Cyber Resilience Act timeline
Three dates, staged deliberately. Notified body machinery first, reporting second, everything else last. The regulation entered into force on 10 December 2024 and applies in full from 11 December 2027.
| Date | What happens | What you should have done |
|---|---|---|
| 10 Dec 2024 | Regulation enters into force | Nothing required. The clock starts. |
| 11 Jun 2026 | Provisions on notification of conformity assessment bodies apply | Notified bodies can be designated. If you need one, this is when to start talking to them. |
| 11 Sep 2026 | Article 14 reporting obligations apply | Reporting process live, platform access tested, named owner and deputy, user notification channel ready. |
| 11 Dec 2027 | Full application. All obligations, CE marking, conformity assessment, technical documentation | Technical file complete, conformity assessment done, declaration signed, CE affixed, support period published. |
A working backwards plan
Counting back from 11 December 2027, for a team that has not started:
- Now → end 2026: classify and scope. Decide whether each product is in scope, whether it is important or critical, and therefore which conformity assessment route applies. Get the reporting process live — that obligation is already running. Scope test →
- Q1 2027: gap assessment against Annex I. Requirement by requirement, what do you already satisfy, what needs engineering work, and what needs evidence you do not currently produce? Engineering changes discovered here still have time to ship.
- Q1–Q2 2027: notified body engaged if you need one. Expect queues.
- Q2–Q3 2027: build the technical documentation as you go. The file is assembled from work you are doing anyway. Written at the end, from memory, it is both worse and more expensive. Annex VII →
- Q3 2027: vulnerability handling in production. SBOM generated at build, disclosure policy published, update mechanism tested, support period decided and justified.
- Q4 2027: assessment, declaration, marking. Sign-off, declaration of conformity, CE, and retention arrangements for ten years.
The harmonised standards problem. The CRA harmonised standards are
still in development. Waiting for them before starting is the single most common plan and the worst
one: if they arrive late, you will have had no time, and the obligation does not move. Build against
the essential requirements in Annex I directly and adopt standards as they land.
Get told when the requirements change
None of the 35 CRA harmonised standards is published yet. When they land — and when deadlines move — we email you. No more than twice a month.