Free regulatory intelligence — powered by Certivo
Public CommentProposedPublic CommentGuidance UpdateProposed Regulation

European Commission publishes draft CRA guidance for feedback (scope and application topics affecting Annex III important products)

EU Cyber Resilience Act (Regulation (EU) 2024/2847) — Annex III Important Products (Additional Requirements / classification implications)European CommissionEU
Announced

Mar 3, 2026

Description

The European Commission published draft guidance for feedback to assist companies applying the Cyber Resilience Act (CRA). The draft guidance addresses scope and application issues (including remote data processing solutions, free and open-source software, support periods, and interplay with other EU legislation) that can directly affect whether a product is in-scope and how CRA obligations apply. These clarifications can materially impact Annex III ‘important products’ determinations and the resulting conformity assessment route (e.g., whether third-party assessment pathways apply). The Commission opened a feedback period (consultation deadline stated as 31 March on the Commission news page).

Get compliance alerts for EU Cyber Resilience Act (Regulation (EU) 2024/2847) — Annex III Important Products (Additional Requirements / classification implications)

Certivo tracks regulatory changes and automates compliance workflows for your products.

Start Free Trial