
The draft is intended to support economic operators and market surveillance authorities in applying the CRA in practice. It does not amend the Regulation, but clarifies how the Commission interprets key concepts and obligations.
In general, the draft covers:
- Scope of the CRA—including what “placing on the market” means for software, how software is treated and when hardware and software constitute a single product.
- Free and open-source software (FOSS)—detailed guidance on when FOSS is considered to have been placed on the market, the role of open-source software stewards and the boundaries of commercial activity.
- Substantial modifications—when updates or changes trigger new obligations.
- Support periods—how long manufacturers must address vulnerabilities.
- Cybersecurity risk assessment and due diligence—particularly in relation to integrated components and external dependencies.
- Remote data processing solutions—clarification of what falls within the scope of the CRA and when.
- Interaction with other legislation—including the AI Act and DORA.
The document is extensive, at more than 70 pages, and provides valuable insight into how enforcement may work in practice.
This is an important step towards operational clarity before the CRA becomes fully applicable.
European Commission portal and documents: Draft Commission guidance on the Cyber Resilience Act
The consultation closed on 13 April 2026. A total of 252 submissions were received.