The CRA timeline, and the date that catches small vendors
Every applicable date of the Cyber Resilience Act in one table, why the reporting date is harder than full application, and a schedule that works backwards.
Regulation (EU) 2024/2847, the Cyber Resilience Act, does not arrive all at once. It arrives in stages, and the stage that catches small vendors is not the one they have in their calendar.
The dates
| Date | What applies |
|---|---|
| 2024-11-20 | Published in the Official Journal. |
| +20 days | Entry into force. The Regulation states this as a formula rather than a date. Obligations do not start here. |
| 2026-06-11 | Provisions on notification of conformity assessment bodies. |
| 2026-09-11 | Reporting of actively exploited vulnerabilities and severe incidents. Applies to products already on the market. |
| 2027-12-11 | Full application: essential requirements, SBOM, vulnerability handling, technical documentation, conformity assessment, CE marking. |
Why the middle date is the hard one
Everything else in the Regulation is work you can schedule. Reporting is work that arrives on a schedule you do not set, at an hour you do not choose, with a clock already running. A company that has done none of the documentation but can notice and report within a day is in a better position than one with a perfect technical file and no monitoring.
The phrase that does the damage is that it applies to products already placed on the market. There is no grandfather clause for the version you shipped in 2024 and stopped thinking about. If it is still out there and still supported, it is still yours.
A schedule that works backwards
- Now: list the artefacts you ship and decide which are in scope. Write down the reason for each verdict.
- Now: get an SBOM out of every release build. This is the input to everything else and the only purely mechanical step.
- Before the reporting date: monitoring that tells you when something you ship is being actively exploited, and a named person who acts on it.
- Before the reporting date: a disclosure policy, a contact address that reaches a human, and a security.txt.
- Before the reporting date: a rehearsal. Run one fake report end to end and time it.
- Through 2027: technical documentation, declared support periods, conformity assessment, CE marking.
The order is deliberate. Steps three to five are cheap and time-critical; step six is expensive and has a longer runway. Teams that start with the documentation because it looks like the bigger task arrive at the reporting date with a technical file and no way to notice an exploited component.
A note on dates you read anywhere
The Regulation is freely readable and it is the only thing that settles a disagreement between two summaries. Where a date matters to a decision you are making, open https://eur-lex.europa.eu/eli/reg/2024/2847/oj and read the transitional provisions yourself.