Timeline
CRA timeline: the key dates
The CRA does not switch on all at once. It phases in — and the obligations that arrive first are easy to miss.
The Cyber Resilience Act was adopted in 2024 and applies in stages. Understanding the phasing matters because the reporting obligations arrive well before the full set of product requirements, and because security-by-design work needs a long runway. Here is the shape of the timeline.
The regulation was published in the EU Official Journal and entered into force twenty days later. This starts the clock; most obligations do not bite yet, but the legal framework is now fixed and manufacturers can plan against final text.
The duties to report actively exploited vulnerabilities and severe incidents — via the ENISA Single Reporting Platform, on the 24-hour / 72-hour / final-report cadence — apply from around 11 September 2026, ahead of the main requirements. If your product is on the market by then, you need a working reporting process even though full conformity is not yet mandatory.
The core of the CRA — the essential requirements, conformity assessment, CE marking, technical documentation and the Declaration of Conformity — applies from 11 December 2027. From this date, products with digital elements placed on the EU market must comply.
Why "2027" is not as far away as it sounds
Three years feels comfortable, but the work does not compress well:
- Design decisions happen early. Secure update mechanisms, key storage, attack-surface reduction and logging are architectural. Adding them to a shipped product is expensive and sometimes impossible without a hardware revision.
- Processes take time to embed. A vulnerability-handling workflow, an SBOM pipeline, a coordinated disclosure policy and an incident-reporting runbook are organisational muscles you build over quarters, not days.
- Product cycles are long. A device you are designing now may still be on sale in 2028 — so it needs to be CRA-ready by design today.
- The reporting duty comes first. If your product is on the market in 2026, you already need the reporting capability before the rest of the regime applies.
What to do, and when
- Now: confirm scope and risk class for each product; run a gap assessment against the Annex I essential requirements; start an SBOM for your key products.
- Well before 2026: stand up your vulnerability-handling and incident-reporting processes and a coordinated vulnerability disclosure policy, so the reporting obligations are a non-event when they start.
- Ahead of December 2027: close design gaps, assemble technical documentation, choose your conformity route (self-assessment or notified body), and prepare the Declaration of Conformity and CE marking.
This article is general information, not legal advice. Confirm all dates against the official Regulation (EU) 2024/2847.