---
title: "EU CRA Compliance Timeline: Key Dates and Deadlines"
description: "The EU Cyber Resilience Act compliance timeline explained: entry into force in December 2024, the September 11, 2026 vulnerability reporting deadline, and full conformity with CE marking by December 11, 2027, plus what to prioritize at each stage."
canonical_url: "https://fossa.com/blog/cra-compliance-timeline/"
markdown_url: "https://fossa.com/blog/cra-compliance-timeline.md"
content_type: "blog"
language: "en"
date_published: "2026-08-06"
date_modified: "2026-08-06"
author: "Andy Drukarev"
organization: "FOSSA"
---

# EU CRA Compliance Timeline: Key Dates and Deadlines

> The EU Cyber Resilience Act compliance timeline explained: entry into force in December 2024, the September 11, 2026 vulnerability reporting deadline, and full conformity with CE marking by December 11, 2027, plus what to prioritize at each stage.

The EU Cyber Resilience Act (CRA) has already been entered into force, but its obligations will be implemented in multiple phases. The vulnerability reporting mandate takes effect in September 2026, and full conformity (including CE marking) is required by December 2027. This post walks through the complete CRA compliance timeline and what to prioritize at each stage.

> Not sure where your organization stands today? Take FOSSA's free [CRA Readiness Assessment](https://fossa.com/resources/regulatory-compliance-tools/cra-readiness-assessment.md) to score your posture against the CRA's essential requirements and get a 30/60/90-day plan mapped to the 2026 and 2027 milestones.

## The CRA Is a Phased Regulation

The Cyber Resilience Act was published in the Official Journal of the EU in November 2024 and entered into force on 10 December 2024. Rather than switching on all at once, its requirements apply on a staggered schedule so manufacturers, notified bodies, and standards organizations have time to prepare.

Two dates matter most: the vulnerability eporting mandate in 2026 and full application in 2027.

## The CRA Compliance Timeline at a Glance

### December 10, 2024: The CRA Enters Into Force

The Cyber Resilience Act (Regulation (EU) 2024/2847) is published and legally binding across the EU. No product-level obligations apply yet, but the compliance clock starts here: the transition periods that follow are measured from this date.

### September 11, 2026: Vulnerability Reporting Obligations Begin

This is the first (and nearest) hard deadline. From this date, manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA and the relevant national CSIRT, starting with a 24-hour early warning from the moment of awareness. A public coordinated vulnerability disclosure (CVD) policy underpins this obligation.

Vulnerabilities that meet the threshold for reporting must be communicated to ENISA via the [Single Reporting Platform](https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp). It's worth noting that ENISA has now standardized a set of data fields that organizations will need to fill out at the different stages of submitting a report. These include information about the affected product, the vulnerability itself, and the nature of the security incident.

### December 11, 2027: Full Conformity and CE Marking Required

The main body of the CRA takes effect in December of 2027. Products with digital elements placed on the EU market from this date must meet all Annex I essential requirements (secure-by-design defaults, vulnerability handling, SBOM and technical documentation, and lifecycle security updates) and carry the CE marking, following the conformity assessment route that matches their product classification. We expect additional technical details for some of these mandates, including the [CRA's SBOM requirement](https://fossa.com/blog/sbom-requirements-cra-cyber-resilience-act.md), to be communicated in the coming months.

## What to Do at Each Stage

**Now → September 2026.** Prioritize the reporting mandate. Publish a coordinated vulnerability disclosure policy, stand up an incident-response workflow that can produce a 24-hour early warning, and put continuous open source vulnerability monitoring in place so active exploitation is caught quickly. Also, ensure you have the tooling and infrastructure to fill out all required data fields (as outlined in Question 16 on [ENISA's Single Reporting Platform Q and A page](https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp/frequently-asked-questions)).

**September 2026 → December 2027.** Close the remaining Annex I gaps: secure-by-design defaults, a machine-readable SBOM, a defined security support period, and decoupled security updates. Complete the conformity assessment route that matches your product classification so you are ready to affix the CE marking.

Although different organizations that face CRA requirements will take different paths to compliance, our strong recommendation is that you start preparation (even for the requirements that take effect in 2027) sooner than later if you haven't already. Many of the CRA's requirements deal with automations and processes that require time to set up and perfect.

  The free CRA Readiness Assessment scores your current posture against the CRA's essential requirements and produces a 30/60/90-day plan mapped to the 2026 and 2027 milestones. No signup is required to run it.

## CRA Timeline and Deadline FAQ

### When does the Cyber Resilience Act take effect?

The Cyber Resilience Act (Regulation (EU) 2024/2847) entered into force on 10 December 2024. Its obligations then phase in: the vulnerability and incident reporting requirements apply from 11 September 2026, and the full set of requirements, including CE marking, applies from 11 December 2027.

### What is the CRA deadline for vulnerability reporting?

Manufacturers must comply with the CRA's reporting obligations from 11 September 2026. From that date, actively exploited vulnerabilities and severe incidents must be reported to ENISA and the relevant national CSIRT, starting with a 24-hour early warning.

### When is full CRA compliance required?

The main body of the CRA, including all Annex I essential requirements and the obligation to affix the CE marking to conformant products, applies from 11 December 2027. Products placed on the EU market from that date must be fully compliant.

### What should we do now to prepare for the CRA?

Because conformity work takes time, most organizations start now: classify their products, stand up vulnerability reporting and a CVD policy ahead of the 2026 deadline, automate SBOM generation and open source monitoring, and close secure-by-design and lifecycle gaps well before the December 2027 deadline.

*This post is directional guidance for planning, not legal advice; consult qualified counsel for a formal conformity determination. Primary sources: [Regulation (EU) 2024/2847 (EUR-Lex)](https://eur-lex.europa.eu/eli/reg/2024/2847/oj), the [European Commission's CRA policy page](https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act), and [ENISA](https://www.enisa.europa.eu/).*

## Related resources

- [SBOM Requirements in the EU’s CRA (Cyber Resilience Act)](https://fossa.com/blog/sbom-requirements-cra-cyber-resilience-act.md): An overview of the Cyber Resilience Act (CRA) and its implications for SBOM requirements, diving into its standards and comparisons to global initiatives.

## Source

Canonical page: https://fossa.com/blog/cra-compliance-timeline/
