Cyber Resilience Act
Updated
The European cyber resilience regulation applies by default to almost every software or connected product placed on the Union market. Its first binding deadline falls on 11 September 2026: reporting actively exploited vulnerabilities. This page keeps track of what the text requires, when, and what is not yet ready on the institutions’ side.
What the regulation requires, in short
The CRA is horizontal law: it does not target a sector, it targets a category. « Products with digital elements » — any software or hardware whose intended use involves a direct or indirect connection to a device or network — fall under it as soon as they are placed on the Union market (Art. 3). The exclusions are sectoral and narrow: medical devices under the MDR and IVDR, civil aviation, motor vehicles, among others (Art. 2).
Reasoning by industry is therefore the first reflex to correct. The question is not « is my line of business covered? » but « is what I ship a product within the meaning of the regulation? ».
The obligations, once a product is in scope
- Handle vulnerabilities throughout the announced support period, and deliver fixes free of charge.
- Maintain a software bill of materials (SBOM) covering at least the top-level dependencies.
- Publish a coordinated vulnerability disclosure policy, with a point of contact.
- Compile and maintain technical documentation (Annex VII), kept for ten years.
- Affix the CE marking after conformity assessment, according to the product class.
- Report actively exploited vulnerabilities and severe incidents (Art. 14).
The timeline
Five dates structure the application of the regulation. Two are behind us; the third is the only one that binds today.
- 10 Dec 2024
Entry into force
The regulation exists in law. None of its obligations is enforceable yet: what opens here is a preparation period.
- 11 Jun 2026
Conformity assessment bodies
Member States may notify the bodies tasked with assessing product conformity (Chapter IV). This date does not directly concern manufacturers.
This deadline rests on Art. 71 of the regulation alone: the Commission guidance does not mention it.
- 11 Sep 2026
Reporting becomes mandatory
Art. 14 enters into application. Every actively exploited vulnerability and every severe incident must be reported: early warning at 24 hours, notification at 72 hours, final report thereafter. This is the first genuinely binding obligation in the text.
- 11 Dec 2027
- 11 Jun 2028
End of earlier certificates
EU type-examination certificates and approval decisions issued under other Union harmonisation legislation cease to be valid, for the risks that legislation covered only (Art. 69 § 1).
The actual state of play
The legal timeline is one thing; whether the instruments actually exist is another. Three institutional workstreams condition compliance, and none is finished. This assessment is dated and re-verified at every update of this page.
Harmonised standards
None publishedNo CRA harmonised standard is cited in the Official Journal of the European Union. The drafts filed with ETSI — browsers, password managers, antivirus, VPNs, operating systems and a dozen other categories — were still open for comment on 12 August 2026. The practical consequence: the presumption of conformity provided for in Art. 27 is unavailable, and self-assessment proceeds without a normative safety net.
EUCC certification scheme
Not adoptedThe delegated act provided for in Art. 8, which is to designate the product categories subject to mandatory certification, has not been adopted.
Reporting platform (ENISA)
Announced, not liveThe single platform through which Art. 14 reports will pass is not yet accessible. It is announced to go live on 11 September 2026, the day the obligation applies. Three guides for authorised representatives were published between 3 and 14 August 2026. No programmatic interface is planned at this stage: submission is through a web form, which weighs on the 24-hour deadline.
Am I in scope?
Qualification turns on three questions, in this order: is what I ship a product within the meaning of the regulation, does that product fall under a sectoral exclusion, and which class does it belong to. The first two decide scope; the third only decides how heavy the assessment will be.
Classification as class I or II — and therefore the obligation to involve a third-party body — depends on the product’s principal function, not on the technologies it embeds. A product that integrates a classified component does not become classified itself.
Read the qualification tree, article by articlePlace my product in a few questions
What non-compliance costs
The penalty regime of Art. 64 applies from 11 December 2027. For a breach of the essential requirements, it provides for administrative fines of up to €15,000,000 or 2.5 % of worldwide annual turnover for the preceding financial year, whichever is higher.
One mitigation exists: Art. 64 § 10 rules out fines for micro and small enterprises on the sole ground of missing the twenty-four-hour deadline. It covers neither the other reporting deadlines nor the essential requirements.
No fine has been issued to date: the regime does not yet apply.
Our analyses on the subject
Each starts from a primary source and cites the article it deals with.
Place your product
The diagnostic follows the regulation’s qualification tree and returns a written report. No account, no code upload.
Start the diagnostic