STORY
The European Commission has published new guidance to help manufacturers, software developers and other businesses comply with the EU Cyber Resilience Act. The legislation introduces mandatory cybersecurity requirements for products containing digital elements.
The guidance explains which products are covered, what counts as a substantial modification and how businesses should approach risk assessments, security support periods and incident reporting.
The Commission said the document includes practical examples and specific information for small and medium sized businesses. Companies are being encouraged to prepare before the Act’s main obligations become mandatory.

