07/27/2026 | Press release | Distributed by Public on 07/27/2026 04:10
Manufacturers, developers and businesses of all sizes across the EU now have new guidance on how to apply the Cyber Resilience Act. This will help them prepare for mandatory cybersecurity requirements and reporting obligations.
The new Commission guidance explains how these rules apply in practice. It clarifies which products fall within the scope of the Act, what constitutes a substantial modification, how support periods should be understood, and how to meet reporting obligations and risk assessment requirements.
It also responds to questions raised by businesses, giving particular attention to microenterprises and small and medium-sized enterprises. It includes practical examples and uses cases to help reduce any unnecessary administrative burden.
Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy, said:
"This guidance is part of our simplification agenda, helping businesses meet their obligations under the Cyber Resilience Act on time and with confidence. A cyber-secure Europe and a business-friendly Europe go hand in hand: today's guidance will help ensure that products on our market are protected from cyber threats, while avoiding unnecessary burden and legal uncertainty for companies."
Recent developments in frontier AI models with cybersecurity capabilities render the swift and correct implementation of the Cyber Resilience Act even more imperative. The Cyber Resilience Act, in force since December 2024, sets mandatory cybersecurity requirements across the full lifecycle of digital products, with reporting obligations applying as of 11 September 2026. Ahead of the December 2027 compliance deadline, the guidance marks a further concrete step in the Commission's simplification agenda.
Read more about the guidance.