Public CommentProposedPublic CommentGuidance UpdateProposed Regulation
European Commission publishes draft CRA guidance for feedback (scope/obligations topics affecting Annex I interpretation)
EU Cyber Resilience Act (CRA) — Annex I Baseline (Essential) RequirementsEuropean CommissionEU
Announced
Mar 3, 2026
Description
The European Commission published draft guidance to assist companies in applying the Cyber Resilience Act (Regulation (EU) 2024/2847). Although the guidance does not amend Annex I text, it is directly relevant to Annex I baseline/essential cybersecurity requirements because it clarifies CRA scope and obligations that determine when/how Annex I requirements apply in practice (e.g., treatment of remote data processing solutions, free and open-source software, support periods, and interplay with other EU legislation). The Commission opened a feedback/consultation period running until 31 March 2026, which compliance teams may wish to monitor and/or respond to given potential impacts on conformity approaches and lifecycle/vulnerability-handling expectations tied to Annex I.
Sources
- OfficialCommission publishes for feedback draft guidance to assist companies in applying the Cyber Resilience Act
- OfficialDraft Commission guidance on the Cyber Resilience Act (Have your say initiative page)
- OfficialEU cybersecurity policies (consultation listing shows CRA draft guidance feedback window 03-03-2026 to 31-03-2026)