Kilde › Guides › CRA › The CRA timeline: what starts 11 Septe…

The CRA timeline: what starts 11 September 2026, and what waits for 2027

Current to 26 August 2026 · updates land in the changelog.

The Cyber Resilience Act does not arrive at once — it arrives in stages, and conflating the stages produces both panic and complacency. The regulation entered into force on 10 December 2024; its obligations switch on across three later dates.

The dates that matter

DateWhat switches on
11 September 2026The Article 14 reporting duty: 24-hour early warning, 72-hour notification, final report — for actively exploited vulnerabilities and severe incidents, covering the whole in-scope installed base (Art 69(3)).
11 December 2026The conformity-assessment-body chapter applies — the machinery for notifying assessment bodies starts ahead of full application.
11 December 2027Full application: Annex I essential requirements, conformity assessment and CE marking, technical documentation, support-period duties — the complete obligation set for products placed on the market.

The date between the dates

One more marker worth tracking: the first harmonised standards under the Commission's standardisation request are currently expected to be cited in the Official Journal around 30 October 2026 (a timeline that has already slipped once — treat it as an estimate). That citation is what switches on the self-assessment route for Class I products; until it happens, Class I effectively needs a third party.

How to plan against this

The 2026 duty is procedural readiness — triage, templates, routing, platform seats: buildable in weeks. The 2027 set is engineering — secure development, documentation, conformity: sized in quarters. The trap is spending 2026 exclusively on the 2027 work and meeting September's reporting clock unprepared; the reporting duty arrives first, applies to everything you have ever shipped, and sits in the top penalty tier.

Related guides

Quick answers

What CRA obligations apply from 11 September 2026?
The Article 14 reporting duty — 24-hour early warning, 72-hour notification and final report for actively exploited vulnerabilities and severe incidents — covering all in-scope products including those already on the market.
When do the CRA's full security requirements apply?
From 11 December 2027: essential requirements, conformity assessment, CE marking, technical documentation and support-period duties for products placed on the market.
Be reporting-ready before 11 September 2026.

The CRA Reporting-Ready Pack: the staged 24h / 72h / final-report runbook and templates, vulnerability-vs-incident triage worksheet, CSIRT-routing and main-establishment worksheet, platform registration runbook, CVD policy and evidence log — built from the regulation and the ENISA platform guides, with pinpoint citations.

Get the pack — US$390 Free 4-page sample (PDF)

Instant download · 14-day unconditional refund · single-organisation licence · full product page

General information only — not legal advice, and never a conformity assessment. Whether a specific product falls in a listed category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, and reporting-platform mechanics are ENISA-published material marked subject to change. Sources are Regulation (EU) 2024/2847 (CELEX 32024R2847; Annex III/IV item texts read verbatim from EUR-Lex) and our audited kit research. © 2026 Kilde.

Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com