The European Commission has published guidance aimed at helping businesses to prepare for new EU rules on cyber-resilience.
The Cyber Resilience Act, in force since December 2024, sets mandatory cyber-security requirements across the full lifecycle of digital products, with reporting obligations applying from 11 September.
It introduces these requirements for all hardware and software, ranging from baby monitors, smart watches, and computer games to firewalls and routers.
The legislation is aimed at protecting digital products across the EU from cyber-attacks.
The commission says that its guidance explains how the rules apply in practice, clarifying which products fall within the scope of the act, what constitutes a substantial modification, how support periods should be understood, and how to meet reporting obligations and risk-assessment requirements.
It also responds to questions raised by businesses, giving particular attention to microenterprises and small and medium-sized enterprises.
According to the commission, the guidance includes practical examples and use cases to help reduce any unnecessary administrative burden.
The deadline for businesses to comply is December 2027.
“Today's guidance will help ensure that products on our market are protected from cyber threats, while avoiding unnecessary burden and legal uncertainty for companies,” said commissioner Henna Virkkunen.