Back to all articles
Fundamentals·29 July 2026·5 min read

The Commission's first CRA guidance, decoded: what it actually answers

On 27 July 2026 the European Commission published its first official guidance on applying the CRA. Here is what it covers, and what to do with it.

On 27 July 2026, the European Commission published its first official guidance on applying the Cyber Resilience Act: a Communication, C(2026) 5252, plus a detailed annex. It is not new law, and it moves no deadlines. It is something more immediately useful: the regulator explaining, in plain language and with worked examples, how it reads its own regulation.

If you place hardware, firmware, or software on the EU market, this is the document to read before the reporting obligations begin on 11 September. Here is what it covers, and where it helps most.

Scope: the does-this-apply-to-me chapter

The guidance works through what counts as a product with digital elements, and it takes on the two questions that cause the most confusion: remote data processing, meaning when the cloud side of your product is in scope, and free and open source software, meaning when open source carries obligations and when it does not. If you have been guessing about a SaaS component or an open-source dependency, there is now an official reading to check yourself against.

Substantial modification: the update question

When does a change to your product re-open the conformity assessment? Every team that ships firmware or regular releases lives with this question, and until now the honest method was to argue it out from the regulation text alone. The guidance sets out how to think about which changes are substantial and which are not. If you ship updates on a schedule, this is the chapter that decides how much process each release carries.

Support periods: how long you owe updates

The guidance also covers how support periods should be understood and determined. Your support period is a commitment that ends up in your user information and shapes your vulnerability-handling duties, so a defensible, documented answer beats an optimistic one. This chapter is the reference for setting it.

Reporting and risk assessment

Two more chapters land close to home. One covers the reporting obligations that start on 11 September 2026: the 24-hour early warning, the 72-hour notification, and the final report. The other covers the risk assessment the regulation requires of every manufacturer. If you have not yet rehearsed the reporting sequence, the guidance plus one dry run is the preparation. Our reporting playbook article walks the same clocks in detail.

Written with SMEs in mind, with 67 worked examples

The annex carries 67 practical examples, use cases, flowcharts and graphs, aimed squarely at microenterprises and SMEs. That is the Commission saying, in effect, that proportionate compliance is the expectation, not enterprise-grade paperwork for a five-person team. When you are unsure how a rule lands on a company your size, check whether one of the examples is you.

What the guidance does not change

  • The deadlines stand: reporting duties from 11 September 2026, full application from 11 December 2027.
  • Guidance is not law. It shows how the Commission reads the regulation; the regulation itself is still what binds you.
  • It does not replace harmonised standards, which are still in development and will define the presumption-of-conformity route when they arrive.

The practical move: skim the annex once, read the two chapters that touch you hardest, for most teams scope and substantial modification, and file the worked examples closest to your product. Then compare the guidance against your own assessment and pay attention wherever the two disagree.

Where that assessment starts: our free applicability check tells you in about a minute whether the CRA applies to your product and how it likely classifies, no signup required. It is exactly the kind of judgment the new guidance now lets you sanity-check against the regulator's own examples.