Cyber Resilience Act deadlines
Three dates, only one of which creates an immediate obligation for most manufacturers today. Here is what applies when, and what has to be done beforehand.
The timeline
Reporting: deadlines counted in hours
This is the most frequently underestimated obligation, because it cannot be improvised: it assumes you have already decided who decides, who drafts and who notifies — before the incident.
| Stage | Deadline | What it contains |
|---|---|---|
| Early warning | 24 hours | As soon as the reportable event becomes known. |
| Notification | 72 hours | The technical details available and, where applicable, the corrective or mitigating measures taken. |
| Final report — vulnerability | 14 days | After a corrective or mitigating measure has been made available. |
| Final report — incident | 1 month | After the 72-hour notification. |
These deadlines run from the moment the manufacturer becomes aware of the reportable event — not from the internal decision to act on it.
A backwards plan that holds
This sequencing is not in the Regulation: it is the order in which the work unblocks most easily, each step enabling the next.
By the end of 2026 — the reporting chain
Appoint the point of contact, write the procedure, identify the competent CSIRT, run one dry run. Inexpensive, and it is the only deadline already in force.
First half of 2027 — the inventory
Build the software bill of materials, map the dependencies, plug vulnerability monitoring into it. Nothing else can be verified until the inventory exists.
Second half of 2027 — the evidence
Technical documentation (Annex VII), risk assessment, conformity assessment procedure, EU declaration and CE marking. If a notified body is required, contact one well ahead.
What does not stop at a date
Vulnerability handling and the supply of security updates run throughout the product's support period. It is not a milestone to clear, it is a process to sustain.
Frequently asked questions
What happens if I am not ready by 11 September 2026?
The reporting obligations apply from that date. An actively exploited vulnerability that goes unreported is a breach, regardless of how far along the rest of your compliance work is.
Can I wait until 2027 to start?
The first deadline only covers reporting. But the work due by 11 December 2027 — software bill of materials, technical documentation, conformity assessment — is measured in months, and access to a notified body needs anticipating for class II and Annex IV products.
Who do you notify?
The CSIRT designated as coordinator and ENISA, following the arrangements set out in Article 14 of the Regulation.
Can these dates change?
The dates quoted here are those set by Regulation (EU) 2024/2847 as published. Any change would require an amending act published in the Official Journal of the European Union.
Source: Regulation (EU) 2024/2847, Articles 14 and 71.