10 August 2026
Share Print

EU Cyber Resilience Act – European Commission finalises guidance

To The Point
(5 min read)

The EU Cyber Resilience Act (CRA) imposes cybersecurity requirements on manufacturers, importers and distributors of connected devices, meaning products with digital elements and data connection to a device or network. The European Commission has recently published its finalised CRA guidance, which is intended to clarify issues relating to the CRA’s scope and obligations. Read our overview of the key points, plus practical steps that in-scope organisations should take to prepare for the CRA.

The EU Cyber Resilience Act (CRA) imposes cybersecurity requirements on manufacturers, importers and distributors of connected devices, meaning products with digital elements and data connection to a device or network. The CRA obligations to report vulnerabilities and incidents become applicable on 11 September 2026 and the remainder of its provisions become applicable on 11 December 2027.

The European Commission has recently published its finalised CRA guidance (the Guidance), which is intended to clarify issues relating to the CRA’s scope and obligations. This follows the draft guidance published earlier this year - see our article EU Cyber Resilience Act – European Commission publishes draft guidance to clarify key obligations for an overview. The Guidance expands on the following areas: 

Software
Remote data processing solutions
Substantial modifications
Support periods
Reporting obligations
Reporting upstream
Cybersecurity risk assessment requirements
Vulnerability handling
What do in-scope organisations need to do?

Next steps

Over the coming months we will publish a series of further CRA materials to help organisations prepare. These will include a closer look at the reporting obligations that apply from 11 September 2026, a short practical guide to what businesses need to know, and – as the December 2027 deadline approaches – guidance on selecting the appropriate conformity assessment route and planning a compliance programme. If you would like to discuss how the CRA applies to your products, please get in touch with a member of our Data Team. 

To the Point


Subscribe to receive legal insights and industry updates directly into your inbox

Sign up now