The Cyber Resilience Act (Regulation (EU) 2024/2847) will remain a recurring topic in our newsletter for some time to come. Manufacturers must comply with the reporting requirements in the event of an incident starting September 11, 2026. The CRA will take full effect on December 11, 2027.
To avoid translation errors, the information from the documents is presented below in the original English text.
CRA FAQ (see hyperlink below)
The fourth version (V1.3) was published on July 1, 2026. Compared to earlier versions, Chapter 4.6 has been removed:
4.6 Other manufacturer’s obligations.
The FAQ is not published in the OJEU.
CRA Guide (see hyperlink below)
The latest draft of the CRA Guide was published in early March 2026. Now, on July 27, 2026, the final text was published by the European Commission in English. Once all EU language versions are available, publication in the OJEU is expected to take place shortly. Compared to the draft version from March 2026, 14 pages have been added, bringing the Guide’s total length to 84 pages.
New sections include, for example:
- 2.7 Products with digital elements designed before the CRA entered into force
- 4.4 Consequences of a substantial modification, with a new subsection:
4.4.1 Substantial modifications carried out by a person other than the original manufacturer
4.4.2 Substantial modifications carried out by the original manufacturer - 5.1 Substantial modifications and the support period
Otherwise, the guide addresses the usual key topics (headings partially abbreviated):
2. Scope
3. Open-Source Software
4. Substantial modifications
5 Support Period
6. Important and Critical Products
7. Cybersecurity Risk Assessment
…
Status of Harmonized Standards for CRA
According to CENELEC, the status remains unchanged, partly because a few deadlines appear to have been missed.
The standards are being developed by the CEN-CENELEC committee “CEN/CLC/JTC 13, WG9.” Working Group 9 focuses on
“Horizontal cybersecurity for products with digital elements”
The Chairman (WG 9) is Ben Kokx, under whose leadership the EN 18031-X series was also developed.
→ Status
EN 40000-1-1
Cybersecurity requirements for products with digital elements
- Part 1-1: Vocabulary
EN 40000-1-2
Cybersecurity requirements for products with digital elements
- Part 1-2: Principles for cyber resilience
EN 40000-1-3
Cybersecurity requirements for products with digital elements
- Part 1-3: Vulnerability Handling
The hope remains that the standards will be published in their final form at least 6 months before the Cyber Resilience Act (CRA) takes effect (December 11, 2027). Implementation within a typical development project would then be nearly impossible. Therefore, the drafts—which will hopefully be published in the coming weeks and months—will be crucial.
Do you have questions about the Cyber Resilience Act?
Whether it’s about the impact on your products, support with implementation, or interpreting current guidelines and standards, our experts are happy to assist you.
Get in touch with us. We’ll provide you with straightforward, practical advice.
Author's note
This article has been machine translated into English.
TERMS AND ABBREVIATIONS
OJEU: Official Journal of the EU
CRA: Cyber Resilience Act (EU) 2024/2847
