Technology, Media and Telecommunications (TMT)

European Commission publishes new guidelines on the Cyber Resilience Act

Published on 23 September 2026

Brussels publishes operational guidelines and tools to facilitate CRA compliance for European companies

Data structure abstract

The European Union’s regulatory framework for digital security took a decisive step forward with the entry into force, in December 2024, of the Cyber Resilience Act (Regulation (EU) 2024/2847) (CRA). This horizontal regulation sets out mandatory cybersecurity requirements throughout the entire lifecycle of products with digital elements placed on the single market, ranging from consumer internet of things (IoT) devices to complex software solutions and industrial network equipment. To mitigate legal uncertainty and facilitate a uniform implementation across the business landscape, the European Commission adopted on 27 July 2026 the official guidelines provided for in Article 26 of the regulation.

The document, developed following extensive public consultations and discussions with the expert group on the cybersecurity of products with digital elements, comprises approximately 80 pages structured to address the operational questions most frequently raised by manufacturers. 

This initiative falls within the Commission’s administrative simplification agenda, aligning with the Digital Omnibus presented in November 2025 to prevent disproportionate bureaucratic burdens. The guidelines place a particular emphasis on micro-enterprises and small and medium-sized enterprises (SMEs), incorporating 67 practical examples, use cases and explanatory diagrams that translate legal requirements into concrete operational guidelines.

Precise definition of scope

One of the most technically significant sections of the approved guidelines concerns the definition of the CRA's material scope, particularly in relation to remote data processing solutions and free and open-source software. The rapid evolution of hybrid cloud architectures made it necessary to clarify to what extent software components located outside the physical device are subject to the essential requirements set out in Annex I of the regulation.

The Commission clarifies the situation regarding remote data processing and cloud-based solutions by establishing a three-part test: the service falls within the scope of the regulation if the processing is carried out remotely, its absence would prevent the product from performing one of its functions, and the software was designed under the manufacturer’s responsibility. 

With regard to free and open-source software, a simplified regime is set out whereby software developed outside the commercial context is excluded; obligations apply only where there is a commercial activity involving the charging of fees, the monetisation of related services, or requests for personal data for reasons other than improving the security, compatibility or interoperability of the software.

Cybersecurity risk assessment 

The CRA requires manufacturers to carry out a cybersecurity risk assessment in order to identify relevant risks, evaluate their potential impact on the product and implement the necessary measures to address them. Unlike organisational risk management, where risks are assessed according to the company’s own internal risk criteria, the CRA requires that the residual cybersecurity risk be assessed in relation to the appropriate level of security for the product, taking into account its intended purpose and reasonably foreseeable use. 

The guidelines are unequivocal on this point: neither the manufacturer’s internal risk tolerance nor its commercial strategy constitutes a valid justification for leaving an identified risk unaddressed. Similarly, the Commission expressly rules out the transfer of responsibility for cybersecurity to users or third parties as a means of compensating for design deficiencies. The obligation to place a safe product on the market and to demonstrate compliance with the CRA rests, in all cases, with the manufacturer.

The guidelines also introduce a significant practical simplification for manufacturers with similar product lines. Where different variants share the same architecture, safety-relevant design and intended purpose, and are exposed to the same cybersecurity risks, the manufacturer may rely on a single risk assessment, a single set of technical documentation and a single conformity assessment procedure to cover all variants, provided that the differences between them are not relevant to the product’s cybersecurity.

Life-cycle dynamics: substantial modifications and support period

Another key section of the guidelines addresses when a modification to a product already on the market requires the conformity assessment to be repeated. In accordance with Recital 39 and Article 3.30 of the regulation, the Commission clarifies that a modification is "substantial" when it changes the level of cybersecurity risk in a way that the manufacturer had not envisaged in its initial risk assessment, or when it changes the intended use of the product for which it was assessed. The relevant criterion is not the technical magnitude of the change, but its impact on the risk profile: new attack vectors, new threat scenarios or a change in the probability or impact of an incident.

In this regard, the guidelines provide clarity on a particularly common scenario: security updates do not, as a general rule, constitute a substantial modification, provided that they do not alter the intended purpose of the product or introduce new risks, since their purpose is precisely to reduce the existing risk. Where a substantial modification does occur, the product is considered to be "re-placed on the market" and, if the change is introduced by an operator other than the original manufacturer, that operator assumes the manufacturer’s obligations in respect of the modified part.

Regarding the support period (the time during which the product’s vulnerabilities must be managed),  the guidelines confirm that the five years provided for in Article 13.8 constitute the minimum legal requirement for products whose expected useful life reaches that threshold. For all other products, the period must be determined based on the length of time the product can reasonably be expected to remain in use: it will be less than five years where the product’s service life is shorter, and must exceed five years where its expected service life so requires.

Osborne Clarke comment

The publication of the European Commission’s first guidelines on the application of the CRA marks a significant milestone in the regulatory maturation of the regulation, as it provides economic operators with a concrete interpretative framework on some of the issues that had generated the greatest uncertainty since its entry into force. 

Although the guidelines are not legally binding, their practical value is undeniable: for the first time, manufacturers have official criteria on how to interpret key concepts of the regulation, such as defining the scope of the product in cloud environments, the scope of the risk assessment, and free and open-source software, which significantly reduces the legal uncertainty associated with compliance.

In this context, it is important not to lose sight of the implementation timetable: the obligations to report vulnerabilities and incidents will apply from 11 September 2026, while the bulk of the essential cybersecurity requirements will not be fully applicable until 11 December 2027.

* This article is current as of the date of its publication and does not necessarily reflect the present state of the law or relevant regulation.

Connect with one of our experts

Interested in hearing more from Osborne Clarke?

Upcoming Events