18 Sep 2026 Cybersecurity Industry Recommendations on the CRA Guidance
Cybersecurity Industry Recommendations on the CRA Guidance
Strengthening legal certainty and ensuring consistent implementation of Regulation (EU) 2024/2847
Executive Summary
Industry welcomes the Commission’s work on the Guidance on the application of the Cyber Resilience Act (CRA). The Guidance is essential to support manufacturers, importers, distributors, conformity assessment bodies and market surveillance authorities in the practical implementation of Regulation (EU) 2024/2847.
The CRA Guidance is formally non-binding. In practice, however, it will become the principal reference used by economic operators and authorities to interpret the Regulation. Its wording will therefore influence conformity assessment, enforcement expectations, contractual requirements and procurement practices across the Union. For that reason, the Guidance must remain closely aligned with the legislative text and must avoid creating de facto obligations that were not adopted by the co-legislators.
This document aims at improving legal certainty, preserving the CRA risk-based and technology-neutral approach, and ensuring that the Guidance remains practically workable for all Products with Digital Elements (PwDE), particularly software products, open-source ecosystems, complex supply chains and legacy technologies. A key element of this workability is the recognition of existing security evidence from established industry schemes such as CC, ISO 21434, EMVCo, FIPS, SESIP, PSA Certified. This would help mitigate assessment bottlenecks and safeguard market resilience during the CRA transition.
This position paper restructures the outstanding recommendations around five policy themes:
- Software products and software systems
- Free and Open-Source Software and Open-Source Software Stewards
- Substantial modifications
- A proportionate approach for complex and legacy environments

