Cyber Resilience Act deadlines

Three dates, only one of which creates an immediate obligation for most manufacturers today. Here is what applies when, and what has to be done beforehand.

The timeline

11 June 2026Chapter IV: designation of notified bodies. No direct obligation for manufacturers, but it is the precondition for any third-party assessment — worth watching if your product falls under class II or Annex IV.
11 September 2026Reporting obligations (Art. 14): any actively exploited vulnerability and any severe incident affecting the security of the product must be notified to the designated CSIRT and to ENISA.First deadline
11 December 2027General application: essential requirements of Annex I, technical documentation, conformity assessment, EU declaration of conformity and CE marking.

Reporting: deadlines counted in hours

This is the most frequently underestimated obligation, because it cannot be improvised: it assumes you have already decided who decides, who drafts and who notifies — before the incident.

StageDeadlineWhat it contains
Early warning24 hoursAs soon as the reportable event becomes known.
Notification72 hoursThe technical details available and, where applicable, the corrective or mitigating measures taken.
Final report — vulnerability14 daysAfter a corrective or mitigating measure has been made available.
Final report — incident1 monthAfter the 72-hour notification.

These deadlines run from the moment the manufacturer becomes aware of the reportable event — not from the internal decision to act on it.

A backwards plan that holds

This sequencing is not in the Regulation: it is the order in which the work unblocks most easily, each step enabling the next.

By the end of 2026 — the reporting chain

Appoint the point of contact, write the procedure, identify the competent CSIRT, run one dry run. Inexpensive, and it is the only deadline already in force.

First half of 2027 — the inventory

Build the software bill of materials, map the dependencies, plug vulnerability monitoring into it. Nothing else can be verified until the inventory exists.

Second half of 2027 — the evidence

Technical documentation (Annex VII), risk assessment, conformity assessment procedure, EU declaration and CE marking. If a notified body is required, contact one well ahead.

What does not stop at a date

Vulnerability handling and the supply of security updates run throughout the product's support period. It is not a milestone to clear, it is a process to sustain.

Frequently asked questions

What happens if I am not ready by 11 September 2026?

The reporting obligations apply from that date. An actively exploited vulnerability that goes unreported is a breach, regardless of how far along the rest of your compliance work is.

Can I wait until 2027 to start?

The first deadline only covers reporting. But the work due by 11 December 2027 — software bill of materials, technical documentation, conformity assessment — is measured in months, and access to a notified body needs anticipating for class II and Annex IV products.

Who do you notify?

The CSIRT designated as coordinator and ENISA, following the arrangements set out in Article 14 of the Regulation.

Can these dates change?

The dates quoted here are those set by Regulation (EU) 2024/2847 as published. Any change would require an amending act published in the Official Journal of the European Union.

Source: Regulation (EU) 2024/2847, Articles 14 and 71.

Know what is coming, and when

The assessment sorts your gaps by deadline: what belongs to September 2026, what belongs to December 2027, and what runs continuously.

Start the free assessment

Understanding the CRA, topic by topic

FirmVox is a compliance assistance tool. It is not legal advice and does not replace consulting the official text or qualified counsel.

CRA deadlines: 11 September 2026 and 11 December 2027 — FirmVox