11 September 2026: reporting starts Art. 14, Art. 71(2)
This is the first date that puts a live obligation on manufacturers. Article 71(2) singles out Article 14 and brings it forward, so the reporting duties for actively exploited vulnerabilities and severe incidents apply more than a year before the rest of the regulation. If you place products with digital elements on the EU market, you need a working reporting process by this date, not by 2027.
11 December 2027: full application Art. 71(2)
This is the general date of application. From here the whole regulation bites: the essential cybersecurity requirements of Annex I, the manufacturer obligations of Article 13, technical documentation, the conformity assessment procedures, the EU declaration of conformity, and the CE marking. A product placed on the EU market on or after this date must be compliant and carry the CE marking. This is the deadline most of the substantive work points at.
11 June 2026: the notified-bodies chapter Art. 71(2)
Between the two headline dates sits a third one that is easy to miss. Chapter IV, which covers the notification of conformity assessment bodies (Articles 35 to 51), applies from 11 June 2026. This is plumbing rather than a duty on you: it lets Member States designate notified bodies early, so that manufacturers who need a notified-body route have somewhere to go before the December 2027 deadline. It matters mainly for planning if your product needs third-party assessment.
Why the staggering, and what it means for you
The order is deliberate: reporting first, then the infrastructure to assess conformity, then the full product requirements. For a small manufacturer the practical reading is simple. Treat September 2026 as the reporting-readiness deadline and December 2027 as the compliance deadline for the product itself, and work backwards from December 2027 for anything (documentation, testing, a notified-body slot) that takes lead time.