Reporting is already live. The big design, documentation and conformity obligations apply from 11 December 2027. The time left is the time to design, test and document properly.
Key dates
| Date | What applies | Status | Source |
|---|---|---|---|
| 10 December 2024 | Regulation entered into force | Past | Article 71(1) |
| 11 June 2026 | Chapter IV, notification of conformity assessment bodies (Articles 35 to 51) | Already applicable | Article 71(2) |
| 11 September 2026 | Manufacturer reporting of actively exploited vulnerabilities and severe incidents (Article 14) | Already applicable | Article 71(2) |
| 11 December 2027 | The rest of the Regulation, including Annex I requirements, conformity assessment and CE marking | Upcoming | Article 71(2) |
Products already on the market
Products placed on the market before 11 December 2027 are subject to the Regulation’s requirements only if they undergo a substantial modification from that date (Article 69(2)). The reporting obligations in Article 14 are an exception: they apply to all in-scope products, including those placed on the market before 11 December 2027 (Article 69(3)).
Standards
The Commission has adopted standardisation request M/606 with 41 standards. Products that conform to harmonised standards whose references are published benefit from a presumption of conformity.
Planning to start in 2027. Risk assessment, secure development changes, SBOM and vulnerability processes and testing take months, and the first batch of reporting duties is already in force.
We help manufacturers turn this requirement into a process and evidence.
Related guidance
- CRA reporting obligations: 24 hours, 72 hours and final report
- Cyber Resilience Act (CRA): what it is and what it requires
This guidance explains the regulation and gives practical recommendations. It is not legal advice. Regulatory facts and recommendations are labelled separately. See our editorial policy (Slovenian): editorial policy.