
Digital products are part of everyday life in Europe - from baby monitors to smartwatches, from apps to computer programs. While these products bring enormous benefits, citizens and businesses deserve the assurance that they are protected from cyber threats. The Cyber Resilience Act, in force since December 2024, delivers exactly that, setting clear and mandatory cybersecurity requirements across the full lifecycle of digital products.
Today's guidance is about making implementation work in practice. Rather than leaving companies - especially smaller ones - to navigate the rules alone, the Commission is stepping in early with clear, accessible, and actionable support. This is simplification in action.
The guidance addresses the questions stakeholders have been asking most, including:
- Clarifying when certain products fall within the scope of the Cyber Resilience Act, including remote data processing solutions and free and open source software
- What constitutes a 'substantial modification'
- How support periods should be understood and applied
- How to meet reporting obligations and risk assessment requirements
Particular attention has been paid to microenterprises and SMEs, with 67 practical examples, a range of use cases, flowcharts and graphs, ensuring that the path to compliance is clear and proportionate, without unnecessary administrative burden.
The publication of this guidance is part of wider efforts towards simplification and effective implementation, including through the Digital Omnibus published in November 2025.
Next steps
The Cyber Resilience Act's main obligations apply from 11 December 2027, with reporting obligations already applying as of 11 September 2026. Today's guidance - though non-binding - gives companies the clarity they need to prepare now, confidently and efficiently.
The Commission remains committed to supporting stakeholders throughout this process and, in line with Article 26 of the Cyber Resilience Act, will consider issuing further guidance as needed.
Background
This guidance was developed through extensive stakeholder consultation, including the expert group on cybersecurity of products with digital elements and a public consultation earlier in 2026. It forms part of the Commission's broader simplification agenda, including the Digital Omnibus published in November 2025.
Find more information
You can download the official communication and the guidance (in the annex) below.