Skip to main content
PolicySpeak
← All files

EU consultation

Draft Commission guidance on the Cyber Resilience Act

150 submissions from 144 organizations told the European Commission what they think about this file. Here is what each of them said, in their own words.

The Commission lists 252 submissions on this file. Shown here: the 150 from organizations. Not shown, by design: submissions from private individuals, which we never publish, and anything filed since our last weekly refresh.

Who showed up

126 submissions from industry — companies and their trade associations — against 15 from civil society: NGOs, consumer organizations, environmental groups and trade unions. That is 8.4 industry submissions for every one from civil society.

Industry 126Civil society 15Public authorities, academia, other 9

Groupings use the respondent type each organization selected when filing. Counting submissions, not organizations — a body that filed twice is counted twice.

What the room declares

65 of 144
in the EU Register
326
full-time lobbying staff
€53.3M+
declared costs a year
222
EP accreditations declared

Self-declared to the EU Transparency Register (snapshot 30 Aug 2026). The cost figure sums band floors, so the true total is higher.

The file, right now

The consultation closed on 13 Apr 2026 — it ran from 3 Mar 2026.

Policy area
Digital & tech (DG CNECT)
Where it stands
Awaiting adoption

How it got here

  1. Dec draft13 Apr 2026

Also on the Commission’s pipeline for this file, with no date recorded: Communication.

150 positions · showing 25

EF

ESYS Foundation

· · filed 13 Apr 2026 · source

Although ESYS fully supports both the substance and the ambition of Regulation (EU) 2024/2847, the current timeline reveals structural implementation gaps liable to compromise the effectiveness and coherence of the Regulation.

LinkedInX
EC

European Cloud User Coalition

· · filed 13 Apr 2026 · source

PDF

The document addresses concerns about overlap between the proposed Cyber Resilience Act (CRA) and the existing Digital Operational Resilience Act (DORA) in the financial sector, urging clearer alignment to avoid duplication and regulatory fragmentation.

LinkedInX
SS

SUSE Software Solutions Germany GmbH

· · filed 13 Apr 2026 · source

PDF

SUSE welcomes the opportunity to provide feedback on the European Commissions Draft Guidance on the Cyber Resilience Act (CRA). While we appreciate the Commissions efforts to provide early guidance, additional clarity is needed to ensure consistent and proportionate implementation.

LinkedInX
G

GitHub

· · filed 13 Apr 2026 · source

PDF

GitHub appreciates the opportunity to provide feedback to the draft Guidance on the application of the CRA. We believe this guidance, along with the already published FAQ and other publications from the Communication, greatly improves the readability and applicability of the CRA for FOSS developers and users of FOSS in various roles.

LinkedInX
EF

ESYS Foundation

· · filed 13 Apr 2026 · source

PDF

Article 100 should be amended so that it is not the Commission but the European Council that shall verify the risk posed by that country and that adopts the measures provided for in Articles 101 and 102 of the proposal.

LinkedInX
BD

Black Duck Software

· · filed 13 Apr 2026 · source

We wish to thank the Commission for producing guidance that includes examples of real-world scenarios. We have chosen to focus our feedback on questions from the Scope section. Due to the value provided by the examples, we do request that additional examples of non-compliant scenarios be included.

LinkedInX
AS

Apache Software Foundation

· · filed 13 Apr 2026 · source

PDF

The Apache Software Foundation (the ASF) compliments the commission on its draft guidance. We welcome the opportunity to respond in this public consultation. The guidance provides the software industry in general and the open source ecosystem with the much needed practical examples.

LinkedInX
RG

RATP Group

· · filed 13 Apr 2026 · source

RATP welcomes the Commission’s initiatives to strengthen the cybersecurity of connected products. With the aim of ensuring optimal functioning of all systems and subsystems, minimising operational impacts in a constrained rail technical environment, it should be possible for the implementation of risk mitigation measures ‘by other means’ within complex systems (section 2.5) to be shared between the customer and the…

Filed in French · English published by the European Commission

LinkedInX
OR

Open Regulatory Compliance Working Group

· · filed 13 Apr 2026 · source

PDF

On behalf of the Open Regulatory Compliance Working Group, we would like to express our gratitude for the opportunity to provide feedback on the draft guidance for the Cyber Resilience Act (CRA). We appreciate the significant effort and work the Commission has put into building this comprehensive document.

LinkedInX
EF

Eclipse Foundation AISBL

· · filed 13 Apr 2026 · source

PDF

Response to the Draft Commission Guidance on the Implementation of the Cyber Resilience Act Eclipse Foundation welcomes the opportunity to provide feedback on the draft guidance supporting the implementation of the Cyber Resilience Act and would like to thank the European Commission for the substantial work already undertaken.

LinkedInX
ES

Epic Systems Corporation

· · filed 13 Apr 2026 · source

PDF

We appreciate the opportunity to provide feedback on the Commissions draft Guidance on the Cyber Resilience Act (Regulation (EU) 2024/2847). We support the Commissions mission to raise the cybersecurity posture of the products made available in the EU and EEA to protect citizens and Member States from threats against the confidentiality, integrity, and availability of information.

LinkedInX
DB

Deutsche Bahn AG

· · filed 13 Apr 2026 · source

PDF

We welcome the opportunity to provide our feedback on the draft Commission guidance on the application of the Cyber Resilience Act (CRA). We strongly support the overarching goal of enhancing the cybersecurity and resilience of products with digital elements across the European market.

LinkedInX
ET

Electronic Theatre Controls, Inc.

· · filed 13 Apr 2026 · source

Electronic Theatre Controls, Inc. (ETC) appreciates the opportunity to comment on the Commissions draft horizontal guidance concerning the application of the Cyber Resilience Act. ETC is a United Statesbased manufacturer of luminaires and power and control systems used in professional theatrical, live events, entertainment, commercial, and architectural environments worldwide.

LinkedInX
W

WindEurope

· · filed 13 Apr 2026 · source

PDF

WindEurope welcomes the opportunity to provide feedback on the draft implementation guidance of the Cyber Resilience Act. We recommend that the guidance better reflect the reality of complex industrial systems, such as wind energy installations, which rely on a set of critical system functionalities spanning multiple digital components and are deployed as integrated systems with long operational lifetimes rather…

LinkedInX
KM

Kongsberg Maritime

· · filed 13 Apr 2026 · source

PDF

Our feedback to the draft CRA guidance outlines several improvements regarding the interpretation of specific requirements in context of European maritime sector and their relationship to tailor-made products and complex, integrated vessel installations.

LinkedInX
EG

European Games Developer Federation (EGDF)

· · filed 13 Apr 2026 · source

PDF

EGDF underlines that it is highly important for the Commission to ensure that the guidance document ensures a well-balanced implementation of the regulation. In particular, the Commission should: 1. Risk-based approach on the scope of stand-alone software and device a.

LinkedInX
GR

German Railway Industry Association (VDB)

· · filed 13 Apr 2026 · source

PDF

The German Railway Industry Association (VDB) welcomes the oportunity to provide feedback on the Draft Commission guidance on the Cyber Resilience Act. VDB speaks for the German rail industry. It combines the interests of its more than 250 member companies, organises and moderates a consensus, gets involved with specific concerns.

LinkedInX
ME

MPW EMEA

· · filed 13 Apr 2026 · source

We would like to thank the Commission for the opportunity to comment on the Draft Guidance on the Cyber Resilience Act. After reviewing the current draft, we believe several points would benefit from additional clarification in order to support consistent implementation across the industry. 1.

LinkedInX
D

DIGITALEUROPE

· · filed 13 Apr 2026 · source

PDF

The clarifications provided in the draft guidance in support of the Cyber Resilience Act (CRA) are most welcome. Nevertheless, several important amendments are required to ensure an effective CRA that works in practice. To that end, please see DIGITALEUROPE's HYS comment template attached.

LinkedInX
HL

Hogan Lovells International LLP

· · filed 13 Apr 2026 · source

PDF

We welcome the opportunity to provide feedback on the European Commissions (Commission) draft guidance on the EU Cyber Resilience Act (CRA) published on 3 March 2026 (the Draft Guidance). In this submission, we urge the Commission to take further steps to clarify the interplay between the CRA and NIS2 by preventing dual regulation for organisations operating Remote Data Processing Solutions (RDPS), that are already…

LinkedInX
SE

Schneider Electric

· · filed 13 Apr 2026 · source

PDF

Schneider Electric welcomes the publication of the draft CRA Guidance and the opportunity to provide feedback. The draft provides valuable clarifications and represents a positive step toward more practical implementation of the Regulation, particularly for complex industrial, OT, software-enabled, and distributed products.

LinkedInX
OE

Orgalim - Europe's Technology Industries

· · filed 13 Apr 2026 · source

PDF

Orgalim represents Europe`s technology industries at EU level: innovative companies across the mechanical engineering, electrical and electronics, ICT and metal technology sectors that develop and manufacture the products, systems and services that enable a prosperous and sustainable future. Orgalim welcomes the opportunity to comment on the draft Cyber Resilience Act (CRA) guidance.

LinkedInX
HH

Hangzhou Hikvision Digital Technology Co., Ltd.

· · filed 13 Apr 2026 · source

PDF

Hikvision welcomes the opportunity to contribute to the public consultation on the Draft Commission guidance on the Cyber Resilience Act. As a world-leading security product and solution provider, Hikvision is deeply committed to fostering a secure digital environment and to providing customers with secure and trusted technology.

LinkedInX
SE

SPECTARIS e.V.

· · filed 13 Apr 2026 · source

PDF

Please find attached SPECTARIS' feedback on the draft Commission guidance on the Cyber Resilience Act. SPECTARIS is the German Industry Association for Optics, Photonics, Analytical, and Medical Technology, headquartered in Berlin. The association represents approximately 400 German companies, most of which are export-oriented and medium-sized.

LinkedInX
Take the dataCSV — all 150 submissionsJSONFull text, not the excerpt. Free to cite.Search every submission →

Follow this file

Get an email when a new organization files a position here: one email on Tuesdays, only when there is something new. Free.

We use your email for updates on this file, and PolicySpeak may contact you about the product. Unsubscribe in one click. Privacy policy.

Method. Every quote is verbatim from the organization’s own submission to the European Commission, trimmed to its opening passage and never summarized by a model. Where a submission was filed in another EU language we show the English text the European Commission publishes alongside it, labeled on the quote; the original is one click away at the source. Groupings use the respondent type the organization itself selected when filing. We deliberately do not label anyone “supportive” or “opposed” — you read what they wrote and draw your own conclusion. Organizations only, never individuals. Reused under Commission Decision 2011/833/EU; the European Commission is not liable for this reuse.