Resilience Act Guidance: What It Actually Covers

The guidance does not create new rules. Instead, it explains how the existing rules should be applied in real situations. According to the Commission, the document addresses the questions stakeholders have raised most often, including:

  • When a product falls within CRA scope, including remote data processing solutions and free and open source software (FOSS)
  • What counts as a “substantial modification” to a product
  • How support periods should be understood and applied
  • How to meet reporting obligations and risk assessment requirements

These are exactly the areas where companies have struggled to interpret the law on their own. Clarifying them now, weeks before the reporting deadline, gives businesses a real chance to close gaps before enforcement begins.

Extra Support for Smaller Businesses

One notable feature of this guidance is its focus on microenterprises and small and medium-sized enterprises (SMEs). These companies often lack dedicated legal or compliance teams, making complex regulation harder to interpret. To address this, the Commission included 67 practical examples, along with flowcharts and diagrams, to make the path to compliance clearer without adding unnecessary administrative burden.

Why This Matters for Smaller Manufacturers

Smaller manufacturers are just as exposed to the reporting obligation as large corporations, but they typically have fewer resources to build compliance processes from scratch. Practical examples and visual tools can shorten the learning curve significantly, helping smaller teams understand what applies to them without hiring outside experts for every question.

Part of a Larger Simplification Effort

This guidance is not a standalone release. It fits into the Commission’s broader simplification agenda, which also includes the Digital Omnibus package published in November 2025. The overall message from the Commission is consistent: implementation should be timely, but it should also be manageable, especially for businesses with limited compliance resources.

The Deadlines Have Not Changed

Importantly, this guidance does not delay or soften the CRA’s core timeline. The Commission confirmed that the Act’s main obligations still apply from 11 December 2027, while reporting obligations remain set for 11 September 2026. The guidance is meant to help companies meet these dates with more confidence, not to push them back.

What Companies Should Do With This Guidance

Because the guidance is non-binding, companies are not legally required to follow it word for word. However, it reflects the Commission’s official interpretation of the rules, based on extensive stakeholder consultation, including input from the expert group on cybersecurity of products with digital elements and a public consultation earlier in 2026. Ignoring it could mean missing practical clarifications that make compliance easier.

The Commission has also stated it will consider issuing further guidance as needed, under Article 26 of the CRA. This suggests companies should treat this document as a starting point, not a final answer, and stay alert for future updates as the September deadline approaches.


Key Takeaways

  • Download and review the guidance now. Assign someone on your compliance or legal team to read the official annex, especially the sections on scope and reporting obligations, before the 11 September deadline.
  • Check if your product is in scope. Pay close attention to the clarified rules on remote data processing and open source software — these areas have caused the most confusion.
  • Use the SME examples if you’re a smaller company. The 67 practical examples are designed to reduce guesswork, so don’t skip them in favor of guessing your obligations.
  • Don’t expect deadline relief. This guidance supports compliance; it does not change the 11 September 2026 reporting deadline or the 11 December 2027 main obligations.
  • Watch for future updates. Since the Commission may issue more guidance under Article 26, build a habit of checking official channels rather than relying only on this one document.

Source of Article

European Commission, Commission publishes new guidance to support timely Cyber Resilience Act implementation, Shaping Europe’s Digital Future, 27 July 2026. https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation

Other posts you may find interesting...