Finite StateFinite State
Finite StateFinite State
Get a DemoGet a Demo
Compliance

Cyber Resilience Act Timeline: What Actually Happens in 2026 and 2027

Most coverage flattens the Cyber Resilience Act into a single date in December 2027. That framing costs you a year.

Larry Pesce

Larry Pesce

VP of Services

August 7, 2026

The CRA rolls out across four fixed milestones, and the next one lands on September 11, 2026. It reaches the products you shipped years ago alongside the ones on your 2028 roadmap, which makes 2026 an active compliance year.

Below is every milestone in order, what switches on at each one, why Brussels wrote a 36-month transition period instead of a 12-month one, and the sequence a hardware team should work in if product security became someone's job last month.

The Cyber Resilience Act timeline at a glance

DateWhat appliesWho feels it first
December 10, 2024Regulation enters into force. Transition period begins.Everyone selling connected products in the EU
June 11, 2026Framework for notifying conformity assessment bodies appliesMakers of important and critical product classes needing third-party assessment
Through 2026First harmonized standards start landingAny team that wants a presumption of conformity
September 11, 2026Article 14 reporting obligations apply (live)Every manufacturer with products already on the EU market
December 11, 2027Full application. CE marking required.Anything placed on the EU market from that date forward

Two of those dates are about visibility. One is about the product itself. Treat them as one deadline and you'll be late for the first one.

December 10, 2024: the clock started

The regulation entered into force. Nothing became enforceable that day, but the transition period everyone is living through now began, and every downstream date counts from here.

If you want the substance of what the regulation asks for rather than when it asks, start with the EU Cyber Resilience Act explainer and come back to the calendar.

June 11, 2026: the conformity assessment plumbing turns on

From this date the rules for notifying conformity assessment bodies apply. In plain terms: member states can start designating the third parties that are allowed to certify higher-risk products, and those bodies can start getting accredited.

This date matters most if your product lands in the important or critical classes, where self-assessment isn't on the table. Notified body capacity is finite, and it gets booked. Teams that wait until 2027 to find an assessor will be queuing behind teams that started in 2026.

Worth knowing before you book anything: what a CRA conformity assessment actually asks you to produce.

September 11, 2026: reporting went live, including on products you already shipped

This is the milestone teams underestimate. From September 11, 2026, manufacturers have to report actively exploited vulnerabilities and severe security incidents. The clocks are short:

  • 24 hours: early warning to ENISA and the relevant national CSIRT
  • 72 hours: full notification with the details you have by then
  • After remediation: final report, once a fix or mitigation exists

Here's the part people miss. This applies to products already on the EU market. Not new launches. Not products certified under the CRA. The fleet you shipped in 2021 counts.

That changes what "readiness" means. A 24-hour clock is not something you can satisfy with a spreadsheet and a group chat. Hitting that clock takes three things working now:

  1. A software inventory grounded in what actually shipped. If you can't answer "which SKUs and which firmware versions contain this component" in minutes, the 24-hour window is gone before you've written a sentence. A ground truth inventory built from firmware and binaries, rather than from what the build system thinks it produced, is what makes that query answerable.
  2. A way to tell exploited from theoretical. The obligation triggers on actively exploited vulnerabilities, so the ability to separate real exposure from CVE noise is now a reporting control, not just a triage nicety. Reachability analysis is how teams do that at portfolio scale.
  3. A PSIRT process with a named owner and a rehearsed path. Who files the ENISA early warning at 2 a.m. on a Sunday? Practice that before it's mandatory. Our notes on rapid PSIRT vulnerability response cover the workflow.

Now that the obligation is live, the useful question isn't 'are we compliant.' It's "if a CVE in our fleet were exploited tomorrow, could we file in 24 hours?" Run that as a tabletop exercise this quarter, and you'll find your gaps cheaply.

Harmonized standards: where they actually stand

As of August 2026, ETSI has 17 vertical final draft standards out for public enquiry under the Commission's standardisation request to CEN, CENELEC and ETSI. None are cited in the Official Journal yet, which means none of them give you a presumption of conformity today.

Conforming to a cited harmonized standard gives you a presumption of conformity: you demonstrate you met the standard, and the relevant CRA essential requirement is presumed satisfied. Without one, you're building the argument from scratch and defending your own interpretation to an assessor.

The Commission also approved its Article 26 implementation guidance on July 27, 2026, roughly 80 pages working through the questions manufacturers ask most. It isn't binding, and it isn't a standard, but it tells you how the Commission reads the text.

The practical move is to track which drafts cover your product category and design against them now. Retrofitting a shipped design to a standard cited in 2027 is the expensive version of this.December 11, 2027: full application, and no CE mark means no market access

Everything else switches on. That includes:

  • Secure by design and secure by default requirements
  • Vulnerability handling across the declared support period
  • Technical documentation
  • The EU Declaration of Conformity
  • CE marking

From that date, a new product without CRA conformity cannot be placed on the EU market. There's no grace window for new placements and no partial credit. No CE mark, no market access.

Two of those five items are where hardware teams lose time. Secure by design is an architecture commitment, which means it gets decided in 2026 for products shipping in 2028: see the security by design guide for the CRA. And technical documentation is an evidence problem, not a writing problem, which is why SBOMs and technical documentation under the CRA deserve their own workstream rather than a sprint in November 2027.

Does the CRA apply to products already on the market?

Products placed on the EU market before December 11, 2027 don't need CE marking or a conformity assessment, unless you substantially modify them after that date.

That's Article 69 of Regulation (EU) 2024/2847, and it's the part of the timeline most often read backwards. Three paragraphs do the work:

  • Article 69(1). EU type-examination certificates issued under other Union harmonisation legislation stay valid until June 11, 2028. Six months past full application, not the same date. Compliance plans that sunset RED-era certificates in December 2027 are giving away half a year.
  • Article 69(2). Units placed on the market before December 11, 2027 are grandfathered, until a substantial modification as defined in Article 3(30) trips the trigger.
  • Article 69(3). The single carve-back. Article 14 reporting applies to every in-scope product, including the fleet you shipped in 2021.

The unit of measurement is the individual unit, not the product line. A router placed on the market in November 2027 is grandfathered. The next 5,000 copies of that same router, placed on the market in January 2028, are not. The Commission's guidance works through that exact example.

So the precise version of "no grace window" is this: none for new placements, a permanent one for old ones, and Article 14 reporting stapled to both. Which means the question worth answering per SKU is when each unit was first placed on the EU market, and what your next release does to it.

What the CRA timeline means for IoT and connected device manufacturers

IoT and embedded device makers hit the timeline harder than software vendors, for one structural reason: your support periods outlast the deadlines.

A sensor shipped in 2026 with a ten-year support commitment is still in the field in 2036. It's grandfathered from the essential requirements under Article 69(2), and it's reportable under Article 14 for its whole life. That's a decade of vulnerability monitoring on a product that never gets a CE mark under the CRA.

Secure by design for IoT also decides itself early. Where a web application can retrofit a control in a sprint, a device fixes its bootloader, its update mechanism and its cryptographic primitives at tape-out. Products shipping in 2028 are having their CRA architecture decided in 2026 design reviews happening now.

Then there's classification. Commission Implementing Regulation (EU) 2025/2392, in force since December 21, 2025, gives the technical descriptions for the important and critical categories in Annexes III and IV. Classification turns on a product's core functionality, so an embedded browser inside a larger application doesn't make the product a browser. If you've been guessing at your class since 2024, that regulation is where the guessing stops.

Key takeaways

  • The Cyber Resilience Act timeline is four dates, not one. December 10, 2024, June 11, 2026, September 11, 2026, and December 11, 2027.
  • September 11, 2026 is the date most teams underestimate. Reporting obligations apply to products already on the EU market, on a 24-hour early warning and 72-hour notification clock.
  • June 11, 2026 opens the notified body pipeline. Important and critical class products should be shopping for assessors then, not in 2027.
  • Harmonized standards landing through 2026 give you a presumption of conformity. Design against the drafts.
  • December 11, 2027 is absolute. New products without CRA conformity and a CE mark can't be placed on the EU market.
  • 2026 is about seeing and reporting. 2027 is about the product standing up to scrutiny. Different work, different lead times.

Where to go from here

Pick the date that's closest and work backward from it. For most manufacturers that's September 11, 2026, which means the next thing to build is an inventory you trust and a reporting path you've rehearsed.

If you'd rather see what that looks like against your own products than plan it on a whiteboard, request a CRA walkthrough and we'll map your portfolio to the milestones above. Already know where the gaps are? Start with a CRA readiness assessment.

Cyber Resilience Act Compliance

Tags

#CRA#eu cra
Larry Pesce

Larry Pesce

VP of Services

Larry Pesce is a lifelong hacker, educator, and leader in embedded and connected device security. As the Vice President of Services, Larry drives strategic security initiatives across the software supply chain, helping product teams build resilient devices from the ground up. With over 15 years of hands-on penetration testing experience spanning IoT, healthcare, ICS/OT, and wireless technologies, he combines deep technical knowledge with real-world expertise. Larry is also a renowned SANS instructor and co-host of the long-running Paul’s Security Weekly podcast, shaping the next generation of security professionals.


Related Articles

Transparent wireframe illustration of a computer hardware device with an orange-highlighted chip, connected to a vertical checklist of glowing hexagonal status indicators on a dark background.

Cyber Resilience Act Checklist: Article 14 Is Now Live

September 11, 2026, tends to get described as a deadline for the CRA. In practice, it behaves more like a starting line.

Aug 31, 2026
Dark, cinematic illustration contrasting a closed gray binder of paper documents, blurred in the background, with a sharply focused industrial control device rendered in glowing teal wireframe scan lines, one internal component highlighted in orange, symbolizing technical verification going beyond written regulation.

CRA Readiness Takes More Than Reading the Regulation

The regulation establishes what manufacturers have to achieve, but it doesn’t tell you how. Filling that gap takes human expertise and judgment – and ...

Aug 20, 2026
X-ray 3/4 view of a connected vehicle, the dark car body shown in shadow while its internal electronics — infotainment unit, telematics module, OBD-II dongle, and dashcam — glow orange and are revealed by scan line passing through the car.

Cyber Resilience Act for Automotive Suppliers: The Car Is Exempt, but What's Inside Isn't

Most suppliers hear "automotive is exempt" and move on. The CRA carves out the finished vehicle, but a meaningful share of what they sell still falls ...

Jun 24, 2026

Ready to Level Up Your Security Knowledge?

Join thousands of security professionals learning from the best in the industry

Start Learning TodayStart Learning Today
Finite StateFinite State

Finite State is the Product Security Automation Platform that functions as an autonomous Product Security OS: design → verify → prove, grounded in what you ship.

Platform

Platform Overview
Ground Truth Inventory
Exploitability-Based Prioritization
Design-Time Architecture Security
Automated Evidence-Backed Compliance

Solutions

Device Manufacturers
Automotive
Medical Devices
Energy & Utilities
Government
Industrial

Resources

Blog
Resource Library
Webinars & Videos
Events
Documentation

Company

About Us
CareersHIRING
Press & News
Contact Sales
Media Inquiries
X

Privacy PolicyTerms of UseCustomer Terms and Conditions