Draft Commission guidance on the Cyber Resilience Act
150 submissions from 144 organizations told the European Commission what they think about this file. Here is what each of them said, in their own words.
The Commission lists 252 submissions on this file. Shown here: the 150 from organizations. Not shown, by design: submissions from private individuals, which we never publish, and anything filed since our last weekly refresh.
Who showed up
126 submissions from industry — companies and their trade associations — against 15 from civil society: NGOs, consumer organizations, environmental groups and trade unions. That is 8.4 industry submissions for every one from civil society.
Industry 126Civil society 15Public authorities, academia, other 9
Groupings use the respondent type each organization selected when filing. Counting submissions, not organizations — a body that filed twice is counted twice.
What the room declares
65 of 144
in the EU Register
326
full-time lobbying staff
€53.3M+
declared costs a year
222
EP accreditations declared
Self-declared to the EU Transparency Register (snapshot 30 Aug 2026). The cost figure sums band floors, so the true total is higher.
The file, right now
The consultation closed on 13 Apr 2026 — it ran from 3 Mar 2026.
Policy area
Digital & tech (DG CNECT)
Where it stands
Awaiting adoption
How it got here
Dec draft13 Apr 2026
Also on the Commission’s pipeline for this file, with no date recorded: Communication.
Although ESYS fully supports both the substance and the ambition of Regulation (EU) 2024/2847, the current timeline reveals structural implementation gaps liable to compromise the effectiveness and coherence of the Regulation.
The document addresses concerns about overlap between the proposed Cyber Resilience Act (CRA) and the existing Digital Operational Resilience Act (DORA) in the financial sector, urging clearer alignment to avoid duplication and regulatory fragmentation.
SUSE welcomes the opportunity to provide feedback on the European Commissions Draft Guidance on the Cyber Resilience Act (CRA). While we appreciate the Commissions efforts to provide early guidance, additional clarity is needed to ensure consistent and proportionate implementation.
GitHub appreciates the opportunity to provide feedback to the draft Guidance on the application of the CRA. We believe this guidance, along with the already published FAQ and other publications from the Communication, greatly improves the readability and applicability of the CRA for FOSS developers and users of FOSS in various roles.
Article 100 should be amended so that it is not the Commission but the European Council that shall verify the risk posed by that country and that adopts the measures provided for in Articles 101 and 102 of the proposal.
We wish to thank the Commission for producing guidance that includes examples of real-world scenarios. We have chosen to focus our feedback on questions from the Scope section. Due to the value provided by the examples, we do request that additional examples of non-compliant scenarios be included.
The Apache Software Foundation (the ASF) compliments the commission on its draft guidance. We welcome the opportunity to respond in this public consultation. The guidance provides the software industry in general and the open source ecosystem with the much needed practical examples.
RATP welcomes the Commission’s initiatives to strengthen the cybersecurity of connected products. With the aim of ensuring optimal functioning of all systems and subsystems, minimising operational impacts in a constrained rail technical environment, it should be possible for the implementation of risk mitigation measures ‘by other means’ within complex systems (section 2.5) to be shared between the customer and the…
Filed in French · English published by the European Commission
On behalf of the Open Regulatory Compliance Working Group, we would like to express our gratitude for the opportunity to provide feedback on the draft guidance for the Cyber Resilience Act (CRA). We appreciate the significant effort and work the Commission has put into building this comprehensive document.
Response to the Draft Commission Guidance on the Implementation of the Cyber Resilience Act Eclipse Foundation welcomes the opportunity to provide feedback on the draft guidance supporting the implementation of the Cyber Resilience Act and would like to thank the European Commission for the substantial work already undertaken.
We appreciate the opportunity to provide feedback on the Commissions draft Guidance on the Cyber Resilience Act (Regulation (EU) 2024/2847). We support the Commissions mission to raise the cybersecurity posture of the products made available in the EU and EEA to protect citizens and Member States from threats against the confidentiality, integrity, and availability of information.
We welcome the opportunity to provide our feedback on the draft Commission guidance on the application of the Cyber Resilience Act (CRA). We strongly support the overarching goal of enhancing the cybersecurity and resilience of products with digital elements across the European market.
Electronic Theatre Controls, Inc. (ETC) appreciates the opportunity to comment on the Commissions draft horizontal guidance concerning the application of the Cyber Resilience Act. ETC is a United Statesbased manufacturer of luminaires and power and control systems used in professional theatrical, live events, entertainment, commercial, and architectural environments worldwide.
WindEurope welcomes the opportunity to provide feedback on the draft implementation guidance of the Cyber Resilience Act. We recommend that the guidance better reflect the reality of complex industrial systems, such as wind energy installations, which rely on a set of critical system functionalities spanning multiple digital components and are deployed as integrated systems with long operational lifetimes rather…
Our feedback to the draft CRA guidance outlines several improvements regarding the interpretation of specific requirements in context of European maritime sector and their relationship to tailor-made products and complex, integrated vessel installations.
EGDF underlines that it is highly important for the Commission to ensure that the guidance document ensures a well-balanced implementation of the regulation. In particular, the Commission should: 1. Risk-based approach on the scope of stand-alone software and device a.
The German Railway Industry Association (VDB) welcomes the oportunity to provide feedback on the Draft Commission guidance on the Cyber Resilience Act. VDB speaks for the German rail industry. It combines the interests of its more than 250 member companies, organises and moderates a consensus, gets involved with specific concerns.
We would like to thank the Commission for the opportunity to comment on the Draft Guidance on the Cyber Resilience Act. After reviewing the current draft, we believe several points would benefit from additional clarification in order to support consistent implementation across the industry. 1.
The clarifications provided in the draft guidance in support of the Cyber Resilience Act (CRA) are most welcome. Nevertheless, several important amendments are required to ensure an effective CRA that works in practice. To that end, please see DIGITALEUROPE's HYS comment template attached.
ARGE - The European Federation of Locks and Building Hardware Manufacturers welcomes the oportunity to provide feedback on the Draft Commission guidance on the Cyber Resilience Act. Details are given in the attached document 'Template for HYS - CRA guidance - feedback ARGE.xlsx'.
We welcome the opportunity to provide feedback on the European Commissions (Commission) draft guidance on the EU Cyber Resilience Act (CRA) published on 3 March 2026 (the Draft Guidance). In this submission, we urge the Commission to take further steps to clarify the interplay between the CRA and NIS2 by preventing dual regulation for organisations operating Remote Data Processing Solutions (RDPS), that are already…
Schneider Electric welcomes the publication of the draft CRA Guidance and the opportunity to provide feedback. The draft provides valuable clarifications and represents a positive step toward more practical implementation of the Regulation, particularly for complex industrial, OT, software-enabled, and distributed products.
Orgalim represents Europe`s technology industries at EU level: innovative companies across the mechanical engineering, electrical and electronics, ICT and metal technology sectors that develop and manufacture the products, systems and services that enable a prosperous and sustainable future. Orgalim welcomes the opportunity to comment on the draft Cyber Resilience Act (CRA) guidance.
Hikvision welcomes the opportunity to contribute to the public consultation on the Draft Commission guidance on the Cyber Resilience Act. As a world-leading security product and solution provider, Hikvision is deeply committed to fostering a secure digital environment and to providing customers with secure and trusted technology.
Please find attached SPECTARIS' feedback on the draft Commission guidance on the Cyber Resilience Act. SPECTARIS is the German Industry Association for Optics, Photonics, Analytical, and Medical Technology, headquartered in Berlin. The association represents approximately 400 German companies, most of which are export-oriented and medium-sized.
Manta Marine Technologies (Sweden) presents the attached document containing the consolidated feedback from the perspective of European solutions providers to the international maritime industry. We appreciate the opportunity to comment on the draft Commission guidance on the Cyber Resilience Act and trust that our observations will support its effective and practical implementation.
Please find attached feedback from: Everllence, branch of Everllence SE, Germany Classification Department Teglholmsgade 41 2450 Copenhagen SV, Denmark. www.everllence.com. Kind regards Vasilij [name removed] (Mr.) Member of SEA Europe Ad hoc CRA Expert Group Senior Classification Engineer
Rockwell Automation supports the Cyber Resilience Act's objectives but identifies critical implementation challenges in Article 2(6)'s spare parts exemption. A strict interpretation threatens the maintainability of long-lifecycle industrial systems lawfully placed on the market before full CRA application.
Open-Xchange, as the leading European open-source software company in the email and DNS space and the service provider of choice for some of the largest Internet access providers in Europe, would like to thank the Commission for the opportunity to participate in its consultation on the guidance on how to apply the Cyber Resilience Act (CRA).
The Cyber Security Platform (CSP) is an Austrian public-private partnership founded in 2015 as part of the Austrian Strategy for Cybersecurity (ÖSCS), counting 500+ security experts as members. The CSP supports the Cyber Security Steering Group (CSS) in improving cybersecurity in Austria below the political and above the technical level, through networked cooperation between actors from administration, business, and…
The European Energy Information Sharing and Analysis Centre (EE-ISAC) welcomes the opportunity to contribute to the European Commissions guidance on the implementation of Regulation (EU) 2024/2847, stressing that the effectiveness of the Cyber Resilience Act (CRA) depends on its alignment with the operational realities of critical energy infrastructure.
ITI welcomes the publication of the draft Cyber Resilience Act (CRA) guidance, as it has the potential to serve as a key tool in clarifying how core provisions of the CRA should be interpreted and implemented by our members.
The draft guidance on the Cyber Resilience Act addresses key aspects of implementation but lacks the level of operational clarity needed for consistent and scalable application in practice. In several areas, the current reliance on qualitative criteria creates uncertainty for manufacturers.
Verisure strongly supports the objectives of the Cyber Resilience Act (CRA) and the ambition to strengthen cybersecurity across the EU. However, important implementation gaps remain that risk undermining its effective and coherent application. In particular, key elements required for compliance with the reporting obligations expected to apply from September 2026 are not yet in place.
We do not consider universities, as institutions of research and education, to be addressees of product legislation within the meaning of the Cyber Resilience Act (CRA). Research results generated in the university context including results arising from joint research and development projects with companies such as research software, opensource artefacts, demonstrators, and projectspecific platforms, do not, by…
EFESME is the European Federation for Elevator Small and Medium-sized Enterprises, and it is active at European and international level to support lift SMEs in their daily work and activities. EFESME represents sixteen members in fourteen Member States, plus one observer.
Dassault Systèmes welcomes the European Commission's initiative to open a public consultation on the draft guidelines of the Cyber Resilience Act. This process reflects a genuine commitment to constructive dialogue on the implementation of a regulation with significant and concrete implications for Europe's entire digital ecosystem.
The European Savings and Retail Banking Group fully supports the objectives of the Cyber Resilience Act (CRA), especially its focus on ensuring the cybersecurity of products with digital elements. Nonetheless, as reflected in our feedback attached, there are significant overlaps between the CRA and the Digital Operational Resilience Act (DORA), which presents serious implementation challenges for the financial…
Decathlon welcomes the draft guidance on the Cyber Resilience Act and the opportunity to provide feedback. Our feedback emphasizes the need for objective financial safe harbors for open-source projects, clearer boundaries for "Remote Data Processing Solutions" (RDPS) to avoid overlap with NIS 2, and adjustments to the definitions of "substantial modification" and "intended purpose" to prevent an excessive regulatory…
CLEPA welcomes the European Commissions initiative to develop practical guidance on the Cyber Resilience Act and encourages an approach that reflects the realities of complex and interconnected supply chains, such as those in the automotive sector.
SolarPower Europe feedback on the CRA SolarPower Europe welcomes the Commissions draft guidance on the application of the Cyber Resilience Act (CRA). Clear, proportionate and operational guidance is essential to ensure consistent implementation across complex digital value chains, including inverterbased technologies that are critical to the European electricity system.
NLnet Labs and Internet Systems Consortium --two non-profit organizations employing maintainers for long-lived open source projects in the public interest-- welcome this opportunity to provide feedback to the Draft Commission guidance on the Cyber Resilience Act. The attached document contains our joint response.
We would like to thank the European Commission for giving us the opportunity to comment on the draft guidelines for the Cyber Resilience Act. The legal and technical clarifications contained in the guidelines are essential for the telecoms sector to ensure the effective, consistent and harmonised implementation of EU law.
Thank you for the opportunity to provide feedback on the Draft Commission Guidance on the Cyber Resilience Act (CRA). As a leading European provider of intelligent metering solutions, Kamstrup welcomes the Commissions efforts to bring clarity to the implementation of the CRA and to support a harmonised, secure, and futureproof digital product landscape across the EU.
Damen Shipyards welcomes the opportunity to provide feedback on the Draft Commission Guidance on the Cyber Resilience Act. While this submission is made by Damen Shipyards in its own name, the observations reflected in the attached document have been developed through joint work within the SEA Europe Digitalisation working group, in which maritime manufacturers and shipyards have collectively assessed the practical…
This feedback document from the Charter of Trust responds to the European Commission's public consultation on the CRA draft guidance document. Given the scope and importance of the Cyber Resilience Act for European manufacturers, software developers and conformity assessment bodies acting as notified bodies, the Charter of Trust members have collected a wide range of questions related to the concrete interpretation…
SEMI Europe, the industry association representing 3,500+ companies globally and 300+ companies in Europe from the entire semiconductor supply chain, provides extensive feedback on the "Draft Commission guidance on the Cyber Resilience Act," please refer to the annex document attached for a complete overview.
Please find attached the response from AFME, representing the views of the globally significant credit institutions. We would be happy to discuss further our comments, particularly those relating to the Mobile Banking Application, where we welcome the recent engagement with industry, and the clarity on specific functions, but think the references to API architecture need adjusted.
Meta Platforms Ireland Limited ("MPIL") welcomes the opportunity to respond to the European Commission's (ECs) public consultation on the draft Guidance on the Cyber Resilience Act ("CRA"). MPIL supports the ECs objective of clarifying how the CRA should be interpreted and implemented, and we offer detailed feedback in the areas where, in our view, the guidance would benefit from refinement to ensure legal…
APPLiA represents household appliance industry in Europe. We found the CRA Guidelines already quite good. However, we would like to use this opportunity to share some comments collected from members aiming at some improvements and clarifications to be further provided in these useful guidelines. We are opened for further discussions or exchange on those elements to finalise the CRA Guidelines soon.
UNIFE, representing the European Rail Supply industry, welcomes the presence of a much needed official guidance document on the CRA, which complements and corroborate the guidance developed within the rail sector. The comments provided in the table propose some further clarifications and examples to make the guidance more easily applicable.
We welcome the opportunity to provide feedback on the draft Commission guidance on the Cyber Resilience Act (CRA). We appreciate and support this initiative as an important means of clarifying the existing implementation questions and contributing to a consistent and effective application of the CRA.
S-group welcomes the opportunity to provide feedback on the draft Commission guidance on the application of the Cyber Resilience Act (CRA). We support the objectives of the CRA in enhancing cybersecurity and consider the guidance essential for ensuring a consistent interpretation and application of the Regulation across the single market. 1.
Could you please specify in the guidance the following example: Company A has developed a FOSS tool for the purpose of providing a service to Companies B and C that are paying for the development and maintenance of the FOSS tool and also for the service results generated by using this tool.
MEDEF welcomes the European Commissions initiative to provide guidance on the implementation of the Cyber Resilience Act through operational guidelines. This effort is both timely and necessary, as it contributes to enhancing legal certainty, facilitating a harmonised application of the Regulation, and better aligning its requirements with industrial, technological and sector-specific realities.
As a small and medium-sized enterprise (SME) navigating the evolving digital landscape, we welcome the Commissions efforts to provide clarity on the CRA. We are an innovation consulting agency, covering software development, policy analysis, media and communication within Horizon Europe and other R&I programmes, but we also deliver professional services to commercial clients.
The clarifications provided in the draft guidance on the application of the Cyber Resilience Act (CRA) are very helpful. However, Cisco still has a number of questions and comments about key parts of the guidance, especially on substantial modifications, support periods and remote data processing solutions. We believe important amendments are necessary to ensure an effective CRA application.
S.4.3: System configuration using limited capability language does not change the cybersecurity risk position of the entire system. Using a limited capability language for PLC configuration or programming does not change the cybersecurity risk position of the entire system when the capabilities of the language do not allow it to affect the original products compliance with the essential cybersecurity requirements or…
Please find attached our detailed submission setting out concrete observations and recommendations regarding this initiative. We broadly support the objectives pursued and welcome the opportunity for stakeholder input at this stage.
EUnited is the European association representing manufacturers of municipal equipment, professional cleaning machines and vehicle wash systems. We welcome the publication of the CRA guidance and the opportunity to provide feedback.
The Community of European Railway and Infrastructure Companies (CER) welcomes the Commission's Draft guidance on the Cyber Resilience Act (CRA). Please find attached two comments on spare parts related to the very long life cycles in the railway sector. CER remains at your disposal to further discuss this topic.
Knorr-Bremse welcomes the European Commissions initiative to prepare a Communication providing practical guidance on the application of the Cyber Resilience Act (CRA). Such guidance is essential to support manufacturers, developers, and other stakeholders in understanding and complying with their obligations under the Regulation, while promoting a consistent approach across the Union.
𝗦𝘂𝗯𝘀𝘁𝗮𝗻𝘁𝗶𝗮𝗹 𝗠𝗼𝗱𝗶𝗳𝗶𝗰𝗮𝘁𝗶𝗼𝗻𝘀 𝗥𝗲𝘀𝘁𝗮𝗿𝘁 𝗦𝘂𝗽𝗽𝗼𝗿𝘁 𝗣𝗲𝗿𝗶𝗼𝗱 §107 states that "making the 𝘀𝘂𝗯𝘀𝘁𝗮𝗻𝘁𝗶𝗮𝗹𝗹𝘆 𝗺𝗼𝗱𝗶𝗳𝗶𝗲𝗱 𝗽𝗿𝗼𝗱𝘂𝗰𝘁 product available on the market constitutes a 𝗻𝗲𝘄 𝗽𝗹𝗮𝗰𝗶𝗻𝗴 𝗼𝗻 𝘁𝗵𝗲 𝗺𝗮𝗿𝗸𝗲𝘁". §120 requires manufacturers to determine the support period according to Article 13.8, whenever a product is placed on the market.
Proofpoint, Inc., along with its subsidiary Hornetsecurity Group, a leading pan-European provider of AI-powered Microsoft 365 security, data protection, compliance and security awareness solutions, welcomes the opportunity to provide comments to the draft Commission guidance on the application of the Cyber Resilience Act in the attached file.
HOPE welcomes the publication of the draft Commission guidance on the application of the Cyber Resilience Act (CRA) as an indispensable reference document addressed to economic operators and supporting the activities of market surveillance authorities, notifying authorities and notified bodies.
Microchip Technology welcomes the Commission's draft guidance on the application of the Cyber Resilience Act (CRA). The guidance provides valuable clarification on many aspects of the regulation and will assist manufacturers in achieving compliance.
We welcome the opportunity to provide feedback on the draft Commission guidance on the application of the Cyber Resilience Act (CRA). The guidance is an important instrument to support consistent interpretation and practical implementation of the Regulation across the internal market. Most of our feedback is already provided trough other associations to which we have contributed.
The French banking sector welcomes the clarifications provided by the European Commission for the banking sector. However, the banking sector wishes to draw the Commissions attention to the persistent risks of regulatory overlap between the CRA, Regulation (EU) 2022/2554 on digital operational resilience in the financial sector (DORA), and other sector-specific regulations (PSD2 , PSR , eIDAS ).
AIOTI welcomes the move to regulate for greater cybersecurity. Our members are committed to providing security in our products, we welcome steps to create maximum trust among users and consumers of the safety, security, and resilience of their digital products. The draft guidance represents the most detailed interpretative resource to date for CRA implementation.
On behalf of Panasonic Europe, we appreciate the opportunity to review and provide feedback on the draft Commission guidance regarding the application of the Cyber Resilience Act (CRA). We highly appreciate the Commissions efforts to provide clarity on this complex and landmark regulation.
Dear Madam or Sir, Please find our feedback on the draft of the Commission guidance on the Cyber Resilience Act attached in the provided template file. We provide this feedback on behalf of the members of the Open Source Automation Development Lab (OSADL) eG. OSADL is a co-operative registered in Germany with over 100 member companies from various industries worldwide whose products fall under the CRA.
Broadcom thanks the Commission for the opportunity to provide comments on this guidance. The EU Cyber Resilience Act (CRA) is groundbreaking legislation that significantly changes the way manufacturers bring technologies to the EU market. Its impact cannot be overestimated for organisations like Broadcom that have a high degree of technological complexity in their product lines.
The IoT Security Working Group of the Japan Network Security Association conducts research and studies on security-related matters for IoT devices, publishes reports, and shares feedback like this. We aim to provide knowledge that can contribute to improving IoT cybersecurity.
Robert Juliat is the oldest French manufacturer working in the stage lighting industry. We take very seriously the CRA and we with other european manufacturers from the the all entertainment industry we are working on solutions that would not only cover the basics CRA recommendations but far beyond . - CRA directives, recommendations et guidances are not easy to follow and understand.
TIC Council, the global trade association representing the Testing, Inspection and Certification (TIC) industry, shares the attached feedback. Our members will become future CRA Notified Bodies, and we are happy to answer any follow-up questions or provide further clarification if needed.
BusinessEurope welcomes the opportunity to provide feedback on the Draft Guidance for the implementation of the Cyber Resilience Act (CRA). We would like to reiterate and highlight two key points previously raised in our position paper "Simplifying the EU digital rulebook", which remain highly relevant in the context of the current draft guidance.
Thank you very much for preparing and publishing the guidance on the Cyber Resilience Act (CRA). We believe that this guidance will make a significant contribution to promoting product security initiatives by deepening the understanding of the intent of the CRA and by providing clearer direction for its implementation.
Efforts to improve the overall cyber security in the EU is always welcome. CRA is a very complicated regulation and the concern raises from the fact that many prerequisites of it's implementation are not finalized to be able to determine what exactly are the requirements and paths forward e.g. harmonized standards, identification of national notified bodies.
INTRODUCTORY STATEMENT - SUPPLEMENTAL SUBMISSION DigiCert, Inc. welcomes the opportunity to submit supplemental comments on the European Commission's Draft Guidance on the application of Regulation (EU) 2024/2847 (the Cyber Resilience Act).
VNO-NCW and MKB-Nederland welcome the opportunity to contribute to the public consultation on the Draft Commission guidance on the Cyber Resilience Act. As the leading employers' organisations in the Netherlands, we represent the interests of both large companies and small and medium-sized enterprises across all sectors of the Dutch economy.
Nedap N.V. is a Dutch technology company that develops and manufactures connected hardware and software products across multiple professional markets, including livestock management, retail, healthcare, and security. Our products are sold exclusively to professional operators and are each independently CE-marked.
Opinion on the Cyber Resilience Act (CRA) from the point of view of IT user companies VOICE Bundesverband der IT-wender e.V. expressly supports the Cyber Resilience Act as a key building block for a uniformly high level of cybersecurity in the EU. The approach of harmonising safety requirements for digital products is correct and necessary.
Filed in German · English published by the European Commission
As the Dutch Public Employment Service (UWV) we would like to point out that when software is protected in such a way that it's impossible to make adaptions by third-parties, the mobility and independence of people with disabilities can be at risk. Software adaptations are currently being made so that cars and other tools using software can be used by people with disablities, including clients of UWV.
NCC Group (trading as Fox-IT in the Netherlands) is a leading pan-European cybersecurity company. With over 25 years experience of delivering digital resilience services, we protect many of the digital products and systems that are used daily by European Union (EU) citizens.
The CRACY consortium welcomes the publication of the Draft CRA Guidance and recognises the European Commission's efforts to make the Cyber Resilience Act more accessible in practice. Further guidance is genuinely needed, and this draft represents a useful step in the right direction. That said, we believe several important gaps remain to be addressed.
JEMA is submitting comments on the European Commissions draft guidance on the Cyber Resilience Act (CRA) from the perspective of Japanese industry. Industrial devices have practical characteristics that differ from those of typical digital products, including long lifecycles, modular system configurations, and reliance on repair and spare parts throughout their operational life.
This question concerns railway rolling stock projects with very long lead times between contract signing and entry into service. In several cases, contracts for new trains were concluded before the Cyber Resilience Act was adopted, while delivery and placing on the market will occur after December 2027. A train constitutes a complex system composed of multiple products with digital elements.
The Open Source Security Foundation (OpenSSF) welcomes the European Commissions draft Guidance on the application of Regulation (EU) 2024/2847 (Cyber Resilience Act) and appreciates the opportunity to contribute to this consultation.
From AMETIC, it is considered that the current draft would benefit from targeted improvements to enhance clarity, proportionality, and practical applicability. In particular, simplifying certain elements (such as timelines or non-essential notes not aligned with the CRA) would help avoid unnecessary complexity.
EUROMOT, the European Association of Internal Combustion Engine and Alternative Powertrain Manufacturers, representing the key manufacturers of internal combustion engines and alternative powertrains installed in industrial non-road mobile machinery, marine and stationary applications that are operating in Europe and worldwide. Please find our feedback in the attached document.
DATEV welcomes the draft guidance published by the European Commission regarding the interpretation of the Cyber Resilience Act (CRA). In particular, the clarification that standalone software is considered placed on the market when it is first commercially made available in the EU provides much-needed legal certainty.
Associazione Italiana Internet Provider (AIIP) is the oldest and largest association of ICT operators in Italy and has been representing for 30 years more than 60 Italian SME operators, who have been and still are committed to create an open, distributed, and independent telecom network, including by setting up colocation data centres and offering and/or using them to provide housing, hosting, and cloud and edge…
CECIMO supports the objectives of the Cyber Resilience Act in enhancing cybersecurity across industrial products, while highlighting the need for a proportionate, risk-based, and industry-adapted implementation. The current guidance raises several concerns for manufacturers of machinery and industrial systems, particularly due to the broad allocation of responsibilities.
We thank the Commission for giving us the opportunity to comment these guidelines. In this frame we have one remark when it comes to the harmonised standards conformity assessment procedure : the regulation does not give a potential transition period when economic operators have used the RED harmonized standards (EN 18031 series).
The OpenMined Foundation welcomes the draft guidance as a useful and proportionate starting point. We particularly welcome the recognition that obligations for open-source software stewards should depend on the concrete type of support they provide. The examples already included are helpful.
We thank the Commission for the chance to provide feeedback on this document. We have one small suggestion for an inclusion that could help manufacturers with the rising cost of compliance. The regulation does not give a transition period for switching between the RED cybersecurity standards and the new standards created under the CRA.
All Digital welcomes the Cyber Resilience Act as a key step towards strengthening Europe's digital security and resilience. Based on our work with a wide network of organisations and digital competence centres across Europe, we emphasise that cybersecurity must be approached not only as a technical issue, but also as a skills and inclusion challenge.
Reference: Draft Guidance Chapter 4.2, points 9194 Article 2(6) of the Cyber Resilience Act (CRA) establishes that spare parts intended to replace identical components and manufactured according to the same specifications are not subject to the CRA.
The guidance needs to define a clear threshold test for "necessary for the product to perform its functions" with worked examples across at least three product archetypes (fully offline, optionally connected, mandatorily connected). Without this, market surveillance enforcement will be arbitrary.
The German Banking Industry Committee fully recognizes that the Cyber Resilience Act will enhance cybersecurity standards of products that contain a digital component, requiring manufacturers and retailers to ensure cybersecurity throughout the lifecycle of their products from 2027 onward. The Commission guidance can help better understand the CRA requirements.
As a producer of industrial telemetry solutions (PLC drivers) and remote data processing services based in Poland, Inventia Sp. z o.o. appreciates the opportunity to comment on the project. However, we would like to point out areas of concern. 1. With reference to the 24-hour deadline for early warning, we believe that the time allowed for early reaction is too short for a reliable assessment of the situation.
Filed in Polish · English published by the European Commission
P.193: 1) clarify if notification is required also for "incident that ... is capable of negatively affecting" as per CRA definition of "incident having an impact ...". Otherwise, the existence and applicability of a vulnerability would not be required to be corrected until an event determines an effect.. 2) provide a definition of "severe", term that is used in the CRA but definition is missing.
The Software Safety Institute (SSI) welcomes the European Commissions draft guidance on the EU Cyber Resilience Act. The guidance provides important clarification on scope, lifecycle responsibility, and the role of economic operators, and represents a meaningful step toward treating software as a product with safety implications.
DigiCert welcomes the Commission's draft guidance on the application of Regulation (EU) 2024/2847 and the opportunity to contribute to this consultation. As a global provider of digital trust infrastructure, including device identity, public key infrastructure (PKI), code signing, and certificate lifecycle management, we bring direct operational experience supporting manufacturers of connected products across…
The draft guidance on the CRA application is a welcome and important implementation step. It addresses several core issues that are highly relevant to the Research & Education sector, including scope, placing on the market, complex systems, free and open-source software, support periods, substantial modification, cybersecurity risk assessment, and remote data processing.
Privacy International (PI) welcomes and thanks the Commission for the opportunity to provide feedback on this crucial guidance as part of the Cyber Resilience Act (CRA). PI is a London-based NGO that researches and advocates globally against government and corporate abuses of data and technology. The full version of our feedback, containing more examples and info, is attached.
Regulatory provisions pose legal constraints for deploying mobile communication networks and related services. The telecommunications sector in Europe has undergone a radical transformation from state monopolies to more competitive domestic markets. This transformation has occurred under a regulatory framework characterized by a blend of deregulation and detailed implimentation by national regulatory authorities.
ASML input to the consultation for guidance pertaining to the EU Cyber Resilience Act (EU) 2024/2847. We appreciate the Commissions efforts to bring clarity to the implementation of the Cyber Resilience Act (CRA) through the draft guidance. Several sections provide meaningful support to manufacturers, and we welcome the opportunity to offer further suggestions for clarification: 1.
ELA welcomes the opportunity to provide feedback. To support the industry effectively, the guidance documents for the Cyber Resilience Act, the Data Act, the Machinery Regulation, and the Lift Directive should constitute a coherent and consistent set.
The Commissions initiative to issue guidance on the application of the CRA is welcome. However, the draft guidance does not explicitly address the interplay between the CRA and DORA. While the guidance explicitly notes (p. 4, section 9) that the Commission may consider issuing further guidance on the interaction between the CRA, DORA, and the AI Act, this remains open for now.
Please see attached document for full version. ESMC advocates for a delegated act to the cyber resilience act to introduce the product group: Products and applications with a purpose to manage energy generation and/or consumption that can be exposed to a public internet connection.
Hello, Comments at my side: - Recital 23: "product's capacity to exchange digital information" - Which usage needs to be considered ? during customer usage (around 100% of life time ), or also during production (less than 0.001%) where some digital communication is fused during commissioning ? - Recital 29: " manufacturers should also periodically reassess" - What frequency do you consider as "Periodically" ?
As co-authors of the French "Guide CRA & Open Source" (CNLL/inno³, v2.0, publicly available at inno3.fr), we have conducted an in-depth analysis of the draft guidance and welcome its overall direction. Our feedback draws on practical experience advising open-source projects and enterprises on CRA compliance readiness. Commercial activity criterion (Recitals 15, 18).
OpenNovations welcomes the draft guidance and considers its overall direction to be sound. The guidance is strongest where it becomes practical: the FOSS role logic, the tiered steward model, the rule against transferring cybersecurity responsibility to users or third parties, the substantial-modification framework for software changes, the support-period interpretation for software, and the RDPS framework.
We welcome the opportunity to provide feedback on the draft Commission guidance on the application of the Cyber Resilience Act (CRA). The guidance is an important instrument to support consistent interpretation and practical implementation of the Regulation across the internal market.
The Shipyards & Maritime Equipment Association of Europe (SEA Europe) represents the European maritime manufacturing industry in 17 countries, encompassing the production, maintenance, repair, retrofit and conversion of all types of ships and floating structures commercial as well as military including the full supply chain with the various producers of maritime systems, equipment material, and services.
According to the Question 5.4. in the FAQ on the Cyber Resilience Act, the following applies to actively exploited vulnerabilities in third-party components: Manufacturers are required to notify any actively exploited vulnerability contained in their product with digital elements.
We would kindly ask for additional guiding and examples for what entails a product with digital elements as well as a clearer delineation of the role as a manufacturer and distributor in cases where a company acts as a project-based system integrator like in the following example: The companys activities correspond to those of a project-based IT systems integrator: from a portfolio of proprietary, in-house developed…
We, the Japan Electronics and Information Technology Industries Association (JEITA) is the leading Japanese association that consists of approx. 400 manufacturers, suppliers and service providers for the electronics and information technology sector.
Please find attached Sophos' contribution to the public consultation on the draft Communication on Commission guidance on the application of Regulation (EU) 2024/2847 (Cyber Resilience Act). As the leading cybersecurity provider of Managed Detection and Response (MDR) services, defending more than 30,000 organizations of all sizes worldwide, Sophos welcomes the draft Commission guidance and the clarity it offers…
Please find attached ISC2's contribution to the public consultation on the draft Communication on Commission guidance on the application of Regulation (EU) 2024/2847 (Cyber Resilience Act). This submission welcomes the practical clarity the guidance provides and focuses on the professional competency dimension of the obligations it clarifies, with specific recommendations on Sections 7 and 9.
We are enclosing our feedback and recommendations on the Draft Commission guidance on the Cyber Resiliency Act as founder of QUAI D'EUROPE, a Luxembourg SA in the establishment phase by Corbenic Capital S.r.l. , an Italian limited liability company with company headquarters in Saronno (VA), Italy. With respect, Trond Johannessen Managing Partner
Connect International welcomes the European Commission's draft and the efforts to strengthen cybersecurity requirements for products with digital elements. From the perspective of our work on youth rights, digital wellbeing, and media literacy, we would like to highlight a complementary dimension that could be more explicitly reflected in the Commissions guidance.
We welcome the draft guidance. However, given Article 26(1)'s explicit focus on SMEs, we note two gaps: first, the guidance does not address the simplified technical documentation form that Article 33(5) requires the Commission to specify for micro-enterprises and SMEs, this would be among the most impactful measures to reduce compliance burden.
Dear readers, first, we would like to express our gratitude to the committee for preparing the Commission Guidance on the Application of CRA. This guidance is extremely helpful and helps to clarify many points that could not easily or explicitly be understood when just reading the CRA on its own.
Red Alert Labs welcomes this draft guidance and in particular the clarifications on scope, substantial modification, support period, remote data processing, and the conformity assessment logic for important and critical products.
General comments The Cyber Resilience Act (CRA) is a significant regulatory step. However, there is a material risk that its implementation becomes documentation-led rather than security-led. Modern digital systems are distributed, continuously changing, and increasingly automated. In this context, compliance cannot be reliably demonstrated through static artefacts alone.
We build monitoring solutions for integration into energy systems, and find it difficult to classify our products correctly within CRA. In older drafts IACS/PLCS where listed specifically, but none in the current list of products describe our functions. We would welcome very specific and detailed guidelines on how to get products categorized correctly.
The European Building Automation and Controls Association (eu.bac) welcomes the European Commissions draft guidance accompanying the Cyber Resilience Act (CRA) and appreciates the opportunity to contribute to this consultation. The contribution in the attached file proposes targeted clarifications to support a clear, proportionate and practical application of the Cyber Resilience Act.
Vulnerability Remediation in OEM-Integrated Products: Our company develops robotic laboratory automation systems used for sample preparation in analytical workflows involving GC/LC instruments. These robots are not placed on the market as standalone end-user products.
I am an open-source developer and software microenterprise owner, based in Spain. I have a few points of feedback on the proposed draft: - Section 4.3 is somewhat outdated vs industry practices. Even small products (my own) are often updated 10s of times a day by a single developer, a widespread practice known as "continuous delivery".
Four comments on the draft guidance, with full detail in the attached document: Article 26 / Annex I The guidance describes what SDL evidence is required but gives no direction on how to generate it continuously. Automated engineering observability tooling (SCM + CI/CD signals) should be explicitly acknowledged as valid Annex II evidence generation, particularly for SMEs without compliance teams.
Section 9 Interplay with other legislation The guidance acknowledges the interplay between the Cyber Resilience Act and other EU legislation, such as NIS2 and DORA, but does not provide practical direction on how overlapping obligations should be operationalised.
Section 7 Dependencies and integrated components The guidance highlights the need to assess risks related to external dependencies but does not clearly define how responsibilities should be allocated when products rely on third-party services or components.
Submitted by REG-DIGITAL (regulatory intelligence platform focusing on EU digital regulation). Section 8 Remote data processing The guidance defines remote data processing based on whether the absence of such processing would prevent the product from performing one of its functions. However, it does not address cases where functionality is only partially dependent on, or enhanced by, external services.
We welcome the draft guide as it provides clarity on particularly sensitive matters for industrial manufacturers: complex systems, products designed before the implementation of the ARC, substantial modifications, spare parts and remote data processing solutions.
Filed in Spanish · English published by the European Commission
Techem appreciates the Commissions initiative to provide draft guidance accompanying the Cyber Resilience Act (CRA) and welcomes the opportunity to contribute to the ongoing consultation. Please find our detailed input in the document we have uploaded.
It would be very helpful for the advice and readability of the CRA if you could still define the individual word ‘product’. In addition, Article 12 of the CRA could be significantly improved. This is almost illegible, even for a lawyer and because of the use of the words in the German version of ‘vorliegenr Verordnung’, ‘this Verordnung’ and ‘the aforesaid VO’, it is not really clear in the end which regulation the…
Filed in German · English published by the European Commission
The comments on the support period convincingly implement the legal requirements from the consumer’s point of view. The chapter sets out precisely how to ensure the protection of users throughout the product life cycle and, in our view, does not require adaptations.
Filed in German · English published by the European Commission
Comment 1 Clarification of Actual Cost Recuperation for FOSS Developers Relevant Guidance Section 3.2.3 states that a natural person providing support services for FOSS is not considered a manufacturer where remuneration only covers the recuperation of actual costs, which may include reasonable living expenses.
Viessmann Climate Solutions welcomes the Commissions draft guidance on the Cyber Resilience Act (CRA). We support the objective of improving cybersecurity for products with digital elements and appreciate the clarifications provided, particularly on complex systems and products designed before the CRA becomes applicable.
Dear European Commission, Thank you for the March 3, 2026, draft guidance on the Cyber Resilience Act (Regulation (EU) 2024/2847). As developers of cybersecurity compliance solutions (Cybessure Labs, Dresden) serving EU essential entities, we value the guidance's coverage of remote data processing (RDPS), SBOMs, and NIS2 interplay.
The draft guidance is very helpful in clarifying the concept of products with digital elements and the role of remote data processing solutions. However, further clarification could be useful for sectors where complex systems are created through the integration of multiple independent digital products.
CRA assessment requirements can be downgraded by adding in more core function definitions, which are reasonable features of the product with digital elements. For example: NMS + PKI + SIEM would be evaluated as default category product as the sum of other core features is larger than the single core feature under evaluation. The fallback should be something else, than the default category.
1. Clearly define the term "manufacturer" to prevent unlimited expansion of liability. It is suggested that the draft be further clarified to define who the true manufacturer is. Only the entity that actually controls the product design, release and market launch should be held accountable; distributors, retailers, logistics providers and component suppliers that do not participate in design and safety…
Although the purpose of the CRA is well understood, the actual implementation of it is very murky for a lot of devices and products that already fall under other regulations and directives. These regulations and directives often already have some part of cybersecurity embedded within them. The scope of the CRA does in fact remove some of these products out of its own scope, but not all.
The draft guidance addresses some of the exclusions from scope in Article 2 but does not address the exclusion in 2(3) relating to Regulation (EU) 2018/1139, i.e. the Basic Regulation on civil aviation. The exclusion relates to "products with digital elements that have been certified" in accordance with the Basic Regulation. It would be helpful to have guidance on the applicability of this exclusion.
Hello, In the draft guidance, there is no explicit reference to threat modelling as a standalone requirement. In earlier interpretations of the Cyber Resilience Act (CRA), threat modelling was often implicitly linked to the risk assessment obligations under Article 13(2) and to the technical documentation requirements under Article 14(4)(c).
We should rely on Cyber Resilience Act from euOmbudsman Only who Can create all regulations for Each municipalty & country to stop cyber attacks as local Regulations er face in our Country. When analyse methods from EU are reliable then all citizens Can have great connections to any Company via legal agreements to have access to income & safety online.
Method. Every quote is verbatim from the organization’s own submission to the European Commission, trimmed to its opening passage and never summarized by a model. Where a submission was filed in another EU language we show the English text the European Commission publishes alongside it, labeled on the quote; the original is one click away at the source. Groupings use the respondent type the organization itself selected when filing. We deliberately do not label anyone “supportive” or “opposed” — you read what they wrote and draw your own conclusion. Organizations only, never individuals. Reused under Commission Decision 2011/833/EU; the European Commission is not liable for this reuse.