The CRA in numbers: deadlines, fines and key figures
Every EU Cyber Resilience Act number that matters in one place — the phase-in dates, the 24/72-hour/14-day reporting windows, the fine tiers, the risk-class split and the support period, each with its source.
Not sure if you’re in scope?
Run the free 3-minute scope check for your product and get your risk class, deadlines and obligations.
Check if the CRA applies to youIn short
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) entered into force on 10 December 2024, the 24-hour reporting obligation applies from 11 September 2026, and full compliance is required from 11 December 2027. Incidents are reported in three windows — early warning within 24 hours, notification within 72 hours, final report within 14 days. Fines reach up to €15 million or 2.5% of worldwide annual turnover (Article 64), and security updates must be provided for at least 5 years.
This is a reference page: every CRA figure that gets quoted, in one place, each with the basis it comes from. Use it to fact-check a claim or cite a number. For the reasoning behind each one, follow the linked guide.
Not sure the CRA applies to your product? Run the free 3-minute scope check first.
Quick reference
| Figure | Value | Basis |
|---|---|---|
| Regulation | (EU) 2024/2847 | Official Journal, 20 Nov 2024 |
| Entered into force | 10 December 2024 | Phased application |
| Reporting obligation applies | 11 September 2026 | Article 71 |
| Full compliance | 11 December 2027 | Article 71 |
| Early warning window | 24 hours | Article 14 |
| Notification window | 72 hours | Article 14 |
| Final report | 14 days | Article 14 |
| Top fine tier | €15M or 2.5% of turnover | Article 64 |
| Mid fine tier | €10M or 2% of turnover | Article 64 |
| Information-offence tier | €5M or 1% of turnover | Article 64 |
| Default (self-assessed) products | ~90% | EU Commission estimate |
| Minimum support period | 5 years | Article 13 |
The dates
| Date | What starts | Basis |
|---|---|---|
| 10 December 2024 | Regulation enters into force; transition begins | Article 71 |
| 11 June 2026 | Provisions on notified bodies apply | Article 71 |
| 11 September 2026 | 24-hour vulnerability and incident reporting to ENISA | Article 71 |
| 11 December 2027 | Full application: SBOM, technical documentation, CE marking | Article 71 |
Two dates carry the weight. The full deadline breakdown explains why the September 2026 date — not December 2027 — is the one most teams miss.
The reporting windows
When a manufacturer becomes aware of an actively exploited vulnerability or a severe incident, three clocks run in sequence. Weekends and holidays are included.
| Window | Deadline from awareness | What is filed |
|---|---|---|
| Early warning | 24 hours | First notice to the relevant CSIRT and ENISA |
| Notification | 72 hours | Known details plus any corrective or mitigating measures |
| Final report | 14 days (vulnerabilities) | Description, severity, impact and fix |
Basis: Regulation (EU) 2024/2847, Article 14. Reports go to the CSIRT designated as coordinator and to ENISA. See the 24-hour reporting guide for the exact process.
The fines
| Breach | Maximum fine | Basis |
|---|---|---|
| Essential requirements (Annex I) and vulnerability-handling obligations | €15 million or 2.5% of total worldwide annual turnover, whichever is higher | Article 64 |
| Other obligations (reporting, technical documentation, CE marking) | €10 million or 2% of turnover | Article 64 |
| Incorrect, incomplete or misleading information to authorities | €5 million or 1% of turnover | Article 64 |
Every figure is a ceiling, not a fixed penalty — national market surveillance authorities set the actual amount proportionately. The fines and enforcement guide covers how that plays out for a small company in practice.
The risk classes
| Class | Share of products | How you prove compliance |
|---|---|---|
| Default | ~90% | Self-assessment |
| Important — Class I | small minority | Harmonised standards or notified body |
| Important — Class II | smaller still | Notified body assessment |
| Critical | very few | European cybersecurity certification |
The ~90% figure is the European Commission’s own estimate of the share of products that fall in the Default class and can self-assess. The product classes guide shows how to place your own product with worked examples.
The support period
| Figure | Value | Basis |
|---|---|---|
| Minimum security-update period | At least 5 years | Article 13 |
| Longer where applicable | The product’s expected lifetime | Article 13 |
Manufacturers must provide security updates free of charge for at least five years, or for the product’s expected lifetime where that is longer. The clock runs from when the product is placed on the market.
The software supply-chain numbers
The CRA exists because modern products are assembled from third-party code, most of it open source, and each component is a potential entry point. Two figures are worth citing carefully.
- The vast majority of commercial codebases contain open-source components. This is the recurring headline finding of the annual OSSRA report and is why a Software Bill of Materials is a CRA requirement, not a nicety.
- An average of 581 vulnerabilities per commercial codebase. Source: the Black Duck (formerly Synopsys) Open Source Security and Risk Analysis (OSSRA) report. Treat this as an order-of-magnitude figure — the exact number shifts with each year’s report, so cite it with the report year when you use it.
We only cite figures we can attribute. If a CRA number appears without a basis, treat it as unverified. A Software Bill of Materials is what turns those hundreds of components into a list you can actually monitor.
Tracking hundreds of components against a moving vulnerability feed, then filing inside a 24-hour window, is not something a spreadsheet keeps up with.
Nordchecks maintains the SBOM, matches it against known vulnerabilities daily, and pre-fills the ENISA notification so the reporting clock is a process, not a scramble.
Try Nordchecks freeOne caveat on every number here
These figures come from the regulation text and named public sources, but they are a reference, not legal advice. Article numbers and dates are fixed by Regulation (EU) 2024/2847; the risk-class share and supply-chain figures are estimates and survey results that shift over time. When a number is load-bearing for a compliance decision, check it against the current source before you rely on it. A CRA compliance tool keeps the moving parts — your component inventory and vulnerability matches — current so the numbers you report are the right ones.
Start with the figures for your product: check your scope, class and deadlines free — three minutes, no signup, based on the regulation text.