The Cyber Resilience Act key deadlines at a glance

The Cyber Resilience Act key deadlines at a glance

The Cyber Resilience Act introduces horizontal cybersecurity requirements for products with digital elements made available on the Union market. Its main obligations apply from 11 December 2027, with earlier dates for the rules on notification of conformity-assessment bodies and manufacturers' reporting duties.

What the Cyber Resilience Act means for businesses

Regulation (EU) 2024/2847, known as the Cyber Resilience Act (CRA), sets horizontal cybersecurity requirements for products with digital elements made available on the Union market. Whether it applies will depend on the product, the organisation's role and the Regulation's scope rules and exclusions.

The CRA sets different obligations for manufacturers, importers and distributors. Coverage must be assessed product by product under the Regulation's scope rules and exclusions.

Products placed on the market before 11 December 2027 are generally subject to the Regulation only where they are substantially modified after that date. The reporting requirements in Article 14 are separate: they also apply to in-scope products placed on the market before that date.

Requirements in brief

Manufacturers must ensure that their products are designed, developed and produced in line with the applicable cybersecurity requirements. They must also carry out and document a product-specific cybersecurity risk assessment and handle vulnerabilities in accordance with Annex I Part II.

The required conformity-assessment route depends on the product classification and the route used. Internal control may be available in some cases, while others may require third-party involvement. The Regulation does not mean that every product requires a notified body or certification.

The key dates

Date Milestone
20 November 2024 The CRA was published in the Official Journal of the European Union.
10 December 2024 The Regulation entered into force, 20 days after publication.
11 June 2026 Chapter IV, Articles 35 to 51, on the notification of conformity-assessment bodies became applicable. This is not the general start date for manufacturers' conformity-assessment obligations.
11 September 2026 Article 14 will apply from this date. It requires manufacturers to report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements.
11 December 2027 The Regulation applies generally. The main product, manufacturer and conformity requirements become applicable.

Article 35 also states that Member States should strive to ensure that a sufficient number of notified bodies are available in the Union by 11 December 2026.

What to prepare now

Start by establishing the products in scope and your role in the supply chain. From there, teams can classify products, identify the appropriate conformity-assessment route and prepare the supporting technical documentation and vulnerability-management arrangements.

It is sensible to treat Article 14 reporting as a separate workstream from the wider product-conformity preparations for 11 December 2027. Organisations that may need a notified body may also wish to assess their likely route early, given the Regulation's aim of avoiding capacity bottlenecks.

Need help implementing cyber regulation?

Talk to Secuvi →