Written by: Haim Ravia, Dotan Hammer
On July 27, 2026, the European Commission published new guidance to support businesses in implementing the Cyber Resilience Act (CRA), which establishes EU-wide cybersecurity requirements for products with digital elements — encompassing both hardware and software products placed on the EU market.
The CRA is being implemented in three phases. Chapter IV, which establishes obligations for conformity assessment bodies, applies from June 11, 2026. Article 14’s vulnerability reporting obligations — requiring manufacturers to report actively exploited vulnerabilities and severe security incidents to the relevant Computer Security Incident Response Teams (CSIRTs) and to ENISA — take effect from September 11, 2026. The CRA as a whole, including the full set of essential cybersecurity requirements for products with digital elements, will apply from December 11, 2027.
The Commission’s guidance clarifies several key aspects of the CRA’s scope and obligations. It confirms that the CRA applies to both hardware and software products with digital elements, covering a broad range of products from consumer IoT devices to enterprise software. The guidance elaborates on the essential cybersecurity requirements that manufacturers must meet, including conducting risk assessments, implementing secure-by-design and secure-by-default principles, establishing vulnerability handling procedures, and providing security updates throughout the product’s expected lifetime. The guidance also addresses the CRA’s interaction with other EU regulatory frameworks, particularly the NIS2 Directive and the EU AI Act, providing clarity on how manufacturers can navigate overlapping obligations.
Click here to read the European Commission’s guidance on the Cyber Resilience Act.