CRA guide

CRA deadlines: what to do before 11 September 2026 vs 11 December 2027

The Cyber Resilience Act has two dates on the calendar, and they ask for different things. Here's what to have in place before each.

Before 11 September 2026 — reporting obligations

From this date, manufacturers must report actively exploited vulnerabilities and severe incidents affecting their products through the EU single reporting platform, on a strict clock:

  • Early warning — within 24 hours of becoming aware.
  • Notification — within 72 hours, with more detail.
  • Final report — within 14 days of a fix or mitigation becoming available.
  • This is an operational-readiness problem, not a paperwork one: you need a process (and an owner) that can actually hit these clocks before September 2026, not a template for it.

Before 11 December 2027 — full obligations

By this date, products placed on the EU market must have:

  • The Annex I essential requirements met (product security properties + vulnerability handling).
  • An SBOM maintained in a common machine-readable format (CycloneDX or SPDX).
  • Annex VII technical documentation compiled and kept current.
  • A signed EU Declaration of Conformity (Annex V).
  • The CE marking affixed.

Why the 15-month gap matters

The reporting obligations land more than a year before the full obligations do. In practice, this means buyers and procurement teams start asking for CRA evidence well before December 2027 — the 2026 date is when the pressure starts, even though it isn't the deadline for the full conformity package.

Key points

  • 11 September 2026 — vulnerability/incident reporting obligations apply.
  • 11 December 2027 — full obligations, including SBOM, technical documentation and CE marking, apply.
  • Reporting timeline once obligations start: 24h early warning, 72h notification, 14-day final report.
  • Preparation is the actual work — the 15-month gap is not extra time to wait.

Frequently asked questions

What are the CRA deadlines?
Reporting obligations (actively exploited vulnerabilities, severe incidents) apply from 11 September 2026. Full obligations — SBOM, technical documentation, conformity assessment and CE marking — apply by 11 December 2027.
Do I need to do anything before 2026?
Nothing is legally due yet, but the reporting clock (24h/72h/14-day) only works if the process exists before you need it. Most teams that wait until the deadline miss it.

Related

General information about the EU Cyber Resilience Act — not legal advice. Normproof provides tooling and audit-ready evidence; the manufacturer self-declares conformity. For your specific product, run the free readiness check or consult a qualified advisor.

See exactly what the CRA requires for your product.

Run the free readiness check — your category, obligations, and deadlines in 60 seconds.