Product Assurance Learning

Home / Guides

Guide

Cyber Resilience Act Dates: What Applies in 2026 and 2027

The Cyber Resilience Act, Regulation (EU) 2024/2847, applies in two main steps. Its reporting obligations for actively exploited vulnerabilities and severe incidents have applied since 11 September 2026. Its main cybersecurity obligations apply to products with digital elements placed on the EU market from 11 December 2027, when the CE marking will also cover them.

7 min readUpdated 3 October 2026By the VeridEx editorial team

What the Cyber Resilience Act covers

The Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, sets cybersecurity rules for products with digital elements. These are hardware and software products that connect, directly or indirectly, to a device or a network. A connected industrial machine, a controller with remote access or a device that talks to a cloud dashboard can all fall into this group.

The CRA is a regulation, so it applies directly in every Member State with the same text. You do not need to look for national versions of it. The text published in the Official Journal of the European Union is the text that applies.

Its focus is cybersecurity as such. It asks for secure design, vulnerability handling and security updates. It also covers the whole life of the product, and not only the moment of sale. This is a change for many manufacturers, who are used to thinking of compliance as a check done once before shipment.

The key Cyber Resilience Act dates

The CRA applies in steps. Two dates matter most for manufacturers outside the EU:

DateWhat applies
11 September 2026Reporting obligations: actively exploited vulnerabilities and severe incidents affecting the security of your products must be reported through the ENISA single reporting platform
11 December 2027Main obligations: products with digital elements placed on the market from this date must meet the CRA cybersecurity requirements, and the CE marking also declares compliance with them

Both dates are set in the regulation as currently published. Guidance on how the rules work in practice is still developing, so check the latest position in the Official Journal and the Commission's guidance before you finalise your plans.

Reporting obligations since 11 September 2026

The reporting obligations have applied since 11 September 2026. Manufacturers must report two kinds of events:

  • actively exploited vulnerabilities in their products;
  • severe incidents that affect the security of their products.

Reports go through a single reporting platform managed by ENISA, the EU cybersecurity agency. The deadlines are short. They start with an early warning within 24 hours.

Because the duty concerns your products on the EU market, it can apply to models you already sell, and not only to new designs. A short deadline leaves no time to work out the process when the event happens. You need an internal procedure in place beforehand:

  1. Name an owner for vulnerability handling, with a deputy.
  2. Define how information reaches that person: customers, service technicians, your EU partner, researchers or your own monitoring.
  3. Decide who assesses whether a vulnerability is actively exploited, and how quickly.
  4. Prepare the steps for the early warning and the follow-up reports through the single reporting platform.
  5. Keep a record of each case: product, version, findings, decisions and dates.

This sits next to your other after-sale duties. Under the EU product laws you already have to investigate complaints, take corrective action and inform authorities when a product presents a risk. The CRA adds a specific reporting channel for security events. Consumer accidents under the General Product Safety Regulation go through a different portal, the Safety Business Gateway, so do not mix the two.

Main obligations from 11 December 2027

The main obligations apply from 11 December 2027. Like other EU product laws, the CRA applies per unit placed on the market. A unit placed on the market on 10 December 2027 does not have to meet the main CRA requirements. An identical unit placed one day later does.

From that date, the CE marking on a product with digital elements also declares compliance with the CRA cybersecurity requirements. The commitment covers the life of the product, including security updates. In practice, you will need:

  • a design process that takes security into account from the start;
  • a vulnerability handling process that works after the sale;
  • a way to provide security updates to products in the field;
  • technical documentation that shows how the requirements are met;
  • an updated EU Declaration of Conformity for units placed from that date.

The CRA also asks for an electronic contact on the product information, such as a website or email address, next to your postal address. Plan the space on the label or data plate early.

The CRA allows the Commission to adopt common specifications when harmonised standards are missing or not good enough. Common specifications, like harmonised standards, can give presumption of conformity. Check which harmonised standards and common specifications exist for your product as the date approaches, because the situation is changing.

How the CRA relates to CE marking and other EU laws

The CRA does not replace the other product laws that apply to your product. It is added to them.

Machinery. The CRA and the machinery law apply together. The Machinery Regulation, Regulation (EU) 2023/1230, applies to machinery placed on the market from 20 January 2027. It asks for protection against corruption of the control system, as a safety matter. The CRA asks for cybersecurity as such. A connected machine will have to meet both. Our guide to the Machinery Regulation 2023/1230 changes covers the machinery side.

Radio equipment. Since 1 August 2025, Delegated Regulation (EU) 2022/30 under the Radio Equipment Directive has required many internet-connected radio products to protect the network, personal data and against fraud. The RED cybersecurity requirements are expected to give way to the CRA once it fully applies, and Delegated Regulation (EU) 2022/30 is currently set to be repealed from 11 December 2027. Check the latest position. Until then, the RED rules apply. See our guide on RED cybersecurity and EN 18031.

Take a hypothetical machine with built-in Wi-Fi, sold to professional users. The same model would move through three regimes. Units placed on the market now follow the Machinery Directive, Directive 2006/42/EC, plus the RED with its cybersecurity delegated act. Units placed from 20 January 2027 follow the Machinery Regulation instead. Units placed from 11 December 2027 must also meet the CRA. The date of each unit counts.

What to prepare now

December 2027 may look far away, but design cycles for industrial products are long. A product you design today may still be in production then. A practical plan:

  • List your products with digital elements. Include products with any network or device connection, and the software you place on the market.
  • Set up the reporting procedure now. The reporting obligations already apply.
  • Map each product against the dates. Record which units will be placed on the market before and after 20 January 2027 and 11 December 2027.
  • Review your design and update process. Check how you handle vulnerabilities and how you deliver security updates in the field.
  • Brief your EU partner. Agree how complaints, authority requests and security reports reach you, and how quickly you will answer.
  • Plan updates to the file and the declaration so that each unit placed after the relevant date meets the new rules.

The Cyber Resilience Act course goes through the requirements in depth.

Key points

  • The CRA, Regulation (EU) 2024/2847, covers products with digital elements that connect to a device or a network.
  • Reporting of actively exploited vulnerabilities and severe incidents has applied since 11 September 2026, through the ENISA single reporting platform.
  • Reporting starts with an early warning within 24 hours, so a procedure must be ready in advance.
  • The main obligations apply to units placed on the market from 11 December 2027, and the CE marking will then cover them.
  • The CRA applies together with the machinery law and is expected to take over the RED cybersecurity role.

To see how the CRA fits into the wider CE system, start with the free first module of CE Marking Fundamentals.

Learn the whole route, step by step

CE Marking Fundamentals takes you from the EU market rules to your first shipment, with templates and quizzes. Module 1 is free.

Frequently asked questions

When does the Cyber Resilience Act apply?

In two main steps. The reporting obligations for actively exploited vulnerabilities and severe incidents have applied since 11 September 2026. The main obligations apply to products with digital elements placed on the market from 11 December 2027. Check the latest position in the Official Journal, as guidance is still developing.

Do I have to report vulnerabilities for products I already sell in the EU?

The reporting duty concerns your products on the EU market, so it can apply to models you already sell. Reports go through the ENISA single reporting platform, starting with an early warning within 24 hours. Prepare an internal procedure so you can meet these deadlines.

Does the CRA replace the Machinery Regulation for connected machines?

No. The two apply together. The Machinery Regulation asks for protection against corruption of the control system as a safety matter, while the CRA asks for cybersecurity as such: secure design, vulnerability handling and updates.

What is the difference between the CRA and RED cybersecurity?

RED cybersecurity comes from Delegated Regulation (EU) 2022/30 and has applied to many internet-connected radio products since 1 August 2025. The CRA covers products with digital elements more broadly and adds duties across the product life. The RED cybersecurity requirements are currently set to give way to the CRA from 11 December 2027.

This guide is general training material, not legal advice. EU rules and standard citations change: check the latest texts in the Official Journal of the European Union before you decide.

Related guides

Be first in line

Join the waitlist for launch pricing and a free CE applicability checklist. We will only email you about VeridEx courses.