Skip to main content
FOSSA Logo

EU CRA Compliance Timeline: Key Dates and Deadlines

July 8, 2026 · 4 min read·Andy Drukarev
EU CRA Compliance Timeline: Key Dates and Deadlines

The EU Cyber Resilience Act (CRA) is already in force, but its obligations arrive in waves. The vulnerability reporting mandate lands in September 2026, and full conformity (including CE marking) is required by December 2027. This post walks through the complete CRA compliance timeline and what to prioritize at each stage.

Not sure where your organization stands today? Take FOSSA's free CRA Readiness Assessment to score your posture against the CRA's essential requirements and get a 30/60/90-day plan mapped to the 2026 and 2027 milestones.

The CRA Is a Phased Regulation

The Cyber Resilience Act was published in the Official Journal of the EU in November 2024 and entered into force on 10 December 2024. Rather than switching on all at once, its requirements apply on a staggered schedule so manufacturers, notified bodies, and standards organizations have time to prepare.

Two dates matter most: the reporting mandate in 2026 and full application in 2027.

The CRA Compliance Timeline at a Glance

December 10, 2024: The CRA Enters Into Force

The Cyber Resilience Act (Regulation (EU) 2024/2847) is published and legally binding across the EU. No product-level obligations apply yet, but the compliance clock starts here: the transition periods that follow are measured from this date.

September 11, 2026: Vulnerability Reporting Obligations Begin

This is the first (and nearest) hard deadline. From this date, manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA and the relevant national CSIRT, starting with a 24-hour early warning from the moment of awareness. A public coordinated vulnerability disclosure (CVD) policy underpins this obligation.

For a full breakdown of the 24-hour, 72-hour, and 14-day reporting stages, see our guide to CRA vulnerability reporting requirements.

December 11, 2027: Full Conformity and CE Marking Required

The main body of the CRA applies. Products with digital elements placed on the EU market from this date must meet all Annex I essential requirements (secure-by-design defaults, vulnerability handling, SBOM and technical documentation, and lifecycle security updates) and carry the CE marking, following the conformity assessment route that matches their product classification.

What to Do at Each Stage

Now → September 2026. Prioritize the reporting mandate. Publish a coordinated vulnerability disclosure policy, stand up an incident-response workflow that can produce a 24-hour early warning, and put continuous open source vulnerability monitoring in place so active exploitation is caught quickly.

September 2026 → December 2027. Close the remaining Annex I gaps: secure-by-design defaults, a machine-readable SBOM for your technical documentation (see our breakdown of SBOM requirements in the CRA), a defined security support period, and decoupled security updates. Complete the conformity assessment route that matches your product classification so you are ready to affix the CE marking.

Because independent conformity assessment and standards adoption take time, waiting until 2027 is risky. The organizations that fare best treat the 2026 reporting deadline as the near-term forcing function and use the runway to build the rest.

See How Ready You Are for Each Deadline

The free CRA Readiness Assessment scores your current posture against the CRA's essential requirements and produces a 30/60/90-day plan mapped to the 2026 and 2027 milestones. No signup is required to run it.

Launch the CRA Readiness Assessment

CRA Timeline and Deadline FAQ

When does the Cyber Resilience Act take effect?

The Cyber Resilience Act (Regulation (EU) 2024/2847) entered into force on 10 December 2024. Its obligations then phase in: the vulnerability and incident reporting requirements apply from 11 September 2026, and the full set of requirements, including CE marking, applies from 11 December 2027.

What is the CRA deadline for vulnerability reporting?

Manufacturers must comply with the CRA's reporting obligations from 11 September 2026. From that date, actively exploited vulnerabilities and severe incidents must be reported to ENISA and the relevant national CSIRT, starting with a 24-hour early warning.

When is full CRA compliance required?

The main body of the CRA, including all Annex I essential requirements and the obligation to affix the CE marking to conformant products, applies from 11 December 2027. Products placed on the EU market from that date must be fully compliant.

What should we do now to prepare for the CRA?

Because conformity work takes time, most organizations start now: classify their products, stand up vulnerability reporting and a CVD policy ahead of the 2026 deadline, automate SBOM generation and open source monitoring, and close secure-by-design and lifecycle gaps well before the December 2027 deadline.

This post is directional guidance for planning, not legal advice; consult qualified counsel for a formal conformity determination. Primary sources: Regulation (EU) 2024/2847 (EUR-Lex), the European Commission's CRA policy page, and ENISA.

Subscribe to our newsletter

Get the latest insights on open source license compliance and security delivered to your inbox.