Logo
StreamLex Home
Logo
StreamLex Home
Laws
Laws
Recitals
Recitals
About Us
News
Recitals
Trackers
Resources
Newsletter
Terms of Use
Privacy Notice
LinkedIn
undefined | StreamLex

CRA implementation guidance

Commission Guidance on the application of the Cyber Resilience Act (CRA) — C(2026) 5252

The guidance clarifies scope questions under the Cyber Resilience Act, including how remote data processing solutions and free and open source software fall within its requirements. It defines what constitutes a "substantial modification" of a product, explains how support periods should be understood and applied, and sets out how manufacturers meet reporting obligations and risk assessment requirements. It includes 67 practical examples, use cases, flowcharts, and graphs, with particular attention to proportionate compliance paths for microenterprises and SMEs.

Metadata

Author: European Commission

Status: Adopted / Published

Adoption date: 2026-07-27

Last updated: 19 Aug 2026

Category: Guidance

Subcategory: Official guidance

Relevant laws and articles:

CRA
2
Source URL:https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation

© 2026 StreamLex

NewsletterAbout UsTerms of UsePrivacy NoticeManage Cookies

© 2026 StreamLex