← All guides

EU Cyber Resilience Act deadlines explained: 11 September 2026 vs 11 December 2027

The CRA has two deadlines that matter — the 24-hour reporting obligation from 11 September 2026 and full compliance by 11 December 2027. What applies when, to which products, and what to do first.

Nordchecks TeamPublished 7 min

Not sure if you’re in scope?

Run the free 3-minute scope check for your product and get your risk class, deadlines and obligations.

Check if the CRA applies to you

Most teams researching the EU Cyber Resilience Act walk away with one date in their head: December 2027. That is a costly misunderstanding. The CRA phases in over three dates, and the one that changes your daily operations arrives first — on 11 September 2026.

This guide explains exactly what applies when, which products each date covers, and what to do if you are starting late.

Not sure whether the CRA applies to your product at all? Run the free 3-minute scope check — it returns your risk class and the deadlines that apply to you.

The timeline at a glance

DateWhat starts applyingWho it affects
10 December 2024Regulation entered into force; transition period beginsEveryone in scope
11 June 2026Provisions on notified bodies apply — conformity assessment bodies can be designatedManufacturers of Class I/II products preparing third-party assessment
11 September 2026Reporting obligations: actively exploited vulnerabilities and severe incidents must be notified (24h/72h)All manufacturers with products in scope — including products already on the market
11 December 2027Full application: security by design, SBOM, technical documentation, CE marking, market surveillanceAll products with digital elements placed on the EU market from this date

What actually happens on 11 September 2026

From this date, a manufacturer that becomes aware of an actively exploited vulnerability in a product with digital elements, or a severe incident having an impact on the security of such a product, must notify ENISA and the CSIRT of their member state:

  1. Early warning within 24 hours of becoming aware
  2. Full notification within 72 hours, including known details and any corrective measures
  3. Final report within 14 days (vulnerabilities) or one month (incidents)

Three things make this deadline sharper than it looks:

It covers products already on the market. The reporting duty is not limited to products launched after 2027. If your device or software is in the field today and an exploited vulnerability surfaces on 12 September 2026, the clock starts.

"Becoming aware" is a low bar. A customer email, a researcher's disclosure, a post naming your product — awareness can start the 24-hour window at any moment, including weekends. You need a monitored intake channel and a named responsible person, not good intentions.

24 hours is a process, not a form. To report within a day you must already know what is in your product (an up-to-date component inventory), be able to assess whether the vulnerability affects you, and have templates and responsibilities agreed. Teams that design this during their first incident miss the window.

Minimum readiness before 11 September: a one-page reporting playbook (who assesses, who decides, who files), pre-filled notification templates, a security@ contact that someone actually reads, and a current SBOM per product so impact assessment takes hours, not days.

What happens on 11 December 2027

This is the date the full regulation applies. From then on, placing a product with digital elements on the EU market requires:

  • A documented cybersecurity risk assessment and security-by-design measures
  • No known exploitable vulnerabilities at release and secure default configuration
  • A Software Bill of Materials covering at least top-level dependencies
  • A vulnerability handling process with free security updates for the support period (at least five years)
  • Technical documentation per the regulation's annexes
  • An EU Declaration of Conformity and CE marking — via self-assessment for default-class products, harmonised standards or a notified body for Important Class I, a notified body for Class II, and European certification for critical products

After this date, a product in scope without CE marking under the CRA cannot legally be sold in the EU. Penalties reach €15 million or 2.5% of worldwide turnover, whichever is higher.

"Does the 2027 deadline apply to products I sold before 2027?"

The full compliance obligations attach to products placed on the market from 11 December 2027. Products placed earlier do not need retroactive CE marking — but two caveats matter:

  1. The reporting obligations from September 2026 apply regardless of when the product was placed on the market.
  2. A substantial modification of an existing product after December 2027 counts as placing a new product on the market — triggering full compliance. Major firmware overhauls and significant feature releases can cross that line.

So "our product is old" is a shield with holes in it. Most manufacturers with actively developed products will be pulled into full compliance through their normal release cycle.

If you are starting today

Work backwards from the nearest deadline:

Before 11 September 2026 (weeks, not months, away): determine scope and class, build or generate your SBOM, set up vulnerability monitoring, write the reporting playbook, publish a disclosure contact. Our CRA compliance checklist covers each step in order.

Between now and 11 December 2027: run the risk assessment, close security-by-design gaps, assemble technical documentation, and plan the conformity route for your class — notified body capacity is expected to be tight as the deadline approaches, so Class I/II manufacturers should start early.

First step, today: check your scope and risk class free. It takes three minutes and tells you exactly which of these deadlines apply to your product.

Does the CRA apply to your product?

Find out in three minutes — your risk class, the deadlines that apply, and exactly what you’ll need to comply.

Start the free check