Cyber Resilience Act timeline: what you must have ready and when

By the QuantumSec team

The Cyber Resilience Act doesn't have a single date of entry into force. It has three critical milestones spread between 2024 and 2027, and understanding exactly what each one requires is essential to plan your compliance without last-minute rushes. If you manage the development of software products or connected hardware, this timeline is the first thing you need to know.

23 October 2024: the CRA is already in force

Regulation (EU) 2024/2847 entered into force in October 2024. This milestone does not yet impose direct technical obligations on manufacturers, but it has immediate practical consequences: products being designed and developed right now will be assessed against the CRA requirements when they reach the market. If you launch a new product in 2026 or 2027 that is in the design phase today, the CRA already applies to that product's entire lifecycle. Companies with long development cycles —industrial hardware, embedded systems, connected medical devices— have to start the compliance process now so they don't discover at the end of 2027 that the product going into production cannot carry the cybersecurity CE marking.

11 August 2026: the first hard deadline — reporting vulnerabilities to ENISA

This is the first deadline with concrete enforceable obligations and the one most companies are underestimating. From 11 August 2026, manufacturers of products with digital elements must notify ENISA of: (1) any vulnerability in their product that is being actively exploited in the wild, within 24 hours of becoming aware of it (early warning); (2) a full vulnerability notification within the following 72 hours; (3) a final report within 14 days. This requires having an operational, structured vulnerability monitoring process, a channel to receive security reports, an internal escalation and verification protocol, and a system to communicate with ENISA. In parallel, from August 2026 the obligation to report security incidents with a significant impact on the security of the product's users also applies.

11 September 2026: notified bodies must be operational

For Class I and Class II products that require third-party conformity assessment, the notified bodies that will carry out those audits must be designated by the Member States no later than 11 September 2026. This deadline has implications for manufacturers: if your product requires third-party assessment, as soon as the notified bodies are operational you will be able to start the formal certification process. Manufacturers of Class I and II products must plan well in advance to complete the assessment before 11 December 2027, bearing in mind that notified bodies will face high demand in the months leading up to the deadline.

11 December 2027: full application of the CRA

This is the date of full application of all CRA requirements. From this day on, any product with digital elements placed on the European market for the first time must: (1) fully comply with the essential requirements of Annex I; (2) have completed the conformity assessment procedure corresponding to its category; (3) hold the EU declaration of conformity issued by the manufacturer; (4) bear the cybersecurity CE marking. Products that fail to meet these requirements may not be distributed in the EU from this date. National market surveillance authorities will have the power to withdraw non-compliant products from the market and impose penalties on manufacturers, importers and distributors.

The grace period for products already on the market

Products that were placed on the market before 11 December 2027 but are still in the distribution channel have a 36-month grace period, until 11 December 2030, to sell off that inventory. This applies strictly to physical products that have already been manufactured and are in the distribution channel, not to software that continues to be developed or updated. From 11 December 2030, only products with digital elements bearing the cybersecurity CE marking will be allowed on the European market.

How to plan your compliance by time horizon

For manufacturers starting now: the immediate priority should be to enable a channel to receive vulnerability reports (security.txt, a security contact form or a bug bounty platform), document a minimum vulnerability assessment and response process, and prepare access to the ENISA reporting platform before 11 August 2026. For the December 2027 deadline, full compliance requires working on three fronts in parallel: (1) classify every product into its CRA category and determine the type of conformity assessment required; (2) implement the technical requirements of Annex I in the development process (secure SDLC); (3) prepare the technical documentation and the EU declaration of conformity. Companies with experience in product certifications (CE, ISO/IEC 27001, IEC 62443) will start with an advantage, as many controls are reusable.

FAQ

What happens if I don't notify ENISA of an actively exploited vulnerability within the 24-hour deadline?

Failure to comply with the ENISA notification obligation can lead to penalties of up to 10 million euros or 2% of global annual turnover. National market surveillance authorities are responsible for investigating and imposing these penalties.

Do the CRA deadlines also apply to software updates?

The obligations to report actively exploited vulnerabilities apply to all products with digital elements on the market, regardless of whether they have been recently updated. If a vulnerability affects versions of your software that are in use by customers, the obligation to notify ENISA applies from August 2026.