


The European Commission has released practical guidance to help manufacturers understand and implement the Cyber Resilience Act, including 67 examples and guidance on product scope, risk assessments, software updates, support periods, open-source software, remote services, and vulnerability reporting.
PMMI members that sell or support connected machinery, components, or software in the European Union should review these resources now. Identify potentially affected product families and prepare for mandatory vulnerability and incident reporting on September 11, 2026, followed by full CRA application on December 11, 2027.
Review the guidance, evaluate your exposure, and develop your compliance plan now.
Download Communication on Cyber Resilience Act
Download Commission guidance on the application of the Cyber Resilience Act (CRA)