Chapter II - OBLIGATIONS OF ECONOMIC OPERATORS AND PROVISIONS IN RELATION TO FREE AND OPEN-SOURCE SOFTWARE
26

Article 26

Guidance

Regulation (EU) 2024/2847 — published 10 December 2024 · Last reviewed by Kunnus: March 2026

(1)

In order to facilitate implementation and ensure the consistency of such implementation, the Commission shall publish guidance to assist economic operators in applying this Regulation, with a particular focus on facilitating compliance by microenterprises and small and medium-sized enterprises.

(2)

Where it intends to provide guidance as referred to in paragraph 1, the Commission shall address at least the following aspects:

a)

the scope of this Regulation, with a particular focus on remote data processing solutions and free and open-source software;

b)

the application of support periods in relation to particular categories of products with digital elements;

c)

guidance targeted at manufacturers subject to this Regulation that are also subject to Union harmonisation legislation other than this Regulation or to other related Union legal acts;

d)

the concept of substantial modification.

The Commission shall also maintain an easy-to-access list of the delegated and implementing acts adopted pursuant to this Regulation.

(3)

When preparing the guidance pursuant to this Article, the Commission shall consult relevant stakeholders.

CHAPTER III

CONFORMITY OF THE PRODUCT WITH DIGITAL ELEMENTS

European Commission Interpretation

Guidance of 27 July 2026

The EU Commission guidance of 27 July 2026 provides official interpretation notes on this provision. Each section: summary, key takeaways, and what it means for you in practice.

Section 1.1 – 1.2Introduction: legal framework and purpose of the guidance

Chapter 1 situates the document: the CRA is built on the EU's New Legislative Framework; market surveillance and enforcement lie with national authorities. The guidance fulfils the mandate of Article 26(1) — with a particular focus on SMEs —, is not legally binding and does not replace a case-by-case assessment. Only the Court of Justice of the European Union can give an authoritative interpretation of the CRA.

Key takeaways

  • Mandatory topics under Art. 26(2) — and exactly what the document covers: scope (in particular remote data processing and FOSS), support periods, interplay with other EU legislation, and the concept of substantial modification.
  • The guidance complements the Commission's FAQs of 3 December 2025; it follows consultation of the Expert Group on Cybersecurity of Products with Digital Elements and a public consultation (3 March – 13 April 2026).
  • It addresses economic operators AND authorities: market surveillance authorities, notifying authorities and notified bodies are also meant to rely on it for harmonised EU-wide enforcement.
  • The numerous examples are illustrative only — they never replace an assessment of the specific individual case.
  • Further guidance is explicitly envisaged, for example on the CRA's interplay with the AI Act (Regulation 2024/1689) and DORA (Regulation 2022/2554).
  • Background: the CRA follows the New Legislative Framework (Regulation 765/2008, Decision 768/2008/EC); market surveillance follows Regulation 2019/1020. The Commission plans to modernise the NLF via the 'European Product Act'.

In practice

Use the guidance as a basis for argument with auditors, notified bodies and market surveillance — cite the specific section and paragraph number. But do not rely blindly on the examples: always document your own case-by-case assessment, as the guidance is not legally binding. And keep an eye on the announced follow-up guidance (AI Act, DORA) if your products are affected there too.

Section in the guidance overview
Browse all guidance chapters

EU Commission Guidance (C(2026) 5252 final)The guidance reflects the European Commission's interpretation and is not legally binding. An authoritative interpretation of the EU CRA may only be given by the Court of Justice of the European Union.

Related Recitals

(1)

CRA updates by email

Deadlines, official guidance, and myth-busting fact-checks on the Cyber Resilience Act — compact in our newsletter.

View newsletters

This text is reproduced from Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024. It is provided for informational purposes only and does not constitute legal advice. Only the text published in the Official Journal of the European Union is legally binding. Original text on EUR-Lex