eu-cyber-resilience-act-timeline-key-compliance-dates
  • Cyber Essentials
  • 22nd Sep 2026
  • 1 min read

EU Cyber Resilience Act Timeline: Key Compliance Dates

In Short..
  1. Three of four major milestones have already passed: Entry into force (December 2024), the notified body framework taking effect (June 2026) and Article 14 reporting duties going live (September 2026) are all behind you; full application lands 11 December 2027.
  2. Reporting obligations are already live, and they apply to existing products too: Since 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents, including for products already on the EU market before the CRA existed.
  3. A soft notified-body capacity target falls on 11 December 2026: Products needing third-party conformity assessment face a bottleneck risk if designations continue to lag.
  4. Unlike the December 2026 capacity target, full application on 11 December 2027 is fixed and enforceable: Every product placed on the EU market for the first time from that date needs CE marking, technical documentation and a completed conformity assessment.
  5. There's no blanket 2030 sell-off period for products already on the market: Article 69 gives a narrow exemption from the substantive requirements, but it ends the moment a product is substantially modified, and it never touches the Article 14 reporting duty.

The practical takeaway: reporting obligations are already running against the clock, and the milestones still ahead need a sequenced plan built around each date in turn.

Introduction

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is already law. It entered into force on 10 December 2024, and its obligations are phasing in on a fixed schedule that runs through to December 2027. Three of its four binding milestones have already passed.

Every milestone below is paired with the specific actions your organisation needs to have completed by that point, so it works as a compliance calendar alongside your CRA readiness programme rather than just a list of dates.

The CRA is in force and in the implementation phase. Reporting obligations have been live since 11 September 2026. The full regulation applies from 11 December 2027. If your product is on the EU market, you're already subject to vulnerability reporting requirements.

Expert View

 

Matt Davies

Chief Product Officer, SureCloud

LinkedIn

 

What Our Experts Say About Treating CRA Deadlines as Sequential

 

"Most of the manufacturers I talk to treat 2027 as the starting point. The reporting clock has actually been running since September. The notified body queue is already forming for anyone who’ll need third-party assessment."

The GRC brief
New frameworks and control changes, monthly.

The CRA Timeline at a Glance

Date

Milestone

Status

10 Dec 2024

CRA enters into force

Complete

11 Jun 2026

Chapter IV applies: notified body framework live

Complete

11 Sep 2026

Article 14 reporting obligations apply

In force

11 Dec 2026

Target: sufficient notified body capacity across the EU

Target date

11 Dec 2027

Full CRA application: all obligations enforceable

Upcoming

 

The phased structure is deliberate. The European Commission designed the CRA so the compliance infrastructure, meaning notified bodies, reporting platforms and harmonised standards, is in place before the full technical obligations take effect. Each milestone functions as a dependency for the ones that follow, more than just a date on a calendar.

Milestone 1: 10 December 2024 – Entry Into Force

The CRA was published in the Official Journal of the EU on 20 November 2024 and entered into force twenty days later. From that point, the regulation became binding law across every EU member state. No substantive technical obligations applied on this date, but the compliance clock started running.

What this meant operationally: any product with digital elements in design or development from December 2024 onwards needed assessment against CRA requirements before being placed on the market. Products already in development needed evaluation against the Annex I essential requirements, even with the compliance deadline three years away.

What You Should Have Done by This Date

  1. Confirmed whether your products fall within the CRA's scope (products with digital elements placed on the EU market)
  2. Begun a gap analysis against the Annex I essential requirements
  3. Assigned internal ownership of CRA compliance

If this work is still outstanding, it needs to happen now. The December 2027 deadline is fifteen months away, and conformity assessment queues are building.

Milestone 2: 11 June 2026 – Notified Bodies Framework Applies

Chapter IV of the CRA, which governs the notification and designation of conformity assessment bodies, applied from 11 June 2026. This is the legal framework that lets EU member states formally designate the third-party bodies authorised to conduct conformity assessments for Class I and Class II products.

This milestone is often misread as meaning notified bodies are already operational. In practice, 11 June 2026 is only when the framework to designate them took effect. Article 35(2) sets a separate target: sufficient notified body capacity in place by 11 December 2026, meant to prevent certification bottlenecks in the run-up to full application.

Why this matters for your programme: if your product falls into Class I or Class II under Annex III, both tiers the regulation treats as higher risk because of their function or how widely they're used, you'll need a notified body to conduct your conformity assessment. Bodies are only now being designated, and capacity is limited. Manufacturers who wait until mid-2027 to begin conformity assessment are likely to hit queues.

What You Should Have Completed by This Point

  1. Determined your product's classification: default (self-assessment), Class I, or Class II
  2. Identified which notified bodies in your relevant EU member states are being designated
  3. Begun pre-assessment preparation if third-party conformity assessment is required
  4. Reviewed the NANDO (New Approach Notified and Designated Organisations) database for designated bodies as they come online

Milestone 3: 11 September 2026 – Reporting Obligations Live

This is the most operationally demanding milestone to have passed so far. From 11 September 2026, Article 14 of the CRA requires manufacturers to report actively exploited vulnerabilities and severe security incidents to ENISA's (the EU Agency for Cybersecurity's) Single Reporting Platform and to the national CSIRT (Computer Security Incident Response Team) of the member state where they have their main establishment.

The reporting window is tight. According to the European Commission's official reporting obligations page, manufacturers must submit:

  1. An early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident
  2. A full notification within 72 hours, including an initial impact assessment and any corrective measures taken
  3. A final report no later than 14 days after a corrective or mitigating measure is available (for vulnerabilities) or within one month of the 72-hour notification (for severe incidents)

The Legacy Product Trap

The detail most manufacturers miss: these reporting obligations apply equally to products already on the EU market and to new launches, including products placed there years before 11 December 2027. Any in-scope product live as of 11 September 2026 falls under Article 14 immediately. If you sell a connected product in the EU today, you're already subject to it.

What You Need in Place Now

  1. A documented vulnerability disclosure and incident response process aligned to the 24-hour/72-hour/14-day windows
  2. A registered account on ENISA's Single Reporting Platform
  3. Internal triage processes to distinguish actively exploited vulnerabilities from those not yet exploited
  4. Clear ownership of who submits notifications and who approves them before submission

Milestone 4: 11 December 2027 – Full CRA Application

This is the date the full weight of the CRA becomes enforceable. From 11 December 2027, any product with digital elements placed on the EU market for the first time must fully comply with the essential requirements set out in Annex I (security by design, vulnerability handling, no default passwords, data minimisation, and more), complete the appropriate conformity assessment procedure for its product class, hold an EU declaration of conformity signed by the manufacturer, and bear the CE marking.

National market surveillance authorities will have the power to withdraw non-compliant products from the market and impose fines of up to €15 million or 2.5% of worldwide annual turnover, whichever is higher. That fine framework sits in Article 64; on a literal reading of Article 71's application dates, it formally applies from 11 December 2027, while the Article 14 reporting duty has already carried its own enforcement exposure since September 2026, so confirm the position with the authority in the member state where you report.

What You Need to Have Completed Before 11 December 2027

The December 2027 deadline is fifteen months away, which can sound like enough time. For Class I and Class II products requiring third-party conformity assessment, it's often tight. A realistic estimated timeline for a complex product looks like this:

Activity

Estimated Duration

Annex I gap analysis and remediation

3–6 months

Technical documentation preparation

2–4 months

Conformity assessment (Class I/II) with notified body

3–6 months

CE marking and declaration of conformity

1 month

Buffer for remediation findings

2–3 months

 

Add those up and a product requiring third-party assessment is looking at eleven to twenty months. Organisations that haven't yet begun their gap analysis are already at risk of missing the deadline.

For default-class products, which make up most connected products, the timeline is more manageable: self-assessment is permitted, and a well-resourced team can usually complete the process in six to nine months.

What Happens to Products Already on the Market

Article 69 of the CRA gives a narrow transitional exemption to products already placed on the EU market before 11 December 2027: they're exempt from the substantive Annex I requirements retrospectively. That exemption holds only until a substantial modification changes the product's cybersecurity properties or intended purpose after that date, at which point the product has to be treated as newly placed on the market and comply in full.

The exemption is narrower than it might look, because it only covers the substantive Annex I requirements. Article 14's reporting obligations apply to every in-scope product on the EU market from 11 September 2026 regardless of when it was first placed there, so a product that's exempt from the substantive requirements can still be subject to the reporting duty today.

Some guidance circulating online cites a fixed 2030 sell-off deadline for pre-2027 products. Article 69 sets no such date. What ends the exemption is a substantial modification to the product, whenever that happens.

What UK Organisations Need to Do

The CRA is EU law, and its reach follows where a product is sold rather than where the organisation is based. UK organisations selling into the EU remain fully in scope; organisations trading only within Great Britain fall outside it.

The CRA applies to any product placed on the EU market, regardless of where the manufacturer is based. A UK company selling connected products in France, Germany or any other EU member state has to comply on the same timeline as an EU-based manufacturer, wherever the product is sold.

The same deadlines apply: Article 14 reporting from 11 September 2026, full compliance by 11 December 2027.

UK-only sales sit outside the CRA and fall instead under the UK's own regime: the Product Security and Telecommunications Infrastructure (PSTI) Act, and the Cyber Security and Resilience Bill, still moving through Parliament as of September 2026 with Royal Assent still pending (our guide to the Bill covers its scope and progress).

We cover the full breakdown of what the CRA requires of manufacturers, importers and distributors, and the reporting mechanics specifically, in companion pieces elsewhere on this site.

Building Your CRA Compliance Roadmap

The CRA's phased timeline works as a planning asset, not just a constraint. Each milestone gives your compliance programme a natural checkpoint. Here's how to use them.

The Four-Phase Compliance Model

  1. Phase 1: Scoping and ownership (complete now if not done): Confirm which products are in scope, assign a compliance owner, and complete an initial gap analysis against Annex I. If you haven't done this, it's the highest-priority action on your list.
  2. Phase 2: Reporting readiness (required immediately): Article 14 is already in force. Your vulnerability disclosure process, ENISA platform registration and internal triage workflow need to be operational right now, three years ahead of the 2027 deadline.
  3. Phase 3: Conformity assessment preparation (now through mid-2027): Prepare technical documentation, complete security testing, and engage a notified body if your product is Class I or Class II. Don't wait: notified body capacity is limited and queues will grow through 2027.
  4. Phase 4: CE marking and declaration of conformity (complete by November 2027): Allow at least four to six weeks before the December 2027 deadline for the final steps: issuing the EU declaration of conformity, affixing the CE marking, and completing any remediation identified during assessment.Key takeaway: The organisations most likely to struggle by December 2027 are the ones still treating the CRA as a future problem. Reporting obligations are live now, conformity assessment queues are building now, and the deadline itself is fixed.

Mapping each of these phases against your own product portfolio is where a structured framework, rather than a spreadsheet rebuilt every quarter, starts to pay for itself. See how Gracie AI Agents with Personas and Skills supports CRA readiness.

See it in action

Turn the CRA Timeline Into a Managed Programme

Gracie AI Agents with Personas and Skills track your CRA milestones against Annex I requirements as they come due, cutting manual evidence collection by up to 65%. See how it fits your compliance timeline.
Google preferred sources
Found this useful?

Choose SureCloud as a preferred source in Google and you will see more of our GRC guidance in Top Stories, AI Overviews and AI Mode. It takes one click and you can undo it at any time.

Your next step
PRICING

See what SureCloud costs

A short form, no sales call. Pricing built around your GRC estate.

Get Pricing
4.2 / 5 · 46 reviews on G2
ANALYST REPORT

IDC names SureCloud the industry's first cross-domain agentic GRC platform"

Read the independent analyst view on how SureCloud is redefining risk and compliance.

Download for free

FAQ’s

When does the Cyber Resilience Act actually apply?

The CRA applies in stages under Article 71: entry into force on 10 December 2024, the notified body framework (Chapter IV) from 11 June 2026, Article 14 reporting obligations from 11 September 2026, and the remaining obligations, including Annex I, conformity assessment and CE marking, from 11 December 2027. Whether the Article 64 fine framework itself formally starts on that same December 2027 date is a point regulatory commentators read differently, so it's worth confirming the position with your Member State authority if it's decision-relevant.

Does the CRA apply to UK manufacturers?

Yes, if they sell products on the EU market. The CRA applies to any product with digital elements placed on the EU market, regardless of where the manufacturer is based, so a UK company selling connected products in any EU member state must comply on the same timeline as an EU-based manufacturer. UK-only sales sit outside the CRA and are governed instead by the Product Security and Telecommunications Infrastructure (PSTI) Act and the still-progressing Cyber Security and Resilience Bill.

What is the 24-hour/72-hour reporting window?

Under Article 14, once a manufacturer becomes aware of an actively exploited vulnerability or a severe security incident affecting an in-scope product, it must submit an early warning within 24 hours, a full notification within 72 hours including an initial impact assessment, and a final report within 14 days of a corrective measure becoming available for vulnerabilities, or within one month of the 72-hour notification for severe incidents. Reports go simultaneously to ENISA via the Single Reporting Platform and to the national CSIRT of the member state where the manufacturer has its main establishment.

What happens to products already on the EU market before December 2027?

Article 69 gives these products a narrow exemption from the substantive Annex I requirements, which holds until the product undergoes a substantial modification that changes its cybersecurity properties or intended purpose. There's no fixed calendar deadline attached to this exemption, despite some guidance that circulates one. The Article 14 reporting obligations apply regardless, to every in-scope product on the EU market since 11 September 2026, whatever the product's original placement date.

When will harmonised standards be available?

The Commission's draft amendment, proposed in July 2026 and not yet formally adopted as of this article's last review, pushes the standardisation deadlines back by two months: the horizontal secure-development and vulnerability-handling standards to 31 October 2026, and the vertical product-specific standards to 31 December 2026. A standard only confers the Article 27 presumption of conformity once its reference is cited in the Official Journal of the EU, so delivery of a draft and its formal availability for use are two different things.