Summary
- Cyber Resilience Act reporting obligations begin on 11 September 2026, ahead of the main product requirements in December 2027.
- Commission guidance covers remote data-processing services, open source software, substantial modifications, support periods, and cybersecurity risk assessments.
- The guidance is non-binding, so manufacturers will still need defensible evidence for decisions that may later be examined by national authorities or courts.
The European Commission has given manufacturers and software suppliers their most detailed account yet of how the Cyber Resilience Act should operate, less than seven weeks before its first reporting duties take effect.
Published on 27 July, the guidance addresses several areas that have remained difficult to apply since the legislation entered into force in December 2024. These include the treatment of remote data-processing services, free and open source software, substantial product modifications, security support periods, vulnerability reporting, and cybersecurity risk assessments.
Although most of the Act’s product-security requirements will not apply until 11 December 2027, manufacturers must begin reporting actively exploited vulnerabilities and severe security incidents from 11 September 2026. The Commission’s implementation guidance therefore arrives against an operational deadline that requires functioning escalation, assessment, and notification processes.
The document contains 67 examples, supported by use cases, flowcharts, and practical explanations intended to help businesses establish whether a product or service falls within scope. The market covered by the Act extends from connected hardware and embedded components to business software, applications, and remote services required for a product to perform its intended function.
Cloud-linked products remain one of the more difficult areas. A connected device may be sold as hardware, while authentication, updates, data processing, and security monitoring depend on a vendor-operated platform. The guidance distinguishes product-related remote services from general-purpose cloud services, but suppliers with layered platform arrangements will still need to examine each dependency and contractual relationship.
Product security becomes an operating responsibility
The Cyber Resilience Act places duties across a product’s supported life rather than treating security as a pre-market approval exercise. Manufacturers must assess risk, address vulnerabilities, provide security updates, maintain technical documentation, and respond when exploitation or serious incidents occur. Importers and distributors also acquire obligations where products placed on the European market do not meet the required standards.
Those duties connect engineering, product security, legal, incident response, customer support, and executive risk management. A newly exploited vulnerability may require technical containment, a regulatory notification, customer communication, remediation commitments, and the preservation of evidence for market-surveillance authorities, often while the scope of exposure is still developing.
Support periods require similarly durable decisions. Vendors will need to show how expected product use, dependency support, hardware limitations, replacement cycles, and customer reliance informed the period during which security fixes will be supplied. Products embedded in healthcare, manufacturing, telecoms, transport, or public infrastructure may remain operational for much longer than the supplier’s preferred commercial cycle.
The guidance on substantial modifications also affects systems integrators and enterprise customers that customise or repurpose products after purchase. Where a change alters intended purpose or materially affects compliance, regulatory responsibility may move towards the organisation making it. Configuration, integration, and product modification will need to be distinguished through technical records rather than informal assumptions.
Commercial use of open source components receives further clarification. Individuals and non-commercial contributors are not treated in the same way as manufacturers placing products on the market, but a business incorporating community-maintained code into a commercial product retains responsibility for the resulting system.
Because the guidance is non-binding, organisations cannot rely on it as an automatic defence. National market-surveillance authorities and courts retain responsibility for applying the legislation, while the Commission may publish further material as implementation develops.
Manufacturers now need reporting processes capable of recognising an actively exploited vulnerability, establishing whether the Act applies, assembling reliable facts, and making a notification without allowing uncertain early assessments to become an inaccurate regulatory record. September’s deadline places those capabilities within current incident operations rather than a future compliance programme.




