Guides

The CRA timeline, and the date that catches small vendors

Every applicable date of the Cyber Resilience Act in one table, why the reporting date is harder than full application, and a schedule that works backwards.

Regulation (EU) 2024/2847, the Cyber Resilience Act, does not arrive all at once. It arrives in stages, and the stage that catches small vendors is not the one they have in their calendar.

The dates

DateWhat applies
2024-11-20Published in the Official Journal.
+20 daysEntry into force. The Regulation states this as a formula rather than a date. Obligations do not start here.
2026-06-11Provisions on notification of conformity assessment bodies.
2026-09-11Reporting of actively exploited vulnerabilities and severe incidents. Applies to products already on the market.
2027-12-11Full application: essential requirements, SBOM, vulnerability handling, technical documentation, conformity assessment, CE marking.

Why the middle date is the hard one

Everything else in the Regulation is work you can schedule. Reporting is work that arrives on a schedule you do not set, at an hour you do not choose, with a clock already running. A company that has done none of the documentation but can notice and report within a day is in a better position than one with a perfect technical file and no monitoring.

The phrase that does the damage is that it applies to products already placed on the market. There is no grandfather clause for the version you shipped in 2024 and stopped thinking about. If it is still out there and still supported, it is still yours.

A schedule that works backwards

  1. Now: list the artefacts you ship and decide which are in scope. Write down the reason for each verdict.
  2. Now: get an SBOM out of every release build. This is the input to everything else and the only purely mechanical step.
  3. Before the reporting date: monitoring that tells you when something you ship is being actively exploited, and a named person who acts on it.
  4. Before the reporting date: a disclosure policy, a contact address that reaches a human, and a security.txt.
  5. Before the reporting date: a rehearsal. Run one fake report end to end and time it.
  6. Through 2027: technical documentation, declared support periods, conformity assessment, CE marking.

The order is deliberate. Steps three to five are cheap and time-critical; step six is expensive and has a longer runway. Teams that start with the documentation because it looks like the bigger task arrive at the reporting date with a technical file and no way to notice an exploited component.

A note on dates you read anywhere

The Regulation is freely readable and it is the only thing that settles a disagreement between two summaries. Where a date matters to a decision you are making, open https://eur-lex.europa.eu/eli/reg/2024/2847/oj and read the transitional provisions yourself.

Keep reading