
The guidance answers frequently asked questions concerning, in particular, the scope of the Act, remote data processing solutions, free and open-source software, interpretation of the term “substantial modification”, product support periods, reporting obligations and risk assessment requirements.
Particular attention is paid to microenterprises and small and medium-sized enterprises.
The document contains 67 practical examples, use cases, flowcharts and diagrams intended to make compliance with the Act easier.
The main obligations under the Cyber Resilience Act will apply from 11 December 2027, while the reporting obligations apply from 11 September 2026.
Although the guidance is not legally binding, it is intended to give economic operators the certainty they need when preparing for the new requirements.
► More information: Commission publishes new guidance to support timely Cyber Resilience Act implementation