Cyber Resilience Act enters into force
Regulation (EU) 2024/2847 was published in the Official Journal on 20 November 2024 and entered into force twenty days later. No obligations applied yet: this date started the transition period.
· Article 71(1)
The dates on which the Cyber Resilience Act starts to bind manufacturers, with suggested preparation targets in between. Add them to your own calendar in one click.
Regulation (EU) 2024/2847 was published in the Official Journal on 20 November 2024 and entered into force twenty days later. No obligations applied yet: this date started the transition period.
· Article 71(1)
Chapter IV (Articles 35 to 51) on the notification of conformity assessment bodies applies from this date, so Member States can designate the notified bodies that carry out third-party conformity assessments.
· Article 71(2)
Article 14 applies from this date. Manufacturers must notify actively exploited vulnerabilities and severe incidents: an early warning within 24 hours, a notification within 72 hours, and a final report within 14 days of a corrective measure being available (vulnerabilities) or within one month of the notification (incidents). This also covers products placed on the market before 11 December 2027.
· Articles 14, 69(3) and 71(2)
Not a legal deadline. The vulnerability handling requirements ask for a software bill of materials in a machine-readable format covering at least the top-level dependencies. Producing it for every release nine months ahead leaves time to act on what it reveals.
· Annex I, Part II, point 1
Not a legal deadline. The risk assessment decides which essential requirements apply to the product and how they are met, so the rest of the technical documentation depends on it. Six months of margin is a reasonable buffer.
· Article 13(2) and (3)
Not a legal deadline. The technical documentation must exist before a product is placed on the market. Finishing it three months early leaves room for the conformity assessment and the EU declaration of conformity.
· Article 31 and Annex VII
All remaining obligations apply to products with digital elements placed on the EU market from this date: the essential requirements of Annex I, conformity assessment, technical documentation, the EU declaration of conformity and CE marking. Breaches of the essential requirements or of Articles 13 and 14 can be fined up to EUR 15 000 000 or 2.5 % of worldwide annual turnover, whichever is higher. Products already on the market are covered only if substantially modified afterwards.
· Articles 64(2), 69(2) and 71(2)
The binding dates are set by Articles 14, 69 and 71 of Regulation (EU) 2024/2847. The suggested targets are RedComply planning advice and have no legal effect. This page is general information, not legal advice.
Regulation (EU) 2024/2847 on EUR-LexNot sure how ready you are? Take the free CRA readiness self-assessment.
Start the assessmentWe use cookies and similar tools to make this site work, to measure usage, and (with your permission) to record sessions for product research. You can change your choice any time via "Cookie preferences" in the footer. Read our cookie policy