The EU Cyber Resilience Act (CRA) imposes cybersecurity requirements on manufacturers, importers and distributors of connected devices, meaning products with digital elements and data connection to a device or network. The CRA obligations to report vulnerabilities and incidents become applicable on 11 September 2026 and the remainder of its provisions become applicable on 11 December 2027.
The European Commission has recently published its finalised CRA guidance (the Guidance), which is intended to clarify issues relating to the CRA’s scope and obligations. This follows the draft guidance published earlier this year - see our article EU Cyber Resilience Act – European Commission publishes draft guidance to clarify key obligations for an overview. The Guidance expands on the following areas:
Software
The CRA applies to products with digital elements. The Guidance seeks to clarify when software falls within this definition, highlighting that the CRA applies to software products with digital elements provided to a user, obtained by that user and operated on, or as part of, an electronic information system on the user’s side. By contrast, software that executes remotely and is merely accessed by the user is not a product with digital elements. For example, an app that a user downloads and installs on their phone is a product with digital elements, while a web application that the user accesses exclusively through a web browser is not, unless it supports the functionality of a product with digital elements. The Guidance adds that software packaged for local installation – including browser extensions and web-technology apps supplied to run on the user’s device – is in scope, while progressive web apps and ordinary websites are not, unless they support a product’s functionality.
Remote data processing solutions
The CRA defines a product with digital elements as “a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately”. The Guidance helps manufacturers determine whether their product comprises a remote data processing solution, breaking the definition into three elements:
- data processing “at a distance”;
- the absence of such data processing that would prevent the product with digital elements from performing one of its functions; and
- designing and developing by the manufacturer, or under its responsibility.
Substantial modifications
The CRA concept of “substantial modification” is key, because a substantially modified product is treated as a new product, triggering obligations for manufacturers, importers and distributors. The Guidance provides additional clarification on what constitutes a substantial modification, including:
- Spare parts - The CRA establishes that spare parts intended to replace identical components and manufactured according to the same specifications as those components are not subject to the CRA. The Guidance clarifies that this exemption should be understood as applying only where the spare part is specifically supplied to repair or extend the durability of a product with digital elements already placed on the market. Where a spare part is not identical to the original component, that spare part constitutes a product with digital elements in its own right and is therefore subject to the CRA. The Guidance provides some clarification on when a spare part is or is not identical.
- Software updates – While software updates that do not modify a product’s intended purpose or introduce new security risks will not usually be considered substantial modifications, one paragraph of the Guidance has been amended to explain that a security update may qualify as a substantial modification where, notwithstanding its security objective, the update results in the product’s intended purpose being modified beyond what was originally foreseen or introduces new or increased cybersecurity risks not foreseen in the original risk assessment. This may be the case, for example, where an update materially changes that product’s boundaries or dependency structure in a way not foreseen in the risk assessment, e.g. by materially altering data flows, or adding new externally reachable interfaces.
- Modifications carried out by actors other than the original manufacturer – The CRA provides that where substantial modifications are carried out by an importer, distributor or another person, they may be considered to be a manufacturer. The Guidance has some additional sections to explain when these provisions apply, and how the position is different from when substantial modifications are carried out by the original manufacturer. Where the modification does not affect the cybersecurity of the whole product, the modifier’s obligations – and the conformity assessment – extend only to the modified part, and the original manufacturer’s obligations continue for the rest.
- Integration vs modification – a person who assembles components into a new product that they place on the market under their own name is the manufacturer of that whole product, not someone modifying an existing one, even where the components were bought in or adapted.
Support periods
The CRA requires manufacturers of in-scope products to determine the support period during which they will handle the product’s vulnerabilities, including identifying, documenting and remediating them. The Guidance:
- Provides additional clarification on the criteria that the manufacturer should use to determine the support period.
- Contains a new section to clarify the impact of substantial modifications on the support period - they do not automatically result in a reset or extension, but do require a reassessment against the criteria used to determine the original support period.
Reporting obligations
The CRA requires manufacturers to notify simultaneously to the CSIRT (a member state’s Computer Security Incident Response Team) designated as coordinator and to ENISA (the EU Cybersecurity Agency):
- any actively exploited vulnerability contained in its product with digital elements that it becomes aware of; and
- any severe incident having an impact on the security of the product that it becomes aware of.
This obligation starts to apply on 11 September 2026. The Guidance has added extra paragraphs to highlight that:
- The reporting obligations continue to apply after a product with digital elements is no longer supported, unlike the vulnerability handling obligations, which continue only during the product’s support period.
- Because the obligation to report actively exploited vulnerabilities applies when the manufacturer becomes aware of active exploitation, the manufacturer is not required to report vulnerabilities of whose active exploitation it had already become aware before 11 September 2026.
- By contrast, the obligation does apply where the manufacturer was aware of a vulnerability before 11 September 2026 but does not become aware of any active exploitation of it until after 11 September 2026.
- Where an actively exploited vulnerability originates in a third-party component, it must be reported only if it is actually exploitable and has been exploited in the manufacturer’s own product; otherwise reporting is voluntary, though the manufacturer must still handle the vulnerability and report it upstream to the component’s maintainer.
Reporting upstream
The CRA requires manufacturers to report vulnerabilities in integrated components to the person or entity manufacturing or maintaining that component (reporting upstream). The Guidance has been amended to clarify that:
- Where the person or entity manufacturing or maintaining the component has established security policies, coordinated vulnerability disclosure processes or designated channels for reporting vulnerabilities, manufacturers should report in accordance with them, particularly where premature disclosure of unpatched vulnerabilities could increase cybersecurity risks.
- Manufacturers are not required to report upstream where they can confirm that the person or entity manufacturing or maintaining a component is aware of the existence of a vulnerability.
- Manufacturers are not required to report the vulnerability upstream where the component no longer has a maintainer, or when the manufacturer no longer relies on the original maintainer for new versions or security fixes.
Cybersecurity risk assessment requirements
The CRA obliges manufacturers to conduct a cybersecurity risk assessment to identify relevant risks and assess their potential impact on in-scope products and integrated components. The Guidance highlights that under the CRA cybersecurity risk must be assessed in light of the requirement that the product ensures an appropriate level of cybersecurity based on the risks, taking into account its intended purpose and reasonably foreseeable use. This may differ from the organisation's internal objectives or risk appetite.
Vulnerability handling
The Guidance contains a new section about the CRA’s requirement for manufacturers to apply effective and regular tests and reviews of the product with digital elements throughout its support period. It explains that this requires regularly reviewing whether new input, such as newly identified threats or newly discovered vulnerabilities, requires the existing tests to be updated.
What do in-scope organisations need to do?
In particular, in-scope organisations should:
- map their products with digital elements and confirm their role – manufacturer, importer or distributor – for each;
- put vulnerability and incident reporting procedures in place ahead of 11 September 2026, aligning them with existing NIS2 and GDPR reporting so that a single event does not trigger inconsistent notifications;
- review the finalised Guidance against their portfolio, checking in particular where the clarified positions on scope, substantial modifications and support periods affect existing products;
- ahead of 11 December 2027, assess products against the CRA’s essential requirements and identify the applicable conformity assessment route, scheduling any notified-body assessment early given limited capacity; and
- review supplier and component contracts to secure the vulnerability information and support needed to meet these obligations.