Summary of the Guidance on Compliance with the EU Cyber Resilience Act (CRA)
Executive Summary
This article looks back at the CONFIRMATE deliverables over the past eighteen months, since the project kick-off in January 2025, and evaluates its results alignment with the evolving requirements of the EU Cyber Resilience Act (CRA). The assessment is based on comparative analyses of the CONFIRMATE CRA infographics, Compliance Guide for SMEs, Penetration Testing Methodology[1], as well as metrics and tools, against the European Commission’s (EC) Draft Guidance (March 2026), the EC’s CRA FAQ (December 2025), and the ENISA Security by Design and by Default Playbook.
The European Cyber Resilience Act is a comprehensive, overarching and evolving set of regulatory specifications that needs to be interpreted dynamically, considering new and evolving standards, guidelines, threats, and technology. After the formal completion of the legislative process, the need to understand and harmonise CRA applicability comes into play, considering the intended product market, business and use case, technology , and the operating environment.
The European Commission, European Agency for Cybersecurity (ENISA), and Standardisation Bodies (ETSI, CEN-CENELEC), clarify the legislative texts in their stages of applicability by structuring and requesting the development of several guidances and implementation standards that elaborate on the legal aspects (scoping and applicability), requirements for specific information security domain (like vulnerability handling, security by design and by default) or product (e.g. smart cards, smart home products, identity and access management systems, browsers, network managing devices, amongst others).
Being one of the pioneering projects to support SMEs in CRA compliance, together with a few other EU co-funded projects clustered in CyberStand, CONFIRMATE had to cautiously but confidently and timely contribute to the clarification of the regulation, maneuver dynamically in the evolving common understanding of the impacts of the CRA.
In view of the above, CONFIRMATE has embraced a continuous learning and regulatory watch, part of the Work Package 2 – Requirements Analysis and Planning, to dynamically evaluate and enhance its deliverables with newly emerging developments explaining specific real cases related to the regulation. Specifically, these developments include the recommendations of the EC and ENISA regarding the regulation.
The overall self-assessment finds out that the CONFIRMATE guides and methodologies are substantively consistent and aligned with the CRA legal framework, the EC Guidance, and the EC FAQ. No legal contradictions or explicit misalignments were identified across the reviewed source documents. Moreover, each of the CONFIRMATE deliverables is complementary, contributing to the overall understanding of the state of play, with the EC text focusing on legal aspects like scoping, ENISA texts focusing on specific security concept, like secure by design and by default, and CONFIRMATE materials focusing on covering the basic but comprehensive set of requirements through the prism of an SME based on industry best practices.
In particular, the European Commission guidance, while it focuses on legal definitions, scope boundaries, and complex interpretive scenarios (e.g., FOSS monetization, legacy systems, and Remote Data Processing Solutions), CONFIRMATE guides and training modules successfully translate these complex concepts into an operational, workflow-based framework tailored specifically for resource-constrained manufacturing SMEs.
While the EC FAQ provides the authoritative, article-driven legal boundaries of the Cyber Resilience Act, written in formal legislative language that assumes prior regulatory expertise, CONFIRMATE acts as the operational translator.
For instance, while the EC FAQ defines and details the legal frameworks conceptually, the CONFIRMATE reorganizes these rules into a workflow-based, Q&A-driven format tailored to real-world business structures and complements this by providing tangible assets in one place, such as a Simplified Declaration of Conformity template and a Risk Assessment Template mapped to ISO 31000 and ISO 14971.
On the other hand,ENISA Playbook on “secure-by-design and secure-by-default” which provides deep technical blueprints for how engineers must build it, CONFIRMATE outlines what must be documented to satisfy the CRA (risk management plans, secure configurations, lifecycle maintenance).
At the same time, The CONFIRMATE guidance is structured and designed to prevent the CRA stakeholders and mostly SMEs of possible misinterpretations of industry best practices as mandatory regulatory baselines. This is done by focusing on the clarity of its illustrative examples and scenarios intended to save them the unnecessary compliance burdens.
Hence, CONFIRMATE bases its solutions on CRA annex I essential cybersecurity requirements, clarified in the prism of industry best practices and effective product regulations (e.g Medical Devices Regulation), and EU cybersecurity acts like the Cyber Security Act, Network and Information Security Directive (NIS). As such, CONFIRMATE complements the regulatory developments by providing practical guidance and examples / scenarios that extend beyond baseline regulatory texts to help SMEs achieve actual legal and technical compliance with the CRA requirements.
Moreover, CONFIRMATE delivers an automation tool for CRA compliance assessment, an open source solution available for any European SME interested to test and identify its product compliance state and recommendations for further improvement. The automation tool is built upon specific metrics, defined within CONFIRMATE and builds upon existing tools developed in earlier EU-funded projects, such as Clouditor, for cloud compliance assessment.
While the CONFIRMATE project is ending on 30 June 2026, its tools and guidance remain relevant and SME-oriented. Further European solutions and harmonised standards to support CRA implementation are emerging. These standardisation efforts are needed for an effective CRA implementation supporting SMEs for a better CRA clarity and understanding, and enable dynamic but harmonised cybersecurity practices across the products on the EU market.
In conclusion, the relationship between the CONFIRMATE deliverables and the European Commission and ENISA recommendations is highly complementary. Together, they bridge the gap between the high-level European law and practical, hands-on engineering execution for SMEs. Further standardisation and EU compliance solutions will enhance clarity and harmonisation in the cybersecurity in products placed on the EU market.
[1] CONFIRMATE Published materials are available in five languages (EN, FR, DE, IT, RO) here: https://confirmate-project.eu/materials/