Compliance

Cyber Resilience Act Timeline: What Actually Happens in 2026 and 2027

Most coverage flattens the Cyber Resilience Act into a single date in December 2027. That framing costs you a year.

Larry Pesce

Larry Pesce

VP of Services

August 7, 2026

The CRA rolls out across four fixed milestones, and the next one lands on September 11, 2026. It reaches the products you shipped years ago alongside the ones on your 2028 roadmap, which makes 2026 an active compliance year.

Below is every milestone in order, what switches on at each one, why Brussels wrote a 36-month transition period instead of a 12-month one, and the sequence a hardware team should work in if product security became someone's job last month.

The Cyber Resilience Act timeline at a glance

DateWhat appliesWho feels it first
December 10, 2024Regulation enters into force. Transition period begins.Everyone selling connected products in the EU
June 11, 2026Framework for notifying conformity assessment bodies appliesMakers of important and critical product classes needing third-party assessment
Through 2026First harmonized standards start landingAny team that wants a presumption of conformity
September 11, 2026Reporting obligations go liveEvery manufacturer with products already on the EU market
December 11, 2027Full application. CE marking required.Anything placed on the EU market from that date forward

Two of those dates are about visibility. One is about the product itself. Treat them as one deadline and you'll be late for the first one.

December 10, 2024: the clock started

The regulation entered into force. Nothing became enforceable that day, but the transition period everyone is living through now began, and every downstream date counts from here.

If you want the substance of what the regulation asks for rather than when it asks, start with the EU Cyber Resilience Act explainer and come back to the calendar.

June 11, 2026: the conformity assessment plumbing turns on

From this date the rules for notifying conformity assessment bodies apply. In plain terms: member states can start designating the third parties that are allowed to certify higher-risk products, and those bodies can start getting accredited.

This date matters most if your product lands in the important or critical classes, where self-assessment isn't on the table. Notified body capacity is finite, and it gets booked. Teams that wait until 2027 to find an assessor will be queuing behind teams that started in 2026.

Worth knowing before you book anything: what a CRA conformity assessment actually asks you to produce.

September 11, 2026: reporting goes live, including on products you already shipped

This is the milestone teams underestimate. From September 11, 2026, manufacturers have to report actively exploited vulnerabilities and severe security incidents. The clocks are short:

  • 24 hours: early warning to ENISA and the relevant national CSIRT
  • 72 hours: full notification with the details you have by then
  • After remediation: final report, once a fix or mitigation exists

Here's the part people miss. This applies to products already on the EU market. Not new launches. Not products certified under the CRA. The fleet you shipped in 2021 counts.

That changes what "readiness" means. A 24-hour clock is not something you can satisfy with a spreadsheet and a group chat. To hit it you need three things working before September:

  1. A software inventory grounded in what actually shipped. If you can't answer "which SKUs and which firmware versions contain this component" in minutes, the 24-hour window is gone before you've written a sentence. A ground truth inventory built from firmware and binaries, rather than from what the build system thinks it produced, is what makes that query answerable.
  2. A way to tell exploited from theoretical. The obligation triggers on actively exploited vulnerabilities, so the ability to separate real exposure from CVE noise is now a reporting control, not just a triage nicety. Reachability analysis is how teams do that at portfolio scale.
  3. A PSIRT process with a named owner and a rehearsed path. Who files the ENISA early warning at 2 a.m. on a Sunday? Practice that before it's mandatory. Our notes on rapid PSIRT vulnerability response cover the workflow.

Twelve months out, the useful question isn't "are we compliant." It's "if a CVE in our fleet were exploited tomorrow, could we file in 24 hours?" Run that as a tabletop exercise this quarter, and you'll find your gaps cheaply.

Through 2026: harmonized standards and why they make your life easier

Expect the first harmonized standards to start landing across 2026. These are the technical specifications drafted under the Commission's standardization request to CEN and CENELEC.

Conforming to a harmonized standard gives you a presumption of conformity. You demonstrate you met the standard, and the relevant CRA essential requirement is presumed satisfied. Without one, you're building the argument from scratch and defending your own interpretation to an assessor.

The practical move is to track which standards cover your product category and design against the drafts rather than waiting for publication. Retrofitting a shipped design to a standard published in 2027 is the expensive version of this.

December 11, 2027: full application, and no CE mark means no market access

Everything else switches on. That includes:

  • Secure by design and secure by default requirements
  • Vulnerability handling across the declared support period
  • Technical documentation
  • The EU Declaration of Conformity
  • CE marking

From that date, a new product without CRA conformity cannot be placed on the EU market. There's no grace window and no partial credit. No CE mark, no market access.

Two of those five items are where hardware teams lose time. Secure by design is an architecture commitment, which means it gets decided in 2026 for products shipping in 2028: see the security by design guide for the CRA. And technical documentation is an evidence problem, not a writing problem, which is why SBOMs and technical documentation under the CRA deserve their own workstream rather than a sprint in November 2027.

Key takeaways

  • The Cyber Resilience Act timeline is four dates, not one. December 10, 2024, June 11, 2026, September 11, 2026, and December 11, 2027.
  • September 11, 2026 is the date most teams underestimate. Reporting obligations apply to products already on the EU market, on a 24-hour early warning and 72-hour notification clock.
  • June 11, 2026 opens the notified body pipeline. Important and critical class products should be shopping for assessors then, not in 2027.
  • Harmonized standards landing through 2026 give you a presumption of conformity. Design against the drafts.
  • December 11, 2027 is absolute. New products without CRA conformity and a CE mark can't be placed on the EU market.
  • 2026 is about seeing and reporting. 2027 is about the product standing up to scrutiny. Different work, different lead times.

Where to go from here

Pick the date that's closest and work backward from it. For most manufacturers that's September 11, 2026, which means the next thing to build is an inventory you trust and a reporting path you've rehearsed.

If you'd rather see what that looks like against your own products than plan it on a whiteboard, request a CRA walkthrough and we'll map your portfolio to the milestones above. Already know where the gaps are? Start with a CRA readiness assessment.

Tags

#CRA#eu cra
Larry Pesce

Larry Pesce

VP of Services

Larry Pesce is a lifelong hacker, educator, and leader in embedded and connected device security. As the Vice President of Services, Larry drives strategic security initiatives across the software supply chain, helping product teams build resilient devices from the ground up. With over 15 years of hands-on penetration testing experience spanning IoT, healthcare, ICS/OT, and wireless technologies, he combines deep technical knowledge with real-world expertise. Larry is also a renowned SANS instructor and co-host of the long-running Paul’s Security Weekly podcast, shaping the next generation of security professionals.


Related Articles

Dark, cinematic illustration contrasting a closed gray binder of paper documents, blurred in the background, with a sharply focused industrial control device rendered in glowing teal wireframe scan lines, one internal component highlighted in orange, symbolizing technical verification going beyond written regulation.

CRA Readiness Takes More Than Reading the Regulation

The regulation establishes what manufacturers have to achieve, but it doesn’t tell you how. Filling that gap takes human expertise and judgment – and ...

Aug 20, 2026
X-ray 3/4 view of a connected vehicle, the dark car body shown in shadow while its internal electronics — infotainment unit, telematics module, OBD-II dongle, and dashcam — glow orange and are revealed by scan line passing through the car.

Cyber Resilience Act for Automotive Suppliers: The Car Is Exempt, but What's Inside Isn't

Most suppliers hear "automotive is exempt" and move on. The CRA carves out the finished vehicle, but a meaningful share of what they sell still falls ...

Jun 24, 2026
A lineup of connected devices — an industrial PLC, a network router, and a smart home IoT hub — on a dark reflective surface, each overlaid with a teal X-ray scan revealing the circuit boards inside, illustrating continuous security scanning for CRA compliance.

CRA Compliance Is Not a Checkbox. It's a Continuous Program.

Manufacturers tend to prepare for the EU Cyber Resilience Act (CRA) the way they'd prepare for an exam, something you study for, pass, and put behind ...

Jun 17, 2026

Ready to Level Up Your Security Knowledge?

Join thousands of security professionals learning from the best in the industry

Start Learning TodayStart Learning Today
Finite StateFinite State

Finite State is the Product Security Automation Platform that functions as an autonomous Product Security OS: design → verify → prove, grounded in what you ship.

Platform

Platform Overview
Ground Truth Inventory
Exploitability-Based Prioritization
Design-Time Architecture Security
Automated Evidence-Backed Compliance

Solutions

Device Manufacturers
Automotive
Medical Devices
Energy & Utilities
Government
Industrial

Resources

Blog
Resource Library
Webinars & Videos
Events
Documentation

Company

About Us
CareersHIRING
Press & News
Contact Sales
Media Inquiries
X

© 2026 Finite State. All rights reserved.

Privacy PolicyTerms of UseCustomer Terms and Conditions
Finite StateFinite State
Finite StateFinite State
Get a DemoGet a Demo