EU publishes answers to frequently asked questions on the CRA

EU publishes answers to frequently asked questions on the CRA

The European Commission services have published updated technical FAQs to help stakeholders navigate implementation of the Cyber Resilience Act. They are a useful starting point, but do not replace Regulation (EU) 2024/2847 or product-specific assessment.

What the FAQs cover

The Cyber Resilience Act, Regulation (EU) 2024/2847, establishes horizontal cybersecurity requirements for products with digital elements made available on the Union market, subject to its scope and exclusions.

The Regulation entered into force on 10 December 2024. Its reporting obligations apply from 11 September 2026, while it generally applies from 11 December 2027, subject to the separate application date for Article 35.

The Commission services published their technical implementation FAQs on 3 December 2025. The current document is version 1.3, dated 1 July 2026, and is available from the Commission's FAQ publication page.

The FAQs are organised around seven main areas:

  • scope
  • interplay with other legislation
  • important and critical products
  • manufacturers' obligations
  • reporting obligations
  • conformity assessment
  • the transition period

They provide practical navigation for questions such as identifying products in scope, considering the relationship with other EU legislation, carrying out risk assessment, handling vulnerabilities, assessing integrated components, setting support periods, meeting reporting obligations and approaching conformity assessment.

Their legal status

The FAQs are preliminary and non-exhaustive. They are intended to be a living document and may be updated as implementation develops.

Crucially, they are prepared by Commission services and do not represent the European Commission's official position. They do not add legal requirements, replace the Regulation or prejudge an authoritative interpretation of Union law by the Court of Justice of the European Union.

Examples in the document can help explain how the Commission services currently approach an issue. They cannot establish that a particular product is in scope, compliant or appropriately assessed.

Practical points for manufacturers

Several FAQ topics are especially relevant when planning implementation work.

The FAQs explain the manufacturer's risk-based approach to essential cybersecurity requirements and vulnerability handling. They discuss whether every identified vulnerability necessarily requires a patch, while making clear that any response remains tied to the Regulation, the product's risk and the manufacturer's vulnerability-handling duties.

They also address due diligence for integrated components, including components without CE marking and free and open-source components. This does not transfer responsibility for the final product: the manufacturer remains responsible for the product with digital elements.

On support periods, the FAQs discuss the relationship between the five-year baseline and a product's expected use. The applicable period requires a product-specific assessment under the criteria in the Regulation; it is not automatically five years in every case.

Guidance has developed since the first FAQ release

When version 1.0 of the FAQs was issued, Commission guidance under Article 26 was still in preparation. The Commission has since published a first set of practical guidance to support timely implementation on 27 July 2026.

The Commission's implementation overview provides the current milestones and links to related material. The FAQs should therefore be read alongside the Regulation and subsequent official guidance, rather than as the only source of implementation information.

A verification workflow

Use the FAQs to identify the implementation question relevant to the product and role involved. Then check the answer against the current FAQ version, the text of Regulation (EU) 2024/2847 and later official Commission guidance.

Finally, assess the specific product, its digital elements, its intended use and the relevant obligations. This is an editorial workflow for checking sources; it is not legal advice or a conformity assessment.

Need help implementing cyber regulation?

Talk to Secuvi →