Compliance Calendar

CRA Timeline

Key dates and deadlines for the Cyber Resilience Act

Next Milestone Critical Deadline
6 days

Vulnerability Reporting Starts

September 11, 2026

You MUST report exploited vulnerabilities to EU authorities.

Action: Set up internal processes for 24h/72h/14-day reporting

Quick Facts

Minimum Support Period 5 years (or product lifetime if less)
Security Update Availability At least 10 years after each update is issued, or the remainder of the support period, whichever is longer
Documentation Retention At least 10 years after placed on market, or the support period, whichever is longer
SBOM Required For all products with digital elements

CRA Timeline

December 10, 2024 Preparation Phase Completed

CRA Enters into Force

The regulation officially becomes EU law.

View Details

Detail: 20 days after publication in Official Journal (Nov 20, 2024).

Action: Begin gap analysis and compliance planning

Reference: Article 71.1

December 11, 2025 Preparation Phase Completed

Technical Descriptions Due

EU defines exactly what products fall into each category.

View Details

Detail: Commission implementing act specifying technical descriptions for Important and Critical product categories.

Action: Review if your product falls under Important/Critical classification

Reference: Article 7.4

June 11, 2026 Transition Phase Completed

Notified Bodies Ready

Third-party auditors available for Class II/Critical products.

View Details

Detail: Conformity assessment body notification provisions apply.

Action: Identify and contact Notified Bodies if third-party assessment required

Reference: Articles 35-51

September 11, 2026 Transition Phase Critical Deadline

Vulnerability Reporting Starts

You MUST report exploited vulnerabilities to EU authorities.

View Details

Detail: Mandatory reporting of actively exploited vulnerabilities and severe incidents to ENISA and national CSIRTs.

Action: Set up internal processes for 24h/72h/14-day reporting

Reference: Article 14

Reporting Requirements:
  • 24 hours - Initial notification
  • 72 hours - Detailed vulnerability information
  • 14 days - Corrective measures and final report
6 days remaining
September 11, 2028 Full Enforcement

ENISA Technical Trend Report

ENISA publishes its first report on emerging cybersecurity risk trends.

View Details

Detail: ENISA publishes a technical report, based on Article 14/15 notifications received, on emerging trends regarding cybersecurity risks in products with digital elements; a report is due every 24 months thereafter.

Action: Review the report for relevant risk trends in your product category

Reference: Article 17.3

737 days remaining
December 11, 2027 Full Enforcement Critical Deadline

CRA Fully Applies

All products MUST be compliant. Fines start.

View Details

Detail: All essential cybersecurity requirements and conformity assessment procedures apply.

Action: Ensure all products meet Annex I requirements with CE marking

Reference: Article 71.2

Penalties:
  • Essential requirements: Up to €15M or 2.5% of turnover
  • Other requirements: Up to €10M or 2% of turnover
  • Incorrect info: Up to €5M or 1% of turnover
462 days remaining
June 11, 2028 Full Enforcement

Legacy Certificate Deadline

EU type-examination certificates and approval decisions issued before the CRA stop being valid.

View Details

Detail: EU type-examination certificates and approval decisions issued under other Union law before this transitional deadline remain valid only until this date.

Action: Confirm any legacy certificates you rely on remain valid, or complete CRA conformity assessment before this date

Reference: Article 69.1

645 days remaining
December 11, 2030 Review Phase

Commission Evaluation

EU reviews how well the CRA is working.

View Details

Detail: European Commission evaluates and reports on CRA effectiveness and implementation.

Action: Provide feedback to industry associations for EU review

Reference: Article 70.1

1558 days remaining

Ready to Start Your Compliance Journey?

Use our free assessment tool to understand your CRA obligations.