Industry News

Commission Adopts Its Guidance on Applying the Cyber Resilience Act

The European Commission has adopted C(2026) 5252, the guidance on the application of Regulation (EU) 2024/2847 that Article 26(1) of the Cyber Resilience Act obliges it to publish. The document runs to 84 pages, 257 numbered points, 67 worked examples and 10 figures, and follows a public consultation held between 3 March and 13 April 2026.

The guidance is not binding. Only the Court of Justice of the European Union can give an authoritative interpretation of the CRA. What it does carry is the Commission's own reading, and it is the document market surveillance authorities, notifying authorities and notified bodies are expected to work from when the regulation is enforced.

The reporting clock now has a definition

The most immediate point concerns Article 14. The guidance confirms that the reporting obligations start on 11 September 2026, that they apply to every product in scope including products placed on the market before 11 December 2027, and that they continue after a product's support period has ended.

It also settles what "becoming aware" means, which is the moment every reporting deadline runs from. A manufacturer becomes aware when, after an initial assessment carried out immediately on detecting a suspicious event or receiving a third-party report, it has a reasonable degree of certainty that a vulnerability in its product is being actively exploited, or that a severe incident has compromised the product's security. The Commission has deliberately aligned this with recital 31 of Implementing Regulation (EU) 2024/2690 and with Section II(A) of the EDPB guidelines on personal data breach notification, so that a manufacturer subject to several regimes can apply one test.

Two limits are worth noting. There is no retroactive reporting, so active exploitation a manufacturer already knew about before 11 September 2026 is not reportable. And a vulnerability in a third-party component is only reportable where it is actively exploited in your product. Where the vulnerable code is unreachable, the mandatory report falls away, although voluntary notification under Article 15 and upstream reporting under Article 13(6) both remain available.

A four-factor test for substantial modification

Point 110 gives manufacturers something they have been working without. To decide whether a software update is a substantial modification, ask whether it introduces new threat vectors, whether it enables new attack scenarios, whether it changes the likelihood of previously identified attack scenarios, and whether it changes their impact. Where all four are negative and the assumptions relied on in the risk assessment still hold, the update is unlikely to be substantial.

The guidance is explicit that the size of the change is irrelevant. A "remember me" feature that stores authentication tokens locally is a substantial modification. Enabling a control feature that was designed, assessed and shipped in a disabled state is not. Security updates are generally not substantial modifications, but that carve-out falls away where the update alters the intended purpose or the dependency structure, as when local encryption is replaced by a remote service.

Five years of support is a floor

Point 126 corrects a widespread reading of Article 13(8). The support period is derived from how long the product is expected to be in use. Five years operates as a safeguard for the short tail, and products reasonably expected to stay in use longer need correspondingly longer periods.

Each substantially modified version needs its own declared support period. A substantial modification does not by itself reset or extend the period, and the question is whether the modification changed the factors that set the expected use time in the first place. A software feature update to a robot vacuum does not. Replacing a controller's computing platform with longer-lived hardware does.

Two scope answers manufacturers have been asking for

A web application accessed exclusively through a browser is not a product with digital elements. Neither is a website that only presents information. Both enter scope only where they support a function of some other product. A locally installed client is in scope even where it is built with web technologies.

Hardware and the software necessary for it to perform its functions are a single product, even when the software ships through a separate channel at a later date. Printer drivers and companion apps for wearables both fall on this side of the line.

Remote data processing reduced to two questions

Section 8 and Figure 9 turn the remote data processing definition into two cumulative questions asked of each remote module. Would its absence prevent the product performing one of its functions, core or otherwise? And was the software designed and developed by the manufacturer, or under its responsibility?

Both yes means the module is part of the product. Your own software running on a third-party IaaS or PaaS qualifies. A third-party SaaS application you integrate does not, and is treated as a component subject to Article 13(5) due diligence instead. Who operates the solution is irrelevant, so on-premises and private cloud deployments qualify on the same terms as public cloud. HR systems, payroll, CRM, build pipelines, penetration testing and statistics-only telemetry are all named as outside the definition.

What happens next

The guidance closes by flagging that the Commission may issue further guidance on how the CRA interacts with the AI Act and with DORA. A footnote also records that the Commission's 2026 work programme envisages a European Product Act updating the New Legislative Framework and the rules on market surveillance and standardisation.

For manufacturers, the nearer date is the one that has not moved. Article 14 applies from 11 September 2026, and the guidance has now removed the main excuse for not knowing when the clock starts.

All 67 numbered examples and the 5 remote data processing use cases are reproduced word for word, grouped by the question each answers, at the worked examples hub.

Article 14 reporting obligations start on 11 September 2026.

Get started free