Official sources
Cyber Resilience Act — Regulation (EU) 2024/2847
The calendar of obligations and deadlines under the Cyber Resilience Act, with references to the primary texts.
Last verified: 29 July 2026 — latest act incorporated: Delegated Regulation (EU) 2026/881, published on 20 April 2026
Calendar
11 December 2027
General application date of the Regulation
The Regulation applies from 11 December 2027 (Article 71(2)), including the essential cybersecurity requirements, conformity assessment, CE marking and technical-documentation obligations.
11 September 2026
The vulnerability and incident reporting obligation applies
Article 14 becomes applicable (Article 71(2)), requiring manufacturers of products with digital elements to report actively exploited vulnerabilities and incidents affecting the security of the product. According to ENISA’s official FAQ, reports will go through the Single Reporting Platform, expected to be operational by this date with a testing period beforehand.
Reg. (UE) 2024/2847, art. 14 · ENISA — Single Reporting Platform
27 July 2026
The Commission publishes the first official guidance on applying the CRA
With Communication C(2026) 5252 final of 27 July 2026, the Commission approves the guidance on the application of the CRA provided for by Article 26 of the Regulation, addressed to economic operators with particular attention to microenterprises and SMEs. The guidance, annexed to the Communication, clarifies the scope of application (including remote data processing solutions and free and open-source software), substantial modifications, support periods and reporting obligations, with practical examples. It does not change the Regulation’s deadlines.
11 June 2026
The rules on conformity-assessment bodies apply
Chapter IV (Articles 35–51) becomes applicable, covering the notification of notifying authorities and the conformity-assessment bodies that some manufacturers will need to use before placing a product on the EU market (Article 71(2)).
11 December 2025
Delegated act on notifications withheld by CSIRTs adopted
Delegated Regulation (EU) 2026/881 (C/2025/8407), adopted on 11 December 2025 and published in the EU Official Journal on 20 April 2026, supplements the CRA by specifying the terms and conditions for applying the cybersecurity-related grounds on which the CSIRT first receiving a notification may delay its dissemination to the other CSIRTs (Article 16(2) CRA). It enters into force on the twentieth day following publication.
28 November 2025
Implementing act on the technical descriptions of important and critical products adopted
Commission Implementing Regulation (EU) 2025/2392, published in the EU Official Journal on 1 December 2025, sets out the technical descriptions of the categories of important and critical products with digital elements under Article 7 of the CRA, which determine the applicable conformity-assessment procedures.
10 December 2024
The Cyber Resilience Act enters into force
The Regulation enters into force on the twentieth day following publication (Article 71(1)). Most obligations remain subject to a transitional period, however.
20 November 2024
The Cyber Resilience Act is published in the EU Official Journal
Regulation (EU) 2024/2847, adopted on 23 October 2024, is published in the Official Journal of the European Union (OJ L, 20.11.2024).
What changed, and when
No changes are recorded yet for this registry.