CRA Timeline
Key dates and deadlines for the Cyber Resilience Act
Vulnerability Reporting Starts
September 11, 2026
You MUST report exploited vulnerabilities to EU authorities.
Action: Set up internal processes for 24h/72h/14-day reporting
Quick Facts
CRA Timeline
CRA Enters into Force
The regulation officially becomes EU law.
View Details
Technical Descriptions Due
EU defines exactly what products fall into each category.
View Details
Notified Bodies Ready
Third-party auditors available for Class II/Critical products.
View Details
Vulnerability Reporting Starts
You MUST report exploited vulnerabilities to EU authorities.
View Details
ENISA Technical Trend Report
ENISA publishes its first report on emerging cybersecurity risk trends.
View Details
CRA Fully Applies
All products MUST be compliant. Fines start.
View Details
Legacy Certificate Deadline
EU type-examination certificates and approval decisions issued before the CRA stop being valid.
View Details
Commission Evaluation
EU reviews how well the CRA is working.
View Details
Ready to Start Your Compliance Journey?
Use our free assessment tool to understand your CRA obligations.