Cyber Resilience Act timeline: 2026 to 2027 deadlines
News · Upcoming deadline
On 11 September 2026, a little over three weeks from now, article 14 of Regulation (EU) 2024/2847 starts to apply: any manufacturer of a product with digital elements must report actively exploited vulnerabilities and severe incidents, with an early warning within 24 hours, through the single platform operated by ENISA. This is the first binding obligation under the Cyber Resilience Act; the main obligations, CE marking included, follow on 11 December 2027.
In short:
- Reporting under article 14 applies from 11 September 2026, with no transitional period.
- The cascade is short: early warning within 24 hours, notification within 72 hours, final report within 14 days or one month.
- Reports go through the ENISA single platform, announced as operational on that date and not yet open.
- The obligation covers products already on the market, not only new launches.
- The main obligations, CE marking included, remain fixed at 11 December 2027.
Regulation (EU) 2024/2847, known as the Cyber Resilience Act (CRA), entered into force on 10 December 2024 and applies in stages. The stage that commits product teams arrives now: from 11 September 2026, a manufacturer that becomes aware of an actively exploited vulnerability has 24 hours to issue an early warning. This is not a design requirement that can be caught up at the end of a project, it is an operational capability that has to exist on the day.
A horizontal regulation, not a directive
Section titled “A horizontal regulation, not a directive”The CRA is a regulation, directly applicable in every Member State without national transposition. It covers products with digital elements, hardware and software, whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network.
Unlike article 3.3 of the RED directive, which targets only radio equipment, its scope is far broader: a wired sensor, a gateway, a software library or a microcontroller connected over Ethernet all fall within it.
When does the Cyber Resilience Act apply?
Section titled “When does the Cyber Resilience Act apply?”The CRA follows a multi-phase ramp-up. The milestones confirmed by the official texts are as follows:
| Date | Milestone |
|---|---|
| 10 December 2024 | Entry into force of Regulation (EU) 2024/2847 |
| 11 June 2026 | Application of Chapter IV, on the notification of conformity assessment bodies |
| 11 September 2026 | Application of reporting obligations for actively exploited vulnerabilities and severe incidents |
| 11 December 2027 | Full application of the main obligations, including conformity assessment and CE marking |
The 10 December 2024 entry into force triggered no immediate obligation for manufacturers. The June 2026 milestone concerns Member States and conformity assessment bodies rather than manufacturers directly.
First binding deadline: reporting
Section titled “First binding deadline: reporting”From 11 September 2026, manufacturers must notify actively exploited vulnerabilities and severe incidents affecting the security of their products. Article 14 sets a cascade of three deadlines:
| Deadline | What is due |
|---|---|
| 24 hours | Early warning to ENISA and the competent national CSIRT, from becoming aware |
| 72 hours | Full notification, including any corrective or mitigating measures taken |
| 14 days | Final report, from the point a corrective measure is available for an actively exploited vulnerability. The deadline is one month for a severe incident |
The obligation covers products already on the market, including units shipped years ago, and a 24-hour deadline presupposes a triage process already running, not an organisation improvised when the alert lands.
The ENISA single platform
Section titled “The ENISA single platform”Reporting is done neither by email nor to each national authority separately: it goes through the Single Reporting Platform (SRP) operated by ENISA, which routes the notification to the agency and to the competent CSIRT. ENISA states that the platform will be used for mandatory reporting by manufacturers and by each national CSIRT from 11 September 2026, with voluntary reporting enabled after that date. It is not yet open.
Three points stand out from the agency's published documentation:
- Access rests on an EU Login account, created by the assigned representatives of manufacturers and open-source software stewards.
- ENISA advises starting registration and validation when a notification actually has to be filed, rather than well in advance.
- No application programming interface is provided at this stage: submission is manual, even if the internal chain feeding it can be tooled.
The platform factsheet is dated July 2026 and the guides for assigned representatives were updated on 3 and 14 August 2026: the operational documentation is settling only weeks before the deadline.
What has to exist on 11 September
Section titled “What has to exist on 11 September”The text imposes no particular organisation, but a 24-hour deadline imposes one in practice:
- A monitored entry point for vulnerability reports, triaged in hours rather than days.
- An inventory of products still sold or still supported, with software versions and SBOM.
- A named decision chain: who rules on active exploitation, who authorises the early warning.
- An EU Login account and a registration route identified before they are needed.
Full application: December 2027
Section titled “Full application: December 2027”From 11 December 2027, the main obligations apply in full: essential cybersecurity requirements, conformity assessment matched to the product category, EU declaration of conformity and CE marking. That is the date to aim for on any product placed on the market.
The clarifications published in 2026
Section titled “The clarifications published in 2026”Three texts have sharpened how the regulation applies, and they change how a file should be prepared.
Implementing Regulation (EU) 2025/2392 sets out the technical descriptions of the important and critical product categories listed in Annexes III and IV. That classification determines which conformity assessment procedure applies, and therefore the volume of testing, the documentation and whether a third party is involved.
Delegated Regulation (EU) 2026/881, adopted on 11 December 2025, specifies the conditions under which a CSIRT may delay the dissemination of a notification on cybersecurity grounds. The decision to hold information back therefore sits with the authority, not with the manufacturer.
On 27 July 2026, the Commission published its guidance under article 26. Non-binding, it works through scope by example, covering remote data processing solutions, free and open source software, substantial modification and the support period. It is the reading market surveillance authorities and notified bodies will apply.
What does the CRA require of manufacturers?
Section titled “What does the CRA require of manufacturers?”The essential requirements cover the product across its whole lifecycle:
- Security by design: minimal attack surface, secure default configuration, no identical factory password across all units.
- Vulnerability handling throughout the declared support period: coordinated handling, patches, disclosure policy.
- Security updates available and, where relevant, automatic, signed and verifiable.
- Software bill of materials (SBOM) documenting at least the top-level dependencies.
- Support period declared and communicated to the user.
For a product already subject to RED 3.3, part of the work (risk analysis, secret handling, signed updates) can be shared, but the two frameworks remain distinct.
Connection to RED and CE marking
Section titled “Connection to RED and CE marking”The CRA fits the CE marking logic: it adds essential requirements assessed within the EU declaration of conformity, without creating a separate marking. Delegated Regulation (EU) 2026/339, published on 29 April 2026, repeals Delegated Regulation (EU) 2022/30 with effect from 11 December 2027, the day the CRA applies in full. No lasting double regime, then, but the RED 3.3 requirements remain applicable until that date: between 11 September 2026 and 11 December 2027, a connected radio product sits under both frameworks, on different grounds.
The declared support period commits the manufacturer to years of vulnerability handling. It is not an end-of-project formality but an architecture parameter, driving component choice, remote-update capability and the maintenance model.
Key takeaways
Section titled “Key takeaways”- Reporting of actively exploited vulnerabilities and severe incidents applies from 11 September 2026.
- Cascade: 24 hours, 72 hours, then a final report at 14 days or one month depending on the case.
- Reports go through the ENISA single platform, via an EU Login account, with no programming interface at this stage.
- The CRA is horizontal: connected hardware and software, radio and non-radio alike.
- Full application, including conformity assessment and CE marking, lands on 11 December 2027.
Going further
Section titled “Going further”- Cyber Resilience Act guide: scope, product classes and assessment routes
- CE scope: applicable directives and regulations
- RED harmonised standards: radio cybersecurity and presumption of conformity
Sources & references
- Regulation (EU) 2024/2847, Cyber Resilience Act , EUR-Lex eur-lex.europa.eu/eli/reg/2024/2847/oj
- Cyber Resilience Act, summary and timeline , European Commission digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act
- The Cyber Resilience Act, summary of the legislative text , European Commission digital-strategy.ec.europa.eu/en/policies/cra-summary
- CRA reporting obligations , European Commission digital-strategy.ec.europa.eu/en/policies/cra-reporting
- Commission guidance supporting CRA implementation, 27 July 2026 , European Commission digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation
- Single Reporting Platform (SRP) , ENISA www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp
- Single Reporting Platform, frequently asked questions , ENISA www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp/frequently-asked-questions