Every worked example in the Commission’s CRA guidance
The Commission adopted its Article 26 guidance on the Cyber Resilience Act on 27 July 2026. Its 67 numbered examples and 5 remote data processing use cases are the part manufacturers actually need. All of them are here, word for word, grouped by the question each one answers.
- Examples
- 74
- Topics
- 8
- New in the final text
- 14
- Adopted
- 27 Jul 2026
The guidance is not binding on economic operators, and only the Court of Justice of the European Union can give an authoritative interpretation of the CRA. It does set out the Commission’s own reading, and market surveillance authorities are expected to apply it.
What counts as a product with digital elements under the Cyber Resilience Act?
The Cyber Resilience Act reaches software that is supplied to a user and executes on that user's device. A mobile application, a desktop application built with web technologies, and source code licensed in a text file are all products with digital elements. A web application used only through a browser is not, unless it supports the functionality of a product that is. Hardware and software that cannot deliver their purpose without each other form one product, even when they are supplied through different channels.
How does the CRA cybersecurity risk assessment justify design decisions?
The Commission's risk assessment examples all turn on the same move. The Article 13(2) assessment decides what a product needs, and it can justify choices that look like gaps. Supporting a legacy protocol for interoperability, integrating a component bought before the CRA applied, placing an older design on the market without redesign, limiting a sensor's intended purpose instead of hardening it, and relying on the operating system's cryptography rather than writing your own are each defensible where the assessment carries them.
5 examples on this page
When is open source software supplied in the course of a commercial activity?
The Cyber Resilience Act reaches free and open-source software only where it is supplied in the course of a commercial activity. The Commission's twenty-two examples locate that line. Charging for a paid version, gating releases or security fixes behind donations, monetising what is sold through the software, and requiring unrelated personal data processing all cross it. Voluntary donations, separately sold consultancy, funded features released openly, and contributing to someone else's project do not.
Are spare parts and repairs subject to the Cyber Resilience Act?
Article 2(6) takes spare parts outside the CRA where they replace identical components in a product with digital elements. The Commission's examples turn on what identical means. A replacement module built to the same specifications is exempt, whether the host product predates the CRA or not. A newer chip with a different cryptographic implementation and secure boot mechanism is not identical and is a product in its own right. A different chipset can still be identical where the protocols and security mechanisms are unchanged.
6 examples on this page
Which software updates has the Commission called substantial modifications?
The Commission tests a software update by its effect on the cybersecurity risk profile rather than by its size. A persistent login feature storing authentication tokens locally is a substantial modification. So is a diagnostics export that leaves sensitive operational data unencrypted. Enabling control features that shipped disabled but assessed is not, and neither is group messaging the original assessment anticipated. Security updates generally fall outside, until they change the intended purpose or add new external dependencies.
How long must a CRA support period be, and does a substantial modification extend it?
Article 13(8) sets the support period by reference to the time the product is expected to be in use. The five year figure is a safeguard floor rather than a default, and products expected to last longer need correspondingly longer periods. Article 13(10) lets a manufacturer remediate only the version last placed on the market, provided users can upgrade free of charge and without additional costs. A substantial modification triggers a reassessment but does not automatically reset or extend the period.
5 examples on this page
How does core functionality decide a product's CRA classification?
Classification follows core functionality, judged against the technical descriptions in Implementing Regulation (EU) 2025/2392. A product that merely integrates an operating system does not take on the core functionality of one. SOAR software generally exceeds the SIEM category and log viewers fall short of it. Modules offered on separate subscriptions are separate products, each classified on its own. Extra functions do not push a product into a stricter conformity route, and the presumption of conformity covers only what the harmonised standard covers.
9 examples on this page
Is my cloud back end a remote data processing solution under the CRA?
Remote data processing is part of your product when two things hold together. The product cannot perform one of its functions without it, and the software was designed and developed by you or under your responsibility. Your own back end qualifies even when it runs on third-party infrastructure. A general purpose third-party SaaS does not, and is treated as a component instead. Systems your product never talks to directly fall outside, and a cellular network is neither a solution nor a component.
What changed between the draft and the adopted text
The March 2026 consultation draft carried 55 numbered examples. Fifty-four survive into the adopted guidance, two of them merged into one. Fourteen examples are new, concentrated in scope, spare parts, integration, support periods and risk assessment. One was deleted, the counter-example showing a physical repair that does amount to a substantial modification.
The deleted example is reproduced on the repairs and spare parts page, labelled as removed, because readers working from the draft will remember it and the rule it illustrated is still in force at point 95.
Work out where your own product lands
Free CRA classification, a vulnerability disclosure portal on your own domain, and Article 14 deadline tracking.