EU Commission sets out details of the Cyber Resilience Act
The Cyber Resilience Act (Regulation (EU) 2024/2847 – CRA) is a legal instrument that significantly affects products with digital elements. This includes both hardware and software that can communicate with other products or a network. Many of the legal terms used in the CRA are open to interpretation and still raise numerous questions in practice. The European Commission has now published comprehensive guidance to clarify the CRA’s key concepts and requirements.
Contents of the guidance
By publishing the guidance on 27 July 2026, the Commission implemented Article 26 of the CRA and gave affected economic operators a key aid to interpretation.
The guidance is not binding but reflects the Commission’s official interpretation and defines terms, responsibilities and reporting obligations under the CRA, among other things.
It also addresses a number of issues that are especially relevant to the CRA’s practical application. These include in particular:
- placing products with digital elements on the market,
- combining hardware and software that together form a product with digital elements,
- determining which software (as a service) falls within the CRA’s scope,
- assessing the CRA’s impact on free and open-source software,
- explaining modifications and spare parts,
- setting out the requirements and use cases for remote data processing solutions, and
- providing sector-specific guidance for the banking sector, especially on classifying banking apps as products with digital elements.
Integration into the wider guidance on the CRA
The Commission’s newly published guidance does not stand alone; it forms part of a growing body of guidance that specifies and supports the Cyber Resilience Act.
Other sources include, first and foremost, the Commission’s FAQs, which addresses practical questions on scope, deadlines and the obligations of the various economic operators and is regularly updated with new case scenarios.
The CRA website of the Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik) supplements this with information and recommendations in German that place the European requirements in a German market context and refine them further. In addition, on 31 July 2026, the Federal Office issued its own technical guidelines on cyber resilience requirements (TR-03183).
The Commission’s Blue Guide remains a key reference on questions of product classification, placing on the market and responsibilities along the supply chain as the CRA and other legal acts under the New Legislative Framework build on its horizontal principles.
The European Union Agency for Cybersecurity (ENISA) is also worth consulting. The agency provides information on the technical reporting platforms and on how the reporting procedure works in practice, a point that carries particular weight given the reporting obligations for vulnerabilities and incidents taking effect from 11 September 2026. ENISA also released a Secure by Design and Default Playbook on 30 July 2026.
Well
informed
Subscribe to our newsletter now to stay up to date on the latest developments.
Subscribe now









