The European Commission has recently issued final guidance for businesses to comply with the Cyber Resilience Act (CRA), a pivotal piece of legislation set to enhance the cybersecurity landscape for software and internet-connected hardware products. This guidance marks a significant shift from a prior draft proposed in March, providing clarity on various critical aspects of the CRA’s implementation.
Scheduled to go into effect, the CRA mandates that severe security incidents must be reported starting September 11, 2026. However, to facilitate a smoother transition, the Commission has granted manufacturers until December 11, 2027, to meet the majority of the law’s requirements. These obligations focus on ensuring that products are designed with security features in mind and that these security standards are upheld throughout the product’s lifecycle.
One of the more notable alterations in the final guidance concerns the categorization of software that falls under the CRA’s jurisdiction. Initially, the draft suggested that any software available for download or accessible via remote means would be bound by the CRA. The finalized guidance now clarifies that for software to be included, it must be delivered to a user and operated as part of an electronic information system on that user’s end. This adjustment means that while browser extensions and locally-run applications utilizing web technologies will be regulated, web applications accessible solely through browsers will not be considered products with digital elements.
This distinction is crucial, as the guidance clarifies that merely accessing software remotely does not classify it within the CRA’s scope. Websites may operate to some extent on a user’s device, yet they do not qualify as products unless they specifically serve to augment the functionality of a product with digital elements.
Furthermore, significant changes have emerged regarding manufacturers making “substantial modifications” to their software. Legal experts had previously warned of potential conflicts over the definition of substantial modifications, but the final guidance now provides specific criteria for these changes. Such modifications may necessitate new compliance efforts, but the guidance alleviates concerns by stating that updates introducing functionalities previously identified in mandatory risk assessments will not automatically qualify as substantial modifications. Similarly, security updates are explicitly excluded from this category, even if they involve considerable technical adjustments.
An important clarification within this guidance is the treatment of a substantial modification in relation to a product’s support period. Notably, a substantial modification does not automatically reset or extend this support period unless it impacts the factors determining the product’s lifespan. This nuanced clarification aims to prevent confusion regarding changes that do not substantially affect a product’s operational timeline.
For instance, if a robot vacuum cleaner receives a software update introducing new cleaning modes but does not alter its expected durability or lifespan, the original support period will remain unchanged. Conversely, if such modifications would extend the product’s operational longevity, manufacturers are obliged to recalculate the support period accordingly.
Moreover, the final guidance sheds light on the financial aspects of charging for security updates. If users can upgrade to new software versions without incurring additional costs, manufacturers retain the option to continue addressing vulnerabilities in older versions, potentially on a paid basis. This flexibility offers businesses some latitude in their pricing strategies while adhering to the CRA.
Particularly noteworthy are the implications the CRA holds for open-source projects. Addressing ongoing concerns in the tech community, the Commission reinforces that contributors to free and open-source software (FOSS) are not liable for obligations under the CRA unless they influence releases or governance decisions. This reassurance is coupled with examples aimed at elucidating this responsibility.
Additionally, the CRA introduces a new legal category for “open-source software stewards,” encompassing organizations that produce FOSS intended for integration into commercial products but do not profit directly from it. The guidance specifies that if such organizations cease to provide consistent support for a specific piece of FOSS, they may no longer qualify as stewards and, therefore, be exempt from certain obligations outlined in the CRA.
In summary, the European Commission’s final guidance on the Cyber Resilience Act represents a crucial development in addressing the evolving cybersecurity landscape for digital products. By clarifying key definitions and compliance requirements, the guidance aims to streamline the implementation process for manufacturers. As businesses prepare for these mandates, the focus remains on enhancing cybersecurity measures to protect users and their data effectively.

