Free regulatory intelligence — powered by Certivo
Public CommentProposedPublic CommentGuidance Update

European Commission opens feedback period on draft CRA guidance (scope/obligations) relevant to Annex IV product classification and compliance

EU Cyber Resilience Act (CRA) - Critical Products Annex IVEuropean Commission (DG CONNECT)EU
Announced

Mar 3, 2026

Description

The European Commission published a draft guidance package to assist companies in applying the Cyber Resilience Act (CRA) and opened a feedback period. Although this is not an amendment to Annex IV, the draft guidance is directly relevant to Annex IV ‘critical products’ compliance because it addresses CRA scope and obligations (including topics such as remote data processing solutions, free and open-source software, support periods, and interaction with other EU legislation), which can affect classification and compliance planning for products that may fall under Annex IV and therefore require stricter conformity assessment routes.

Get compliance alerts for EU Cyber Resilience Act (CRA) - Critical Products Annex IV

Certivo tracks regulatory changes and automates compliance workflows for your products.

Start Free Trial
European Commission opens feedback period on draft CRA guidance (scope/obligations) relevant to Annex IV product classification and compliance | Certivo Regulations