ISMSJan Kahmen3 min read

The Commission's CRA Guidance: What C(2026) 5252 Settles for Manufacturers

The Commission published its CRA guidance on 27 July 2026. What it settles on scope, substantial modification, support periods and open source.

The Commission's CRA Guidance: What C(2026) 5252 Settles for Manufacturers

On 27 July 2026 the European Commission published its guidance on the application of the Cyber Resilience Act, document C(2026) 5252 with its annex. Article 26 of Regulation (EU) 2024/2847 obliges the Commission to do so, with particular attention to SMEs. The result runs to 84 pages with 67 examples, flowcharts and use cases. The text is not legally binding; only the Court of Justice can interpret EU law authoritatively. In practice it is the working basis for market surveillance authorities, in Germany soon the BSI.

Scope: Websites Out, Cloud Backends In

Plain websites and web applications used exclusively in the browser are not products with digital elements. Downloaded clients, browser extensions, desktop apps and locally installable web apps are.

For remote data processing under Article 3(2), three cumulative conditions apply: the processing happens remotely, the product cannot function without it, and the software was developed by the manufacturer or under its responsibility. An IoT device's own cloud backend is therefore part of the product, including tests and reporting duties. Third-party SaaS services embedded in a product are not part of it but external components subject to the due diligence duty in Article 13(5).

Substantial Modification: A Four-Question Test

Point 110 of the guidance answers when a software update is a substantial modification under Article 3(30) and triggers a new conformity assessment. It asks four questions: Does the update introduce new threat vectors, such as interfaces, communication channels or external dependencies? Does it enable new attack scenarios? Does it change the likelihood of known scenarios? Does it change their impact? Four negative answers, with the assumptions of the risk assessment still valid, mean the change is not substantial under Point 111.

The size of the change is irrelevant. A persistent login that stores tokens is substantial; enabling a function that was already assessed is not. Security updates are exempt in principle, even where they replace an entire library. According to Point 109 the exemption ends where a security update introduces a new external dependency. Compared with the draft, Point 106 narrows the yardstick to adverse effects: changes that do not increase risk are never substantial.

Support Period: Five Years Is the Floor, Not the Default

Point 126 makes clear that the five years in Article 13(8) are a safeguard, not a preset. The period must follow from the expected time in use, determined by user expectations, product type, intended purpose and applicable Union law. The end date must be communicated to the buyer at least as month and year.

Under Point 133 a substantial modification does not automatically reset the period. It is recalculated only where the modification itself affects the expected time in use, for instance through a hardware revision. For software with rolling releases it is sufficient to fix vulnerabilities in the latest version only, provided users can upgrade without additional costs. Staff effort counts as reasonable, new hardware does not.

Open Source: Funding Does Not Decide, Monetisation Does

Free and open source software faces a two-stage test. First, who as maintainer controls development, releases and distribution; individual contributors carry no responsibility. Second, monetisation: software is placed on the market when money is charged for it or its binaries, when the platform monetises other products, when personal data is processed beyond security purposes, or when paid editions condition access on payment. Voluntary donations, grants and sponsorship do not create a commercial product as long as releases are not reserved for donors. Whoever qualifies as an open-source software steward under Article 24 carries reduced duties and cannot be fined.

Testing and Legacy Products

On the testing duty in Annex I Part II the Commission moves away from fixed intervals: what is required is a regular review of whether new threats have overtaken existing tests; without new input no retest is needed. For products placed on the market before 11 December 2027, Article 69(2) is read proportionately: a substantial modification obliges the manufacturer to full CRA conformity only for the modified part, unless the change worsens the security of the whole product.

Conclusion

Manufacturers should build the four-question test into their release process as a fixed step, document the reasoning behind their support period, and include their cloud backend in risk assessment and pentest scope. Fifteen months remain until full application on 11 December 2027.

Our Services