started · updated
European Commission issues guidelines for Cyber Resilience Act
The European Commission has released new guidelines to support the implementation of the Cyber Resilience Act (CRA), aimed at enhancing cybersecurity for products with digital components. These guidelines, developed with cybersecurity experts and following public consultation, are intended to provide clarity to manufacturers, importers, and distributors regarding the practical application of the law, including questions on product scope and open-source software.
Starting September 11, 2026, companies will face strict mandatory reporting requirements for active vulnerabilities. This process involves a three-stage procedure: an initial early warning within 24 hours of discovery, a detailed incident report within 72 hours, and a final comprehensive report once the issue is resolved.
Non-compliance with these transparency and security regulations carries significant financial risks. Violations can result in fines of up to 15 million euros or 2.5 percent of a company's total worldwide annual turnover, whichever is higher.