Cyber Resilience Act Timeline: What Actually Happens in 2026 and 2027
Most coverage flattens the Cyber Resilience Act into a single date in December 2027. That framing costs you a year.

Larry Pesce
VP of Services
The CRA rolls out across four fixed milestones, and the next one lands on September 11, 2026. It reaches the products you shipped years ago alongside the ones on your 2028 roadmap, which makes 2026 an active compliance year.
Below is every milestone in order, what switches on at each one, why Brussels wrote a 36-month transition period instead of a 12-month one, and the sequence a hardware team should work in if product security became someone's job last month.
The Cyber Resilience Act timeline at a glance
| Date | What applies | Who feels it first |
|---|---|---|
| December 10, 2024 | Regulation enters into force. Transition period begins. | Everyone selling connected products in the EU |
| June 11, 2026 | Framework for notifying conformity assessment bodies applies | Makers of important and critical product classes needing third-party assessment |
| Through 2026 | First harmonized standards start landing | Any team that wants a presumption of conformity |
| September 11, 2026 | Reporting obligations go live | Every manufacturer with products already on the EU market |
| December 11, 2027 | Full application. CE marking required. | Anything placed on the EU market from that date forward |
Two of those dates are about visibility. One is about the product itself. Treat them as one deadline and you'll be late for the first one.
December 10, 2024: the clock started
The regulation entered into force. Nothing became enforceable that day, but the transition period everyone is living through now began, and every downstream date counts from here.
If you want the substance of what the regulation asks for rather than when it asks, start with the EU Cyber Resilience Act explainer and come back to the calendar.
June 11, 2026: the conformity assessment plumbing turns on
From this date the rules for notifying conformity assessment bodies apply. In plain terms: member states can start designating the third parties that are allowed to certify higher-risk products, and those bodies can start getting accredited.
This date matters most if your product lands in the important or critical classes, where self-assessment isn't on the table. Notified body capacity is finite, and it gets booked. Teams that wait until 2027 to find an assessor will be queuing behind teams that started in 2026.
Worth knowing before you book anything: what a CRA conformity assessment actually asks you to produce.
September 11, 2026: reporting goes live, including on products you already shipped
This is the milestone teams underestimate. From September 11, 2026, manufacturers have to report actively exploited vulnerabilities and severe security incidents. The clocks are short:
- 24 hours: early warning to ENISA and the relevant national CSIRT
- 72 hours: full notification with the details you have by then
- After remediation: final report, once a fix or mitigation exists
Here's the part people miss. This applies to products already on the EU market. Not new launches. Not products certified under the CRA. The fleet you shipped in 2021 counts.
That changes what "readiness" means. A 24-hour clock is not something you can satisfy with a spreadsheet and a group chat. To hit it you need three things working before September:
- A software inventory grounded in what actually shipped. If you can't answer "which SKUs and which firmware versions contain this component" in minutes, the 24-hour window is gone before you've written a sentence. A ground truth inventory built from firmware and binaries, rather than from what the build system thinks it produced, is what makes that query answerable.
- A way to tell exploited from theoretical. The obligation triggers on actively exploited vulnerabilities, so the ability to separate real exposure from CVE noise is now a reporting control, not just a triage nicety. Reachability analysis is how teams do that at portfolio scale.
- A PSIRT process with a named owner and a rehearsed path. Who files the ENISA early warning at 2 a.m. on a Sunday? Practice that before it's mandatory. Our notes on rapid PSIRT vulnerability response cover the workflow.
Twelve months out, the useful question isn't "are we compliant." It's "if a CVE in our fleet were exploited tomorrow, could we file in 24 hours?" Run that as a tabletop exercise this quarter, and you'll find your gaps cheaply.
Through 2026: harmonized standards and why they make your life easier
Expect the first harmonized standards to start landing across 2026. These are the technical specifications drafted under the Commission's standardization request to CEN and CENELEC.
Conforming to a harmonized standard gives you a presumption of conformity. You demonstrate you met the standard, and the relevant CRA essential requirement is presumed satisfied. Without one, you're building the argument from scratch and defending your own interpretation to an assessor.
The practical move is to track which standards cover your product category and design against the drafts rather than waiting for publication. Retrofitting a shipped design to a standard published in 2027 is the expensive version of this.
December 11, 2027: full application, and no CE mark means no market access
Everything else switches on. That includes:
- Secure by design and secure by default requirements
- Vulnerability handling across the declared support period
- Technical documentation
- The EU Declaration of Conformity
- CE marking
From that date, a new product without CRA conformity cannot be placed on the EU market. There's no grace window and no partial credit. No CE mark, no market access.
Two of those five items are where hardware teams lose time. Secure by design is an architecture commitment, which means it gets decided in 2026 for products shipping in 2028: see the security by design guide for the CRA. And technical documentation is an evidence problem, not a writing problem, which is why SBOMs and technical documentation under the CRA deserve their own workstream rather than a sprint in November 2027.
Key takeaways
- The Cyber Resilience Act timeline is four dates, not one. December 10, 2024, June 11, 2026, September 11, 2026, and December 11, 2027.
- September 11, 2026 is the date most teams underestimate. Reporting obligations apply to products already on the EU market, on a 24-hour early warning and 72-hour notification clock.
- June 11, 2026 opens the notified body pipeline. Important and critical class products should be shopping for assessors then, not in 2027.
- Harmonized standards landing through 2026 give you a presumption of conformity. Design against the drafts.
- December 11, 2027 is absolute. New products without CRA conformity and a CE mark can't be placed on the EU market.
- 2026 is about seeing and reporting. 2027 is about the product standing up to scrutiny. Different work, different lead times.
Where to go from here
Pick the date that's closest and work backward from it. For most manufacturers that's September 11, 2026, which means the next thing to build is an inventory you trust and a reporting path you've rehearsed.
If you'd rather see what that looks like against your own products than plan it on a whiteboard, request a CRA walkthrough and we'll map your portfolio to the milestones above. Already know where the gaps are? Start with a CRA readiness assessment.

Larry Pesce
VP of Services
Larry Pesce is a lifelong hacker, educator, and leader in embedded and connected device security. As the Vice President of Services, Larry drives strategic security initiatives across the software supply chain, helping product teams build resilient devices from the ground up. With over 15 years of hands-on penetration testing experience spanning IoT, healthcare, ICS/OT, and wireless technologies, he combines deep technical knowledge with real-world expertise. Larry is also a renowned SANS instructor and co-host of the long-running Paul’s Security Weekly podcast, shaping the next generation of security professionals.


