EU Finalizes Cyber Resilience Act Guidance, Clarifying Scope and Deadlines
The European Commission has released final guidance for the Cyber Resilience Act (CRA), setting key compliance deadlines and clarifying the scope of software covered by the landmark 2024 law.

The European Commission has published the final guidance for the Cyber Resilience Act (CRA), a pivotal 2024 law aimed at bolstering the cybersecurity of internet-connected hardware and software products. This updated guidance introduces significant refinements compared to the draft version circulated for consultation in March, offering clearer definitions and adjusted timelines for compliance.
The CRA mandates that manufacturers must report severe security incidents starting September 11. However, the commission has extended the deadline for most other requirements, including product design and ongoing security maintenance, to December 11, 2027. This phased approach allows businesses more time to adapt to the comprehensive security mandates.
A major clarification in the final guidance pertains to the definition of "products with digital elements" and the types of software that fall under the CRA's purview. The law generally excludes websites and web applications that are solely accessed via a browser. Instead, the guidance emphasizes that for software to be covered, it must be "provided to a user, obtained by that user and operated on, or as part of, an electronic information system on the user’s side." This means browser extensions and locally run applications built with web technologies are within scope, but remote-accessed web apps are not.
Further clarity is provided regarding "substantial modifications" to products. The guidance aims to reduce uncertainty for vendors by specifying that product updates will not automatically trigger new compliance burdens if the new functionalities do not alter the product's cybersecurity risk profile or were already accounted for in the mandatory risk assessment. Security updates themselves are explicitly excluded from being considered substantial modifications, even if they involve significant technical changes, as their primary purpose is risk reduction.
The guidance also addresses the support period for products. A substantial modification will not automatically reset or extend the product's security support period unless it genuinely affects the factors that determined the original expected use time. For instance, a software update adding new features to a robot vacuum cleaner might be a substantial modification but wouldn't extend its lifespan, thus not requiring a support period reset.
In a notable addition, the final guidance clarifies the commercial aspects of security updates. Manufacturers may continue to offer security updates for earlier software versions on a paid basis or under other commercial arrangements, even if users can upgrade to the latest version for free. The CRA does not mandate that security updates for older versions must be provided at no cost.
The act's implications for open-source software have been a point of concern, and the commission has attempted to address these anxieties, though details on this aspect were cut short in the provided text. The final guidance aims to provide a more predictable regulatory environment for the IoT sector, encouraging greater security by design and fostering consumer trust in connected devices.