Introduction: legal framework and purpose of the guidance
Chapter 1 situates the document: the CRA is built on the EU's New Legislative Framework; market surveillance and enforcement lie with national authorities. The guidance fulfils the mandate of Article 26(1) — with a particular focus on SMEs —, is not legally binding and does not replace a case-by-case assessment. Only the Court of Justice of the European Union can give an authoritative interpretation of the CRA.
Key takeaways
- Mandatory topics under Art. 26(2) — and exactly what the document covers: scope (in particular remote data processing and FOSS), support periods, interplay with other EU legislation, and the concept of substantial modification.
- The guidance complements the Commission's FAQs of 3 December 2025; it follows consultation of the Expert Group on Cybersecurity of Products with Digital Elements and a public consultation (3 March – 13 April 2026).
- It addresses economic operators AND authorities: market surveillance authorities, notifying authorities and notified bodies are also meant to rely on it for harmonised EU-wide enforcement.
- The numerous examples are illustrative only — they never replace an assessment of the specific individual case.
- Further guidance is explicitly envisaged, for example on the CRA's interplay with the AI Act (Regulation 2024/1689) and DORA (Regulation 2022/2554).
- Background: the CRA follows the New Legislative Framework (Regulation 765/2008, Decision 768/2008/EC); market surveillance follows Regulation 2019/1020. The Commission plans to modernise the NLF via the 'European Product Act'.
In practice
Use the guidance as a basis for argument with auditors, notified bodies and market surveillance — cite the specific section and paragraph number. But do not rely blindly on the examples: always document your own case-by-case assessment, as the guidance is not legally binding. And keep an eye on the announced follow-up guidance (AI Act, DORA) if your products are affected there too.
Linked CRA provisions