Skip to main content

Deadlines

All important dates and transition periods for the European Cyber Resilience Act (CRA) in a clear timeline. Check your compliance obligations in due time.

12/10/2024Past

CRA entered into force

Regulation (EU) 2024/2847 is in force; obligations apply in stages.

06/11/2026Past

Notified bodies start operating

Provisions on notified bodies apply; the first conformity assessment bodies begin operating.

09/11/2026... days left

Reporting obligations (Art. 14)

Actively exploited vulnerabilities and severe incidents: 24h early warning, 72h notification, final report — via the ENISA Single Reporting Platform.

12/11/2026

Sufficient assessment capacity

Member states ensure a sufficient number of notified bodies (Art. 35(2)).

12/11/2027

Full applicability

All CRA requirements apply: Annex I before placing on the market, lifecycle vulnerability handling, transparency, CE marking.

These contents are general, automatically processed information based on Regulation (EU) 2024/2847 and do not replace legal advice in individual cases. No legal services within the meaning of the RDG. Data basis as of: 07/08/2026.