Alessandro Del Ninno
News
European Commission: Cyber Resilience Act – operational guidance published; first reporting obligations apply from 11 September.
CYBERSECURITY
08/09/2026

The European Commission has published its first operational guidance to facilitate the implementation of the Cyber Resilience Act – Regulation (EU) 2024/2847, providing manufacturers, developers and businesses with practical guidance to prepare for the new EU cybersecurity obligations applicable to products with digital elements. The guidance, set out in Commission Communication C(2026) 5252 and its accompanying Annex, is non-binding, but constitutes an important interpretative reference for the implementation of the Regulation.

The publication is particularly significant in view of 11 September 2026, the date from which the reporting obligations laid down by the CRA become applicable. From that date, manufacturers will be required to notify actively exploited vulnerabilities and severe incidents having an impact on the security of products with digital elements. An initial early warning must be submitted within 24 hours of becoming aware of the relevant event, followed by a notification within 72 hours and, subsequently, by a final report within the time limits prescribed by the Regulation. Notifications will be submitted through the single reporting platform established by ENISA.

The guidance addresses a number of areas that have raised significant interpretative and implementation issues for businesses, including the scope of application of the CRA, free and open-source software, remote data processing solutions, substantial modifications to products, the duration of the support period, cybersecurity risk assessments and compliance with reporting obligations. The Commission also devotes specific attention to microenterprises and SMEs and supplements the guidance with 67 practical examples, use cases, diagrams and visual illustrations designed to facilitate the identification of the obligations applicable in individual cases.

The publication therefore represents an important step in the progressive implementation of the CRA. While the reporting obligations become applicable from 11 September 2026, most of the Regulation’s other substantive obligations will apply in full from 11 December 2027.

For businesses falling within the scope of the Regulation, the guidance provides, above all, an operational tool for commencing or completing the mapping of products with digital elements, identifying their role within the relevant supply chain, defining appropriate support periods, structuring vulnerability-handling processes and establishing internal procedures capable of ensuring compliance with the new and stringent reporting deadlines.

The entry into application of the first obligations therefore confirms that businesses should not wait until 2027 to complete their overall compliance programmes. Vulnerability management, reporting workflows, the allocation of internal responsibilities and the documentation of cybersecurity processes already require organisational and procedural safeguards aligned with the Cyber Resilience Act.