EU Cybersecurity
EU Cyber Resilience Act: deadlines, obligations & 2026 timeline
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) entered into force in December 2024. Its reporting obligations have applied since 11 September 2026, when ENISA's Single Reporting Platform went live; its main obligations apply from 11 December 2027. It covers nearly every product with digital elements sold into the EU.
Next deadline: 11 December 2026 · 68 days
Deadline timeline
-
Entry into force · passed
Regulation (EU) 2024/2847 enters into force; the phased application clock starts.
Applies to: All products with digital elements
Source ↗ -
Delegated act on withheld notifications adopted · passed
The Commission adopts a delegated act (published as Regulation (EU) 2026/881) specifying the terms and conditions under which a CSIRT may, on justified cybersecurity grounds, delay disseminating a manufacturer's notification to other CSIRTs through the Single Reporting Platform.
Applies to: CSIRTs; manufacturers submitting reports through the Single Reporting Platform
Source ↗ -
Product-class technical descriptions take effect · passed
Commission Implementing Regulation (EU) 2025/2392 takes effect, setting out the technical descriptions of the important (Annex III) and critical (Annex IV) product categories so manufacturers can classify products and determine their conformity assessment route.
Applies to: Manufacturers of important and critical products with digital elements
Source ↗ -
Conformity assessment bodies · passed
Provisions on the notification of conformity assessment bodies begin to apply.
Applies to: Notified/conformity assessment bodies
Source ↗ -
First Commission implementation guidance · passed
The Commission publishes its first set of practical guidance on CRA implementation. Section 9.1 covers the reporting obligations; the accompanying implementation FAQ covers reporting in Section 5.
Applies to: Manufacturers, importers, distributors of products with digital elements
Source ↗ -
Reporting obligations apply; Single Reporting Platform live · passed
Manufacturers must report actively exploited vulnerabilities and severe incidents through the Single Reporting Platform: an early warning within 24 hours, a full notification within 72 hours, and a final report no later than 14 days after a corrective measure is available for an actively exploited vulnerability, or within one month for a severe incident. ENISA deployed the platform's initial operating capability the same day; registration runs on an EU Login account with multi-factor authentication.
Applies to: Manufacturers of products with digital elements
Source ↗ -
Conformity assessment bodies notified
Target date for sufficient conformity assessment bodies to be notified across Member States, so that manufacturers needing third-party assessment have capacity available before full application.
Applies to: Manufacturers of important (Annex III) and critical (Annex IV) products
Source ↗ -
Main obligations apply
Full application: essential cybersecurity requirements (Annex I), CE marking, conformity assessment, and technical documentation. The Article 24(3) reporting obligations for open-source software stewards also apply from this date (Article 71(2)).
Applies to: Manufacturers, importers, distributors; open-source software stewards (reporting only)
Source ↗
Who’s in scope
- Any product with digital elements — hardware or software — whose use includes a direct or indirect data connection to a device or network
- Smart consumer electronics, industrial IoT, embedded components, and standalone software
Exclusions
- Medical devices under MDR/IVDR (Article 2(2))
- Motor vehicles under the EU type-approval regime (Article 2(2)(c)) — but the same systems sold separately remain in scope
- Civil aviation products (Article 2(3)) and marine equipment (Article 2(4))
- Products developed exclusively for national security or defence (Article 2(7))
The Cyber Resilience Act phases in over three years. The first obligation is now live: since 11 September 2026 the vulnerability and incident reporting duty binds every manufacturer of a product with digital elements — an early warning to ENISA within 24 hours of becoming aware of an actively exploited vulnerability or severe incident, and a substantive notification within 72 hours. The final report runs on two different clocks — no later than 14 days after a corrective measure is available for an actively exploited vulnerability, but within one month for a severe incident. The “becoming aware” trigger is wide — the clock starts at first credible internal awareness, not formal escalation — so if the reporting decision is not yet written into your incident-response runbook, that is the gap to close first.
Reports go through one route only. Manufacturers file once, into the CRA Single Reporting Platform that ENISA established under Article 16; the notification is addressed to the CSIRT of the manufacturer’s main establishment and, absent exceptional circumstances, reaches ENISA at the same time. That receiving CSIRT then shares it with the CSIRTs of every other Member State where the product has been made available. ENISA switched on the platform’s initial operating capability on 11 September 2026, with registration through an EU Login account with multi-factor authentication, and has said it will expand the platform’s functions over the following months. Its user manual, FAQ and glossary sit on ENISA’s Single Reporting Platform page. Register and validate the channel before you need it — a first login during a live 24-hour clock is the failure mode to design out.
The heavier lift lands on 11 December 2027, when the essential cybersecurity requirements in Annex I, CE marking, conformity assessment, and technical documentation all apply. Reporting failures sit in the top penalty tier under Article 64 — up to €15 million or 2.5% of worldwide annual turnover — so this is not a regime to treat as low-stakes. The default assumption for any regulated hardware product is that the CRA applies until you have verified a specific exclusion holds.
Since 27 July 2026 there is also a first set of Commission implementation guidance, with the reporting obligations covered in its Section 9.1 and in Section 5 of the accompanying implementation FAQ. If you have been working from the legal text alone, that guidance is the closest thing to an official answer on the questions manufacturers actually ask.
For the operational detail on the reporting workflow itself, see the deep dive: What the EU CRA’s September 2026 reporting obligation requires.
Last reviewed . Deadlines change — always confirm against the cited primary source.