The European Commission’s new guidance on the Cyber Resilience Act (CRA) offers a roadmap for companies as they prepare to meet upcoming compliance deadlines. With the CRA’s reporting obligations taking effect on September 11, 2026, and full compliance required by December 2027, in-house lawyers and compliance professionals must prepare to implement governance, documentation and reporting processes that can withstand both regulatory scrutiny and potential market-access challenges. With commentary from experts at Akin, Alston & Bird and Hogan Lovells Cadwalader, this article provides insights and compliance advice regarding key elements of the guidance. See “What International Companies Should Do to Comply With the E.U. Cyber Resilience Act” (Jan. 28, 2026).