What the Commission's July 2026 CRA guidance actually says
On 27 July 2026 the European Commission published its first official Cyber Resilience Act guidance: 67 practical examples, a set of flowcharts, and clarifications on five concepts. It contains no templates. Technical documentation and Declarations of Conformity remain entirely the manufacturer's responsibility — and the guidance is explicitly non-binding.
What it is
A Commission Communication with an annex, aimed squarely at organisations without in-house legal teams. That framing matters: the flowcharts are unusually plain for an EU document, and the examples are concrete rather than abstract.
It is not binding. It is the Commission's interpretation of its own regulation. In a dispute, the regulation text and the harmonised standards govern — a point worth remembering before treating any example as a safe harbour.
The five things it clarifies
Scope
The bulk of the 67 examples address what is and is not a product with digital elements. The recurring themes are remote data processing, standalone software, and products that sit near a sector-specific exclusion.
Remote data processing
The SaaS boundary, clarified. Pure cloud services sit under NIS2. Remote processing that is integral to a product — where the product does not function without it — is treated as part of that product and falls in scope.
Substantial modification
When a change to an existing product makes you the manufacturer. This is the clarification that matters most to integrators and white-labellers, who frequently do not realise they have assumed manufacturer duties.
Support periods
How to determine the period, and what justifies a shorter one. The default expectation is five years unless the product's reasonably expected lifetime is shorter.
What a risk assessment should record
The guidance states what is expected to be written down. It does not supply the form — a distinction worth reading carefully if you were hoping for a template.
What it deliberately does not do
There is a structural reason. The Commission cannot write a technical file template that fits both a smart doorbell and a CNC machine. So the regulations enumerate required content in an annex and leave the form to the manufacturer, who alone knows the product.
What to do with it
- Read the examples nearest your product. If you have ever wondered whether your cloud component is in scope, the answer is probably in there.
- Do not treat it as a safe harbour. Non-binding means non-binding. Document your own reasoning in the technical file.
- Do not wait for standards. The guidance's own position is that manufacturers should anticipate requirements from the drafts and build the Annex I evidence regardless. Obligations apply on 11 December 2027 whether or not the standards are published.
Get told when the requirements change
None of the 35 CRA harmonised standards is published yet. When they land — and when deadlines move — we email you. No more than twice a month.