Nordchecks
← All guides

The CRA in numbers: deadlines, fines and key figures

Every EU Cyber Resilience Act number that matters in one place — the phase-in dates, the 24/72-hour/14-day reporting windows, the fine tiers, the risk-class split and the support period, each with its source.

Nordchecks TeamPublished 6 min

Not sure if you’re in scope?

Run the free 3-minute scope check for your product and get your risk class, deadlines and obligations.

Check if the CRA applies to you

In short

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) entered into force on 10 December 2024, the 24-hour reporting obligation applies from 11 September 2026, and full compliance is required from 11 December 2027. Incidents are reported in three windows — early warning within 24 hours, notification within 72 hours, final report within 14 days. Fines reach up to €15 million or 2.5% of worldwide annual turnover (Article 64), and security updates must be provided for at least 5 years.

This is a reference page: every CRA figure that gets quoted, in one place, each with the basis it comes from. Use it to fact-check a claim or cite a number. For the reasoning behind each one, follow the linked guide.

Not sure the CRA applies to your product? Run the free 3-minute scope check first.

Quick reference

FigureValueBasis
Regulation(EU) 2024/2847Official Journal, 20 Nov 2024
Entered into force10 December 2024Phased application
Reporting obligation applies11 September 2026Article 71
Full compliance11 December 2027Article 71
Early warning window24 hoursArticle 14
Notification window72 hoursArticle 14
Final report14 daysArticle 14
Top fine tier€15M or 2.5% of turnoverArticle 64
Mid fine tier€10M or 2% of turnoverArticle 64
Information-offence tier€5M or 1% of turnoverArticle 64
Default (self-assessed) products~90%EU Commission estimate
Minimum support period5 yearsArticle 13

The dates

DateWhat startsBasis
10 December 2024Regulation enters into force; transition beginsArticle 71
11 June 2026Provisions on notified bodies applyArticle 71
11 September 202624-hour vulnerability and incident reporting to ENISAArticle 71
11 December 2027Full application: SBOM, technical documentation, CE markingArticle 71

Two dates carry the weight. The full deadline breakdown explains why the September 2026 date — not December 2027 — is the one most teams miss.

The reporting windows

When a manufacturer becomes aware of an actively exploited vulnerability or a severe incident, three clocks run in sequence. Weekends and holidays are included.

WindowDeadline from awarenessWhat is filed
Early warning24 hoursFirst notice to the relevant CSIRT and ENISA
Notification72 hoursKnown details plus any corrective or mitigating measures
Final report14 days (vulnerabilities)Description, severity, impact and fix

Basis: Regulation (EU) 2024/2847, Article 14. Reports go to the CSIRT designated as coordinator and to ENISA. See the 24-hour reporting guide for the exact process.

The fines

BreachMaximum fineBasis
Essential requirements (Annex I) and vulnerability-handling obligations€15 million or 2.5% of total worldwide annual turnover, whichever is higherArticle 64
Other obligations (reporting, technical documentation, CE marking)€10 million or 2% of turnoverArticle 64
Incorrect, incomplete or misleading information to authorities€5 million or 1% of turnoverArticle 64

Every figure is a ceiling, not a fixed penalty — national market surveillance authorities set the actual amount proportionately. The fines and enforcement guide covers how that plays out for a small company in practice.

The risk classes

ClassShare of productsHow you prove compliance
Default~90%Self-assessment
Important — Class Ismall minorityHarmonised standards or notified body
Important — Class IIsmaller stillNotified body assessment
Criticalvery fewEuropean cybersecurity certification

The ~90% figure is the European Commission’s own estimate of the share of products that fall in the Default class and can self-assess. The product classes guide shows how to place your own product with worked examples.

The support period

FigureValueBasis
Minimum security-update periodAt least 5 yearsArticle 13
Longer where applicableThe product’s expected lifetimeArticle 13

Manufacturers must provide security updates free of charge for at least five years, or for the product’s expected lifetime where that is longer. The clock runs from when the product is placed on the market.

The software supply-chain numbers

The CRA exists because modern products are assembled from third-party code, most of it open source, and each component is a potential entry point. Two figures are worth citing carefully.

  • The vast majority of commercial codebases contain open-source components. This is the recurring headline finding of the annual OSSRA report and is why a Software Bill of Materials is a CRA requirement, not a nicety.
  • An average of 581 vulnerabilities per commercial codebase. Source: the Black Duck (formerly Synopsys) Open Source Security and Risk Analysis (OSSRA) report. Treat this as an order-of-magnitude figure — the exact number shifts with each year’s report, so cite it with the report year when you use it.

We only cite figures we can attribute. If a CRA number appears without a basis, treat it as unverified. A Software Bill of Materials is what turns those hundreds of components into a list you can actually monitor.

Tracking hundreds of components against a moving vulnerability feed, then filing inside a 24-hour window, is not something a spreadsheet keeps up with.

Nordchecks maintains the SBOM, matches it against known vulnerabilities daily, and pre-fills the ENISA notification so the reporting clock is a process, not a scramble.

Try Nordchecks free

One caveat on every number here

These figures come from the regulation text and named public sources, but they are a reference, not legal advice. Article numbers and dates are fixed by Regulation (EU) 2024/2847; the risk-class share and supply-chain figures are estimates and survey results that shift over time. When a number is load-bearing for a compliance decision, check it against the current source before you rely on it. A CRA compliance tool keeps the moving parts — your component inventory and vulnerability matches — current so the numbers you report are the right ones.

Start with the figures for your product: check your scope, class and deadlines free — three minutes, no signup, based on the regulation text.

Does the CRA apply to your product?

Find out in three minutes — your risk class, the deadlines that apply, and exactly what you’ll need to comply.

Start the free check