Official sources

Cyber Resilience Act — Regulation (EU) 2024/2847

The calendar of obligations and deadlines under the Cyber Resilience Act, with references to the primary texts.

Last verified: 29 July 2026 — latest act incorporated: Delegated Regulation (EU) 2026/881, published on 20 April 2026

Calendar

  1. General application date of the Regulation

    The Regulation applies from 11 December 2027 (Article 71(2)), including the essential cybersecurity requirements, conformity assessment, CE marking and technical-documentation obligations.

    Reg. (UE) 2024/2847, art. 71

  2. The vulnerability and incident reporting obligation applies

    Article 14 becomes applicable (Article 71(2)), requiring manufacturers of products with digital elements to report actively exploited vulnerabilities and incidents affecting the security of the product. According to ENISA’s official FAQ, reports will go through the Single Reporting Platform, expected to be operational by this date with a testing period beforehand.

    Reg. (UE) 2024/2847, art. 14 · ENISA — Single Reporting Platform

  3. The Commission publishes the first official guidance on applying the CRA

    With Communication C(2026) 5252 final of 27 July 2026, the Commission approves the guidance on the application of the CRA provided for by Article 26 of the Regulation, addressed to economic operators with particular attention to microenterprises and SMEs. The guidance, annexed to the Communication, clarifies the scope of application (including remote data processing solutions and free and open-source software), substantial modifications, support periods and reporting obligations, with practical examples. It does not change the Regulation’s deadlines.

    C(2026) 5252

  4. The rules on conformity-assessment bodies apply

    Chapter IV (Articles 35–51) becomes applicable, covering the notification of notifying authorities and the conformity-assessment bodies that some manufacturers will need to use before placing a product on the EU market (Article 71(2)).

    Reg. (UE) 2024/2847, art. 71

  5. Delegated act on notifications withheld by CSIRTs adopted

    Delegated Regulation (EU) 2026/881 (C/2025/8407), adopted on 11 December 2025 and published in the EU Official Journal on 20 April 2026, supplements the CRA by specifying the terms and conditions for applying the cybersecurity-related grounds on which the CSIRT first receiving a notification may delay its dissemination to the other CSIRTs (Article 16(2) CRA). It enters into force on the twentieth day following publication.

    Delegated Reg. (EU) 2026/881

  6. Implementing act on the technical descriptions of important and critical products adopted

    Commission Implementing Regulation (EU) 2025/2392, published in the EU Official Journal on 1 December 2025, sets out the technical descriptions of the categories of important and critical products with digital elements under Article 7 of the CRA, which determine the applicable conformity-assessment procedures.

    Implementing Reg. (EU) 2025/2392

  7. The Cyber Resilience Act enters into force

    The Regulation enters into force on the twentieth day following publication (Article 71(1)). Most obligations remain subject to a transitional period, however.

    Reg. (UE) 2024/2847, art. 71

  8. The Cyber Resilience Act is published in the EU Official Journal

    Regulation (EU) 2024/2847, adopted on 23 October 2024, is published in the Official Journal of the European Union (OJ L, 20.11.2024).

    Reg. (UE) 2024/2847

What changed, and when

No changes are recorded yet for this registry.