The EU explains the Cyber Resilience Act. Companies have a few weeks to prepare

The European Commission has published practical guidelines designed to help companies prepare for the initial obligations under the Cyber Resilience Act.

2 Min Read
Unia europejska

On 27 July, the European Commission published a practical guide to the Cyber Resilience Act, the EU’s legislation on cyber resilience. The document contains 67 examples, diagrams and use cases. Among other things, it explains which products are covered by the regulations, how to treat open-source software and remote data processing services, what constitutes a ‘substantial modification’, and how to determine a product’s support period.

The publication comes just ahead of the first key deadline. From 11 September 2026, manufacturers will be required to report actively exploited vulnerabilities and serious security incidents. Reporting is to take place via ENISA’s common platform. The main obligations, including conformity assessment and CE marking, will come into force on 11 December 2027.

The guidelines are not legally binding, but may serve as a practical reference point for businesses and supervisory authorities. This is particularly important for SMEs, for whom an unclear scope of regulation means a greater risk of costly errors. The Commission is presenting the document as part of a wider effort to simplify digital law, alongside the Digital Omnibus package.

This means that companies will need to quickly clarify responsibilities for product security, risk documentation, vulnerability management and cooperation with suppliers. In the short term, the costs of testing, compliance and software maintenance are likely to rise. In the longer term, however, the CRA may reduce the presence of poorly secured products on the EU market and boost customer confidence. The greatest risk lies with companies that treat the September obligation as a mere formality and start setting up their reporting processes too late.

Guidance is available on the website.

Share This Article