Orrick, Herrington & Sutcliffe·CYBERSECURITY

EU Commission Issues Key Guidance on Cyber Resilience Act

The European Commission has published long-awaited guidance on the Cyber Resilience Act, clarifying its scope, the treatment of open-source software, and reporting duties for manufacturers of products with digital elements.

The European Commission on July 27, 2026, published guidance interpreting the Cyber Resilience Act (CRA), a sweeping regulation for products with digital elements sold in the EU. The non-binding guidance clarifies crucial ambiguities affecting a vast range of manufacturers. Key interpretations address the scope of covered products, the specific conditions under which free and open-source software (FOSS) falls under the Act, and what constitutes a "substantial modification" that triggers new compliance assessments. The guidance also confirms that reporting obligations for actively exploited vulnerabilities and severe incidents begin as early as September 11, 2026, well before most other CRA provisions take effect in late 2027.

Manufacturers of connected hardware and software should immediately review the guidance to determine if their products are in scope and prepare to meet the imminent reporting deadlines. They must also assess how the clarifications on FOSS integration, product support lifecycles (a minimum of five years is the default), and risk assessments impact their development and compliance roadmaps. Further Commission guidance on the CRA's interaction with the AI Act and DORA is expected.

cyber-resilience-acteuropean-commissioncybersecurityproduct-liabilityopen-source-softwaresoftwaretechnology-regulation
Read the original firm alert → Friday, September 11, 2026

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.