Cyber Resilience Act Gap FinderProduct list reading ยท Regulation (EU) 2024/2847, UK PSTI, Cal. Civ. Code 1798.91.04

Cyber Resilience Act timeline: the three dates that matter to a product list

Regulation (EU) 2024/2847 entered into force in December 2024 and applies in three steps, read from Article 71(2) of the held text. The reporting duty already applies to products on the market, whatever date they were placed there.

The dates of application

DateWhat appliesArticleProducts it touches
11 Jun 2026Notified bodies: Chapter IV appliesArt. 71(2)products whose class asks for a notified body or a certification scheme
11 Sep 2026Reporting duty applies (Art. 14)Art. 71(2) and Art. 69(3)every product with digital elements on the EU market
11 Dec 2027The Act applies in fullArt. 71(2)every product with digital elements on the EU market

Article 69(3) brings every product placed on the market before 11 December 2027 under the Article 14 reporting duty; Article 69(2) otherwise subjects such a product to the Act only on a substantial modification. How that reads for units of an older model placed on the market after that date is a question for legal. The finder draws these dates as a timing diagram against the as-at date of your list and counts the products each one touches.

The clauses behind the reporting duty

CRA Art. 14(1)Notifying actively exploited vulnerabilities to the CSIRT and ENISA

A manufacturer that becomes aware of an actively exploited vulnerability in its product must notify it at the same time to the CSIRT designated as coordinator and to ENISA, through the single reporting platform of Article 16. Applies from 11 September 2026, including to products placed on the market before 11 December 2027 (Article 69(3)).

What a notified body or authority asks to see: Procedure defining 'actively exploited' against the Article 3 definition and who decides; Single reporting platform account and credentials held by named staff; Log of exploited-vulnerability notifications
Where lists usually fall short: No criteria for when reliable evidence of exploitation starts the clock; Reporting owned by nobody outside office hours
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 14(2)(a)Early warning within 24 hours of awareness of an exploited vulnerability

An early warning of the actively exploited vulnerability must go in without undue delay and within 24 hours of the manufacturer becoming aware of it, naming, where applicable, the Member States where the manufacturer knows the product has been made available.

What a notified body or authority asks to see: Awareness timestamp recorded per case; Early warning submissions with time stamps showing the 24-hour limit met; List of Member States of availability kept current for each product
Where lists usually fall short: Awareness time not recorded, so the 24 hours cannot be evidenced; No sales footprint data to name Member States
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 14(3)Notifying severe incidents affecting product security

A manufacturer that becomes aware of a severe incident with an impact on the security of its product must notify it at the same time to the coordinating CSIRT and ENISA via the single reporting platform. An incident is severe where it harms or can harm the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or has led or can lead to malicious code being introduced or run in the product or in users' systems (Article 14(5)).

What a notified body or authority asks to see: Incident classification procedure applying the two Article 14(5) severity tests; Incident register showing classification decisions; Notifications for incidents classed severe
Where lists usually fall short: Incidents in build or update infrastructure not recognised as affecting product security; Severity judged by business impact instead of the Article 14(5) tests
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)

See the specimen timelineThe product list template