The European Commission has published new practical guidance to support manufacturers, software developers and businesses in preparing for compliance with the Cyber Resilience Act.
The guidance explains key areas such as the scope of the Regulation, remote data processing solutions, free and open-source software, substantial modifications, support periods, cybersecurity risk assessments and reporting obligations. It also includes practical examples, use cases and flowcharts, with particular attention to the needs of microenterprises and SMEs.
The Cyber Resilience Act has been in force since December 2024.
- Reporting obligations for manufacturers apply from 11 September 2026
- Main obligations will apply from 11 December 2027
Although the guidance is non-binding, it provides useful clarification to help organisations prepare for implementation in a timely and proportionate manner.
Find the guidance here.
