Cyber Resilience Act timeline

Last reviewed: 11 September 2026~4 min read

Three dates, staged deliberately. Notified body machinery first, reporting second, everything else last. The regulation entered into force on 10 December 2024 and applies in full from 11 December 2027.

Key Cyber Resilience Act dates
DateWhat happensWhat you should have done
10 Dec 2024Regulation enters into forceNothing required. The clock starts.
11 Jun 2026Provisions on notification of conformity assessment bodies applyNotified bodies can be designated. If you need one, this is when to start talking to them.
11 Sep 2026Article 14 reporting obligations applyReporting process live, platform access tested, named owner and deputy, user notification channel ready.
11 Dec 2027Full application. All obligations, CE marking, conformity assessment, technical documentationTechnical file complete, conformity assessment done, declaration signed, CE affixed, support period published.

A working backwards plan

Counting back from 11 December 2027, for a team that has not started:

  1. Now → end 2026: classify and scope. Decide whether each product is in scope, whether it is important or critical, and therefore which conformity assessment route applies. Get the reporting process live — that obligation is already running. Scope test →
  2. Q1 2027: gap assessment against Annex I. Requirement by requirement, what do you already satisfy, what needs engineering work, and what needs evidence you do not currently produce? Engineering changes discovered here still have time to ship.
  3. Q1–Q2 2027: notified body engaged if you need one. Expect queues.
  4. Q2–Q3 2027: build the technical documentation as you go. The file is assembled from work you are doing anyway. Written at the end, from memory, it is both worse and more expensive. Annex VII →
  5. Q3 2027: vulnerability handling in production. SBOM generated at build, disclosure policy published, update mechanism tested, support period decided and justified.
  6. Q4 2027: assessment, declaration, marking. Sign-off, declaration of conformity, CE, and retention arrangements for ten years.
The harmonised standards problem. The CRA harmonised standards are still in development. Waiting for them before starting is the single most common plan and the worst one: if they arrive late, you will have had no time, and the obligation does not move. Build against the essential requirements in Annex I directly and adopt standards as they land.

Sources