Gwida indipendenti dwar ir-Regolament (UE) 2024/2847 · Status: fis-seħħ
Din il-paġna hija traduzzjoni awtomatika (IA) u ma ġietx riveduta minn persuna. L-artikoli tal-blog huma disponibbli bl-Ingliż biss.
← All news
CRA Insights27 July 2026

On 27 July 2026, the Commission Published Its First Official Guidance on Applying the Cyber Resilience Act

On 27 July 2026, the Commission Published Its First Official Guidance on Applying the Cyber Resilience Act

On 27 July 2026, the European Commission published practical guidance on the application of the Cyber Resilience Act, issued as Communication C(2026) 5252 with a detailed annex. It is the Commission's most substantial interpretive document on the CRA so far, and it lands less than seven weeks before the first hard deadline, when vulnerability and incident reporting begins on 11 ta' Settembru 2026. The guidance changes no obligation and no date. What it does is answer, in the Commission's own words, the questions manufacturers and developers have been asking most, aimed squarely at the smaller companies that have found the regulation hardest to interpret.

What the guidance is, and what it is not

The document is grounded in Article 26 of the CRA, which tasks the Commission with publishing guidance to help economic operators apply the regulation, with particular attention to SMEs. It is explicitly non-binding: only the Court of Justice can give an authoritative interpretation of EU law, and a harmonised standard, not a guidance note, is what unlocks the Article 27 presumption of conformity. But non-binding is not the same as unimportant. This is the Commission's own reading of contested scope and lifecycle questions, and market surveillance authorities will treat it as the reference point. It complements, rather than replaces, the technical FAQ the Commission updated on 2 July 2026 and maintains as a living document.

The scope questions it settles

The most useful part of the guidance is where it draws the boundary of the CRA. It clarifies when remote data processing solutions fall in scope, an important point because the CRA reaches beyond the physical device to remote components whose absence would stop the product working. It also addresses free and open-source software, the area where the line between a regulated product and an unregulated contribution has caused the most confusion; the guidance walks through when open-source software is caught and when the lighter regime for open-source software stewards applies. If you are trying to work out whether a given product is in scope at all, our classification tool and full Fast Check walk through the same scope and tier questions the guidance now formalises.

Substantial modification and support periods

Two lifecycle concepts get dedicated treatment because they decide how long and how far the obligations run. A substantial modification, defined in Article 3(30), is a change made after a product is placed on the market that affects its compliance with the Annex I essential requirements. When it happens, the modified product is treated as newly placed on the market and must go through conformity assessment again, so knowing where the threshold sits is a real commercial question, especially for software that ships continuous updates. The guidance also explains how the perjodu ta' appoġġ, defined in Article 3(20), should be understood: the window during which a manufacturer must handle vulnerabilities and supply security updates, which the CRA sets at a minimum of five years unless the product is expected to be in use for less. Our matriċi tal-konformità maps each of these lifecycle duties to its article reference.

Status at publication, 27 July 2026

The guidance is a helpful map, but two things it points toward are still not in place. ENISA's Single Reporting Platform, the entry point for Article 14 notifications, is not yet operational; ENISA has scheduled it to be live by 11 ta' Settembru 2026, when the reporting duty begins. And no CRA harmonised standard has yet been cited in the Official Journal, so the Article 27 presumption of conformity is not available for any product category; several product-specific drafts have reached a mature stage but none is cited yet. Guidance clarifies how to read the rules; it does not stand in for the standards or the reporting tool a manufacturer will ultimately need.

Reporting, risk assessment, and a deliberate focus on SMEs

The guidance also covers how to meet the reporting obligations u l- risk assessment that underpins the whole regime. On reporting, the fixed rhythm has not moved: from 11 September 2026, a manufacturer aware of an actively exploited vulnerability must send an early warning within 24 siegħa, a fuller notification within 72 siegħa, and a final report within 14-il jum of a fix; our Article 14 reporting guide sets out the sequence. What stands out is the delivery: the document is built around 67 practical examples, plus use cases, flowcharts and diagrams, with microenterprises and SMEs named as the priority audience. That matches what ENISA's SME work this summer found, that awareness of the CRA has outrun the practical ability to comply. The risk assessment and SBOM work under Annex I is exactly where smaller firms struggle, and our free analysis tooling can generate and screen an SBOM to support it.

Għaliex jgħodd

The Commission frames this release as part of its wider simplification agenda, alongside the Digital Omnibus published in November 2025, and says it will consider issuing further guidance under Article 26 as needed. For companies preparing now, the value is concrete: the scope and lifecycle questions that have stalled internal CRA projects, is my product in scope, does this update reset my obligations, how long is my support period, now have an official answer to point to. It is non-binding, and the dates are unchanged, but it removes a common excuse for waiting.

Published 27 July 2026 · CRA Insights. Part of the CRA insights blog on cyberresilienceact.eu.