Article 71 ยท Regulation (EU) 2024/2847

What are the key CRA compliance deadlines?

Verified against the Official Journal text on

The CRA entered into force in 2024 but applies in stages, and two dates matter most for manufacturers. From 11 September 2026 the reporting duties for actively exploited vulnerabilities and severe incidents apply. From 11 December 2027 the regulation applies in full: the essential requirements, technical documentation, conformity assessment, and CE marking. A third, earlier date sits between them: the notified-bodies chapter (Chapter IV, Articles 35 to 51) applies from 11 June 2026, so conformity assessment bodies can be in place before manufacturers need them.

Basis: Art. 71(2)

Judgment call: Article 71(2) sets these three dates explicitly. Separate Commission acts (such as the technical descriptions of Annex III and IV categories) had their own earlier deadlines but do not change the application dates for manufacturers.

11 September 2026: reporting starts Art. 14, Art. 71(2)

This is the first date that puts a live obligation on manufacturers. Article 71(2) singles out Article 14 and brings it forward, so the reporting duties for actively exploited vulnerabilities and severe incidents apply more than a year before the rest of the regulation. If you place products with digital elements on the EU market, you need a working reporting process by this date, not by 2027.

11 December 2027: full application Art. 71(2)

This is the general date of application. From here the whole regulation bites: the essential cybersecurity requirements of Annex I, the manufacturer obligations of Article 13, technical documentation, the conformity assessment procedures, the EU declaration of conformity, and the CE marking. A product placed on the EU market on or after this date must be compliant and carry the CE marking. This is the deadline most of the substantive work points at.

11 June 2026: the notified-bodies chapter Art. 71(2)

Between the two headline dates sits a third one that is easy to miss. Chapter IV, which covers the notification of conformity assessment bodies (Articles 35 to 51), applies from 11 June 2026. This is plumbing rather than a duty on you: it lets Member States designate notified bodies early, so that manufacturers who need a notified-body route have somewhere to go before the December 2027 deadline. It matters mainly for planning if your product needs third-party assessment.

Why the staggering, and what it means for you

The order is deliberate: reporting first, then the infrastructure to assess conformity, then the full product requirements. For a small manufacturer the practical reading is simple. Treat September 2026 as the reporting-readiness deadline and December 2027 as the compliance deadline for the product itself, and work backwards from December 2027 for anything (documentation, testing, a notified-body slot) that takes lead time.

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

When does the CRA fully apply?

From 11 December 2027. That is the general date of application in Article 71(2), covering the essential requirements, technical documentation, conformity assessment, and CE marking for products with digital elements placed on the EU market. (Art. 71(2))

When do the reporting obligations start?

From 11 September 2026. Article 71(2) brings Article 14 forward, so the duty to report actively exploited vulnerabilities and severe incidents applies well before the rest of the regulation. (Art. 14, Art. 71(2))

Is there any CRA deadline before September 2026?

Yes, for infrastructure rather than manufacturers: Chapter IV on notified bodies (Articles 35 to 51) applies from 11 June 2026, so conformity assessment bodies can be designated ahead of the December 2027 deadline. (Art. 71(2))

Has the CRA already entered into force?

Yes. Under Article 71(1) it entered into force on the twentieth day following its publication in the Official Journal, in late 2024. Entry into force and application are different things: the obligations apply from the staged dates above. (Art. 71(1), Art. 71(2))

Which of these dates actually apply to you?

The free Vexwatch Scope Checker tells you whether you are in scope and which obligations land on 11 September 2026 and 11 December 2027 for your specific product and role.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.