Cyber Resilience Act
Commission guidelines
Practical term
Commission guidelines are the interpretive material on the Cyber Resilience Act (CRA) that Article 26 of the Regulation expressly provides for. The Commission publishes them to facilitate implementation and to keep that implementation consistent, with a particular focus on making compliance easier for microenterprises and small and medium-sized enterprises. Article 26 is headed “Guidance” in the English text and “Leitlinien” in the German one.
The audience is the economic operators, above all manufacturers, authorised representatives, importers and distributors. Guidance does not say what the law is; it says how the Commission reads the law. That is where its practical value lies, and equally where its limit lies.
The four topics Article 26 prescribes
Paragraph 2 fixes what the Commission has to address as a minimum whenever it provides guidance:
- the scope of the Regulation, with particular attention to remote data processing and free and open-source software
- how support periods apply to particular categories of products with digital elements
- material aimed at manufacturers who are subject not only to the CRA but also to other Union harmonisation legislation or to other related Union legal acts
- the concept of substantial modification
That is a floor, not a closed list. The same provision also obliges the Commission to maintain an easy-to-access list of every delegated and implementing act adopted under the Regulation.
Guidance binds no one
A piece of guidance is not a legal act. It creates no presumption of conformity. Article 27 attaches that effect to harmonised standards or parts thereof, the references of which have been published in the Official Journal of the European Union (paragraph 1), to common specifications (paragraph 5) and to EU statements of conformity and European cybersecurity certificates issued under a European cybersecurity certification scheme (paragraph 8). Guidance appears nowhere in that list. Following guidance therefore demonstrates nothing on its own.
In practice the gap is narrower than it sounds. Market surveillance authorities and notified bodies as a rule work from the same reading, and anyone departing from it should be able to explain why. The benefit lies in predictability rather than in legal certainty.
Where binding effect is intended, the Regulation names an instrument
Wherever the Commission is meant to act with binding force, the CRA says so explicitly. Three examples show the difference:
- Article 7(4) obliges the Commission to adopt an implementing act by 11 December 2025 specifying the technical description of the Annex III product categories in classes I and II and of the Annex IV categories.
- Article 27(2) allows common specifications by implementing act, but only where the route via harmonised standards has failed.
- Article 8(1) allows delegated acts requiring certification for critical products, provided a relevant European cybersecurity certification scheme has been adopted and is available to manufacturers.
Article 26 names neither an instrument nor a deadline. Nothing in the Regulation settles when a given piece of guidance arrives, or in what form.
Guidance from other bodies
The Commission is not the only source. Under Article 52(16), the administrative cooperation group (ADCO) publishes statistics on the average support periods per category of product with digital elements and provides guidance setting out indicative periods for those categories. Article 13(8) names that guidance explicitly as something manufacturers may take into account when setting their own support period.
Authorities also have a power to advise in their own right. Under Article 52(10), market surveillance authorities may give economic operators guidance and advice on implementation, with the support of the Commission and, where appropriate, the CSIRTs and ENISA. For microenterprises and SMEs, Article 33(3) points back to Article 26.
What this means for planning
The Regulation applies from 11 December 2027, and the reporting obligations in Article 14 from 11 September 2026. Those dates do not move because guidance on a particular question has yet to appear.
Anyone who has to decide today whether a feature addition amounts to a substantial modification, or how long a support period should run, therefore decides on their own footing. The workable approach is to write that reading down together with the reasoning behind it, and to revisit it once the Commission speaks.
Practical questions
-
Yes, through the consultations the Regulation requires. Article 26(3) obliges the Commission to consult relevant stakeholders when preparing guidance. Article 9(1)(a) names that preparation as one of the cases where the Commission is to consult in a structured manner, where appropriate, and the stakeholders listed there include microenterprises and SMEs as well as the open-source software community. In practice the route runs through public consultations and industry associations.
-
No. Where no harmonised standard covers a requirement, there is no presumption of conformity, and guidance does not change that. For exactly that situation Article 27(2) provides for common specifications adopted by implementing act, though only under narrow conditions. With neither a standard nor a common specification in place, you have to evidence compliance with the Annex I requirements yourself.
-
Guidance does not change the law; it exposes how the Commission reads it. Where it shows that your assessment rested on a wrong assumption, correct the assessment and update the technical documentation. For products placed on the market before 11 December 2027, Article 69(2) means the requirements bite only on a substantial modification. The reporting obligations in Article 14 are carved out of that and apply to every product within scope.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.