The guidance clarifies scope questions under the Cyber Resilience Act, including how remote data processing solutions and free and open source software fall within its requirements. It defines what constitutes a "substantial modification" of a product, explains how support periods should be understood and applied, and sets out how manufacturers meet reporting obligations and risk assessment requirements. It includes 67 practical examples, use cases, flowcharts, and graphs, with particular attention to proportionate compliance paths for microenterprises and SMEs.
Author: European Commission
Status: Adopted / Published
Adoption date: 2026-07-27
Last updated: 19 Aug 2026
Category: Guidance
Subcategory: Official guidance