Cyber Resilience Act Dates: What Applies in 2026 and 2027
Cyber Resilience Act dates: vulnerability reporting since 11 September 2026, main obligations from 11 December 2027, and how the CRA fits with CE marking.

Under the Cyber Resilience Act, Regulation (EU) 2024/2847, most products with digital elements fall in the default category and may use self-assessment. Products whose core functionality matches a category in Annex III are important products of class I or class II, and those matching Annex IV are critical products. Class II and critical products need a notified body or a European cybersecurity certification, and class I needs one unless you fully apply harmonised standards, common specifications or certification.
The Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, sets cybersecurity requirements for products with digital elements. The requirements are the same for every product. What changes with the category is the conformity assessment procedure you may use, and so whether a notified body must be involved. There are four categories:
The category affects the conformity assessment route from the date the main obligations apply, 11 December 2027. For the full timeline, including the reporting obligations that have applied since 11 September 2026, see our Cyber Resilience Act dates guide.
Article 7 of the CRA defines important products. Class I and class II reflect the level of cybersecurity risk linked to the product's function. The names below are taken from Annex III. Some entries are shortened here, so read the full wording in the Official Journal.
Article 8 deals with critical products. Annex IV currently lists three categories:
The Commission can amend Annex III and Annex IV by delegated act, adding, moving or removing categories, with a transition period. Check the consolidated text before you rely on a list you saved some time ago.
The names in Annex III and Annex IV are short. Article 7(4) of the CRA required the Commission to adopt an implementing act with a technical description of each category by 11 December 2025. The Commission did so with Commission Implementing Regulation (EU) 2025/2392 of 28 November 2025 on the technical description of categories of important and critical products with digital elements. It was published in the Official Journal on 1 December 2025 and entered into force on 21 December 2025.
Its Annex I describes the important product categories, class I and class II. Its Annex II describes the critical product categories. When a category name could be read in more than one way, the technical description is the text to compare with your product. Read the description for every category that might be close to your product, and keep a copy of your reasoning.
A product is important or critical only if it has the core functionality of a category in Annex III or Annex IV. Article 7(1) sets this rule. It is the main question in any classification.
Article 7(1) also says that integrating an important product into another product does not, in itself, make the host product subject to the stricter procedures. A component may be important while the product that contains it stays in the default category. The host product still has to meet all the CRA requirements.
In practice, ask these questions for each product:
Where the answer is unclear, record the arguments on both sides. Check the Commission guidance on the CRA, which the Commission started publishing in July 2026, for its reading of borderline cases.
Article 32(1) lists four procedures, set out in Annex VIII:
Which of these you may use depends on the category:
| Category | Examples (Annex names) | Allowed routes | Notified body? |
|---|---|---|---|
| Default | Any product with digital elements not listed in Annex III or IV | A, B+C, H or a European cybersecurity certification scheme | No, unless you choose B+C or H |
| Important, class I | Password managers, VPN products, routers, smart home products with security functionalities | A only if harmonised standards, common specifications or a European cybersecurity certification scheme (at least level "substantial") are applied; otherwise B+C or H | Yes, unless you fully apply those specifications or use certification |
| Important, class II | Hypervisors, firewalls, tamper-resistant microcontrollers | B+C, H, or a European cybersecurity certification scheme at least at level "substantial" | Yes, or certification under a scheme |
| Critical | Hardware Devices with Security Boxes, smartcards, secure elements | A European cybersecurity certificate if a delegated act under Article 8(1) requires it; otherwise the class II routes | Yes, or certification under a scheme |
For class I, module A depends on full application. If you apply a harmonised standard only in part, or no suitable standard exists, you need B+C or H.
For critical products, Article 8(1) allows the Commission to require a European cybersecurity certificate at assurance level at least "substantial" for some Annex IV categories. Until such an act applies to your category, Article 8(2) sends you to the class II procedures. Check whether a delegated act has been adopted for your product.
Two further points from Article 32. Free and open-source software in an Annex III category may use any procedure in Article 32(1), provided the technical documentation is made public. Article 32(6) also requires conformity assessment fees to take into account the needs of microenterprises and small and medium-sized enterprises (SMEs), and to be reduced proportionately.
The CRA provisions on the notification of conformity assessment bodies have applied since 11 June 2026. Look for bodies notified under the CRA in NANDO, the Commission's database, and check that their scope covers your module and product category. Our guide Do I need a notified body? explains the modules and how to choose a body.
For class I products, harmonised standards decide whether module A is possible. The Commission adopted standardisation request M/606, which covers 41 standards, both horizontal and product-specific. According to the Commission, the first request gives priority to standards for the important and critical product categories in Annex III and Annex IV.
The Commission's implementation timeline currently lists the first standardisation deliverables for the third quarter of 2026, and more by 30 October 2027. A standard gives presumption of conformity only once its reference is published in the Official Journal. Check the latest position before you plan a module A route, and read any restriction in the citation. Our guide on harmonised standards and presumption of conformity explains how citations work.
Radio products have a separate, current cybersecurity framework under the Radio Equipment Directive, with the EN 18031 series. See our RED cybersecurity guide.
The Cyber Resilience Act course works through these steps in detail.
To see how the CRA fits into the wider CE system, start with the free first module of CE Marking Fundamentals.
CE Marking Fundamentals takes you from the EU market rules to your first shipment, with templates and quizzes. Module 1 is free.
Yes, if routing is its core functionality. Annex III, class I, lists "routers, modems intended for the connection to the internet, and switches". Check the technical description in Implementing Regulation (EU) 2025/2392 to confirm your product matches it.
Only if you do not fully apply harmonised standards, common specifications or a European cybersecurity certification scheme at level "substantial" or higher. If you do, module A is allowed. Otherwise you must use EU-type examination (B+C) or full quality assurance (H), both with a notified body.
Important products are listed in Annex III, split into class I and class II. Critical products are listed in Annex IV and may be required to obtain a European cybersecurity certificate by delegated act. Without such an act, critical products follow the class II procedures.
Not in itself. Article 7(1) says that integrating a product with the core functionality of an Annex III category does not, in itself, subject the host product to the stricter procedures. The host product is classified by its own core functionality.
This guide is general training material, not legal advice. EU rules and standard citations change: check the latest texts in the Official Journal of the European Union before you decide.
Cyber Resilience Act dates: vulnerability reporting since 11 September 2026, main obligations from 11 December 2027, and how the CRA fits with CE marking.
When EU law requires a notified body: modules A to H, rules for LVD, EMC, RED, ATEX, PED and machinery, how to check NANDO and what a notified body issues.
RED cybersecurity since August 2025: Delegated Regulation 2022/30, Article 3(3)(d)(e)(f), EN 18031 restrictions and when a notified body becomes necessary.
Join the waitlist for launch pricing and a free CE applicability checklist. We will only email you about VeridEx courses.
Thanks, you are on the list. We will be in touch before launch.