Cyber Resilience Act timeline: the three dates that matter to a product list
Regulation (EU) 2024/2847 entered into force in December 2024 and applies in three steps, read from Article 71(2) of the held text. The reporting duty already applies to products on the market, whatever date they were placed there.
The dates of application
| Date | What applies | Article | Products it touches |
|---|---|---|---|
| 11 Jun 2026 | Notified bodies: Chapter IV applies | Art. 71(2) | products whose class asks for a notified body or a certification scheme |
| 11 Sep 2026 | Reporting duty applies (Art. 14) | Art. 71(2) and Art. 69(3) | every product with digital elements on the EU market |
| 11 Dec 2027 | The Act applies in full | Art. 71(2) | every product with digital elements on the EU market |
Article 69(3) brings every product placed on the market before 11 December 2027 under the Article 14 reporting duty; Article 69(2) otherwise subjects such a product to the Act only on a substantial modification. How that reads for units of an older model placed on the market after that date is a question for legal. The finder draws these dates as a timing diagram against the as-at date of your list and counts the products each one touches.
The clauses behind the reporting duty
CRA Art. 14(1)Notifying actively exploited vulnerabilities to the CSIRT and ENISAA manufacturer that becomes aware of an actively exploited vulnerability in its product must notify it at the same time to the CSIRT designated as coordinator and to ENISA, through the single reporting platform of Article 16. Applies from 11 September 2026, including to products placed on the market before 11 December 2027 (Article 69(3)).
CRA Art. 14(2)(a)Early warning within 24 hours of awareness of an exploited vulnerabilityAn early warning of the actively exploited vulnerability must go in without undue delay and within 24 hours of the manufacturer becoming aware of it, naming, where applicable, the Member States where the manufacturer knows the product has been made available.
CRA Art. 14(3)Notifying severe incidents affecting product securityA manufacturer that becomes aware of a severe incident with an impact on the security of its product must notify it at the same time to the coordinating CSIRT and ENISA via the single reporting platform. An incident is severe where it harms or can harm the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or has led or can lead to malicious code being introduced or run in the product or in users' systems (Article 14(5)).