CRA Compliance Deadline Calendar

    The dates on which the Cyber Resilience Act starts to bind manufacturers, with suggested preparation targets in between. Add them to your own calendar in one click.

    Legend Past Upcoming Binding deadline Suggested target, not a legal date
    1. Regulation

      Cyber Resilience Act enters into force

      Regulation (EU) 2024/2847 was published in the Official Journal on 20 November 2024 and entered into force twenty days later. No obligations applied yet: this date started the transition period.

      · Article 71(1)

    2. Regulation

      Rules on notified bodies start to apply

      Chapter IV (Articles 35 to 51) on the notification of conformity assessment bodies applies from this date, so Member States can designate the notified bodies that carry out third-party conformity assessments.

      · Article 71(2)

    3. Reporting Binding deadline

      Reporting obligations for manufacturers apply

      Article 14 applies from this date. Manufacturers must notify actively exploited vulnerabilities and severe incidents: an early warning within 24 hours, a notification within 72 hours, and a final report within 14 days of a corrective measure being available (vulnerabilities) or within one month of the notification (incidents). This also covers products placed on the market before 11 December 2027.

      · Articles 14, 69(3) and 71(2)

    4. Suggested target

      Suggested target: software bill of materials in place

      Not a legal deadline. The vulnerability handling requirements ask for a software bill of materials in a machine-readable format covering at least the top-level dependencies. Producing it for every release nine months ahead leaves time to act on what it reveals.

      · Annex I, Part II, point 1

    5. Suggested target

      Suggested target: cybersecurity risk assessment complete

      Not a legal deadline. The risk assessment decides which essential requirements apply to the product and how they are met, so the rest of the technical documentation depends on it. Six months of margin is a reasonable buffer.

      · Article 13(2) and (3)

    6. Suggested target

      Suggested target: technical documentation ready

      Not a legal deadline. The technical documentation must exist before a product is placed on the market. Finishing it three months early leaves room for the conformity assessment and the EU declaration of conformity.

      · Article 31 and Annex VII

    7. Regulation Binding deadline

      Cyber Resilience Act applies in full

      All remaining obligations apply to products with digital elements placed on the EU market from this date: the essential requirements of Annex I, conformity assessment, technical documentation, the EU declaration of conformity and CE marking. Breaches of the essential requirements or of Articles 13 and 14 can be fined up to EUR 15 000 000 or 2.5 % of worldwide annual turnover, whichever is higher. Products already on the market are covered only if substantially modified afterwards.

      · Articles 64(2), 69(2) and 71(2)

    Where these dates come from

    The binding dates are set by Articles 14, 69 and 71 of Regulation (EU) 2024/2847. The suggested targets are RedComply planning advice and have no legal effect. This page is general information, not legal advice.

    Regulation (EU) 2024/2847 on EUR-Lex

    Not sure how ready you are? Take the free CRA readiness self-assessment.

    Start the assessment