CRA Kit
Reference · Regulation (EU) 2024/2847 · updated 2026-09-06

Cyber Resilience Act timeline and obligations for software makers

The dates, the articles and the numbers, in one table you can cite. Source: Official Journal L, 20 November 2024.

DateWhat appliesArticleWho
10 Dec 2024Entry into forceArt. 71(1)No duty yet
11 Jun 2026Provisions on notified conformity assessment bodies apply (Chapter IV)Art. 35–51, 71(2)Member States, notified bodies
11 Sep 2026 Reporting obligations for actively exploited vulnerabilities and severe incidents. Early warning 24 h, notification 72 h, final report 14 days after the fix (vulnerability) or 1 month after the notification (incident), via the ENISA single reporting platform (Art. 16, operational from this date). You must also inform impacted users. Applies to products already on the market (Art. 69(3)).Art. 14, 71(2)Manufacturers (open-source stewards: Art. 24(3), formally from 11 Dec 2027, though ENISA accepts their reports from Sep 2026)
11 Dec 2027 Full application: essential requirements, vulnerability handling incl. SBOM, technical documentation, conformity assessment, EU declaration of conformity, CE marking, user information, support period, importer/distributor duties, penalties. Products placed on the market before this date are covered only if substantially modified afterwards (Art. 69(2)).Art. 13, 18–21, 24, 27–32, 64, 69, Annexes I–VIIIEveryone in scope

Reporting clocks (Article 14)

EventEarly warningNotificationFinal reportTo whom
Actively exploited vulnerability in the product24 h from awareness72 h from awareness14 days after a corrective or mitigating measure is availableCSIRT designated as coordinator + ENISA, via the single reporting platform
Severe incident having an impact on the security of the product24 h from awareness72 h from awareness1 month after the notificationSame
Impacted usersInformed without undue delay of the vulnerability/incident and of corrective or mitigating measures (Art. 14(8))Users

Key numbers

Support periodAt least 5 years from placing on the market, unless the product is expected to be in use for less (Art. 13(8)). Security updates remain available for at least 10 years after issuance or for the remainder of the support period, whichever is longer (Art. 13(9)).
Record keepingTechnical documentation and EU declaration of conformity kept for 10 years after placing on the market or for the support period, whichever is longer (Art. 13(13)).
SBOMMachine-readable, covering at least the top-level dependencies (Annex I Part II (1)). It goes in the technical documentation (Annex VII (8)). You do not have to publish it.
PenaltiesUp to €15,000,000 or 2.5 % of worldwide annual turnover (Annex I, Art. 13, Art. 14); up to €10,000,000 or 2 % (other obligations); up to €5,000,000 or 1 % (incorrect, incomplete or misleading information). See Art. 64, applicable from 11 Dec 2027. Micro and small enterprises get no fine for merely missing the 24-hour early-warning deadline. Open-source stewards get no fines at all (Art. 64(10)).
Conformity routesDefault products: internal control (Module A). Important class I: internal control only if harmonised standards, common specifications or an EU certification scheme are fully applied, otherwise third-party. Important class II: third-party (notified body). Critical: EU cybersecurity certificate where required by delegated act. See Art. 32 and Annex VIII. Categories are detailed in Implementing Regulation (EU) 2025/2392.
Out of scopePure SaaS (Recital 12, NIS2 instead); free and open-source software outside a commercial activity (Recital 18); medical devices, vehicles, civil aviation, marine equipment, national security (Art. 2).

Check anything important against the consolidated text on EUR-Lex (CELEX 32024R2847). This page is a summary, not legal advice.