Implementing and delegated acts, corrigenda, ENISA guidance, harmonised standards and application deadlines for the Cyber Resilience Act, pulled from the official sources.
30 updates · Sources last checked 6 October 2026
Notified bodies (Chapter IV)
11 June 2026
Vulnerability reporting (Article 14)
11 September 2026
Full application
11 December 2027
DeadlineHigh impact
Full application of the Cyber Resilience Act — 11 December 2027
All remaining obligations apply from 11 December 2027 (Article 71(2)): essential requirements of Annex I, conformity assessment, CE marking, technical documentation, the EU declaration of conformity and the obligations of importers and distributors. Products placed on the market before that date are covered only if substantially modified afterwards (Article 69).
Action required
Plan the placing-on-market date of every product release against this date; anything shipped after it needs the full technical file and declaration.
Article 14 reporting obligations apply — ENISA Single Reporting Platform live
From 11 September 2026 manufacturers must notify actively exploited vulnerabilities and severe incidents through the ENISA Single Reporting Platform: early warning within 24 hours, vulnerability or incident notification within 72 hours, final report within 14 days (vulnerabilities) or one month (incidents). Notifications go to the CSIRT designated as coordinator and to ENISA via the platform (Article 14 and Article 16).
Action required
Register your reporting representatives on the platform, decide who signs off notifications, and rehearse the 24 h / 72 h / 14 d sequence with a tabletop exercise.
The EU Agency for Cybersecurity (ENISA) has deployed the initial operating capability of the Single Reporting… Single Reporting Platform (SRP) National/Authorities Private Sector
Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on public contracts and concessions, repealing Directives 2014/23/EU, 2014/24/EU and 2014/25/EU, and amending Regulations (EC) No 1370/2007, (EU) 2023/1542, (EU) 2024/1157, (EU) 2024/1252, (EU) 2024/1735, (EU) 2024/1781, (EU) 2024/2847, (EU) 2024/3110 and (EU) 2025/40, and Directives 2008/98/EC, (EU) 2019/882, (EU) 2022/2381, (EU) 2023/1791 and (EU) 2024/1760 (Public Procurement Act)
Commission proposal (not yet adopted): Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on public contracts and concessions, repealing Directives 2014/23/EU, 2014/24/EU and 2014/25/EU, and amending Regulations (EC) No 1370/2007, (EU) 2023/1542, (EU) 2024/1157, (EU) 2024/1252, (EU) 2024/1735, (EU) 2024/1781, (EU) 2024/2847, (EU) 2024/3110 and (EU) 2025/40, and Directives 2008/98/EC, (EU) 2019/882, (EU) 2022/2381, (EU) 2023/1791 and (EU) 2024/1760 (Public Procurement Act)
ETSI launches approval process for 17 European Standards supporting the Cyber Resilience Act
ETSI published 17 vertical final-draft European Standards developed under the CRA standardisation request, one per product category (for example routers, password managers, smart home hubs, connected toys, wearables). They translate Annex I essential requirements into testable criteria for each category. Until they are cited in the Official Journal they give no presumption of conformity under Article 27.
Action required
Read the draft that matches your product category and map its clauses to your Annex I applicability matrix; treat it as a preview, not as a harmonised standard.
NATO Communications and Information Agency (NCIA), along with AI and cybersecurity innovator AISLE, join the Common Vulnerabilities and Exposures (CVE) Numbering Authorities (CNAs), under the ENISA Root. Vulnerability Services National / EU authorities Private Sector
Berichtigung der Verordnung (EU) 2024/2847 des Europäischen Parlaments und des Rates vom 23. Oktober 2024 über horizontale Cybersicherheitsanforderungen für Produkte mit digitalen Elementen und zur Änderung der Verordnungen (EU) Nr. 168/2013 und (EU) 2019/1020 und der Richtlinie (EU) 2020/1828 (Cyberresilienz-Verordnung) (ABl. L, 2024/2847, 20.11.2024) (not available in English; language DEU)
A Practical Guide to Secure by Design and Default Principles for SMEs Modern products with digital elements are increasingly expected to be secure by design and secure by default. However, many organisations, in particular small and medium… Product Security National / EU authorities Private Sector
Commission publishes new guidance to support timely Cyber Resilience Act implementation
In a clear demonstration of its commitment to simplification and timely implementation, the Commission today published practical guidance to help manufacturers, developers, and businesses of all sizes meet their obligations under the Cyber Resilience Act.
The SME Cyber Resilience Maturity Assessment Model provides a structured approach for micro, small and medium-sized enterprises (SMEs) to evaluate and strengthen their overall cyber resilience, while taking into account the requirements of the… Product Security National / EU authorities Private Sector
Where do SMEs stand in preparing for the Cyber Resilience Act?
The EU Agency for Cybersecurity (ENISA) publishes the Micro, Small and Medium-sized enterprises (SME) Cyber Resilience Maturity Assessment Model, a simple and practical guidance for SMEs to support them assess their current status, identify… Product Security Product Security and Certification National / EU authorities Private Sector
ENISA is is working on practical guidance, tools and support activities tailored to the realities and needs of smaller organisations, to help small and medium-sized enterprises (SMEs) understand and implement the Cyber Resilience Act (CRA). This… Product Security National / EU authorities Private Sector
Chapter IV applies — Member States may notify conformity assessment bodies
Articles 35 to 51 on the notification of conformity assessment bodies apply from 11 June 2026 (Article 71(2)). Notified bodies for the CRA can now be designated, which is the precondition for module B, module H and EU-type examination routes for important and critical products.
Action required
If your product is important class I/II or critical, shortlist notified bodies as they appear in NANDO and ask for lead times.
ENISA launched a survey at the end of 2025 to gather factual data on how organisations across industries and of varying sizes are approaching Software Bill of Materials (SBOM) adoption in response to the EU Cyber Resilience Act (CRA). This report… Product Security National / EU authorities Private Sector
Technical Competence Requirements for CRA Notified Bodies
The document focuses on high-level competences which will be required to perform conformity assessment activities, in particular the experience and training requirements for the personnel employed by a CAB wishing to be notified (CRA NB) –… Product Security Product Security and Certification National / EU authorities
Today, four organisations have newly joined the Common Vulnerabilities and Exposures (CVE™) Program as CVE Numbering Authorities (CNAs) under ENISA Root. These organisations were all trained and onboarded by ENISA. Vulnerability Services National / EU authorities Private Sector
Rectificatif au règlement (UE) 2024/2847 du Parlement européen et du Conseil du 23 octobre 2024 concernant des exigences de cybersécurité horizontales pour les produits comportant des éléments numériques et modifiant les règlements (UE) n° 168/2013 et (UE) 2019/1020 et la directive (UE) 2020/1828 (règlement sur la cyberrésilience) (JO L, 2024/2847, 20.11.2024) (not available in English; language FRA)
Korigendum k nariadeniu Európskeho parlamentu a Rady (EÚ) 2024/2847 z 23. októbra 2024 o horizontálnych požiadavkách kybernetickej bezpečnosti pre produkty s digitálnymi prvkami a o zmene nariadení (EÚ) č. 168/2013 a (EÚ) 2019/1020 a smernice (EÚ) 2020/1828 (akt o kybernetickej odolnosti) (Ú. v. EÚ L, 2024/2847, 20.11.2024) (not available in English; language SLK)
Call for Feedback: Advancing Software Supply Chain Security together!
ENISA invites industry stakeholders and interested parties to provide their feedback on the draft SBOM Landscape Analysis and the Technical Advisory for Secure Use of Package Managers. Product Security Product Security and Certification National / EU authorities Private Sector
Commission Delegated Regulation (EU) 2026/881 — cybersecurity grounds for delaying dissemination of notifications
Supplements the CRA by specifying the terms and conditions under which a CSIRT may delay disseminating a vulnerability notification received under Article 14 on cybersecurity-related grounds (Article 16(2)). Relevant to how and when your reported vulnerabilities reach other CSIRTs and ENISA.
Commission Implementing Regulation (EU) 2025/2392 — technical description of important and critical product categories
Adopted under Article 7(4), this implementing regulation gives the precise technical description of each product category listed in Annex III (important, class I and II) and Annex IV (critical). It is the text that decides borderline classification cases and therefore which conformity assessment route (module A self-assessment or a notified-body route) is available.
Action required
Re-check your product classification against the technical descriptions; a move into class II or critical removes the self-assessment route.
Stepping up our role in Vulnerability Management: ENISA Becomes CVE Root
The European Union Agency for Cybersecurity (ENISA) is now a Common Vulnerabilities and Exposures (CVE) Program-Root, thus becoming a central point of contact within the CVE program for national/EU authorities, EU CSIRTs network members, and… Vulnerability Services National / EU authorities Private Sector
Corrigendum to Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) (OJ L, 2024/2847, 20.11.2024)
Rectificatif au règlement (UE) 2024/2847 du Parlement européen et du Conseil du 23 octobre 2024 concernant des exigences de cybersécurité horizontales pour les produits comportant des éléments numériques et modifiant les règlements (UE) n° 168/2013 et (UE) 2019/1020 et la directive (UE) 2020/1828 (règlement sur la cyberrésilience) (JO L, 2024/2847, 20.11.2024) (not available in English; language FRA)
Commission Delegated Regulation (EU) 2025/1535 — exclusion of certain L-category vehicle products
Supplements the CRA with an exclusion for products with digital elements that fall within the scope of Regulation (EU) No 168/2013 on two- or three-wheel vehicles and quadricycles, where equivalent cybersecurity requirements apply under that framework (Article 2(5) mechanism).
Corrigendum to Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) (OJ L, 2024/2847, 20.11.2024)
Consult the European Vulnerability Database to enhance your digital security!
The European Union Agency for Cybersecurity (ENISA) has developed the European Vulnerability Database - EUVD as provided for by the NIS2 Directive. The EUVD service , to be maintained by ENISA, is now… Vulnerability Services National / EU authorities Private Sector
Regulation (EU) 2025/327 of the European Parliament and of the Council of 11 February 2025 on the European Health Data Space and amending Directive 2011/24/EU and Regulation (EU) 2024/2847 (Text with EEA relevance)
The Cyber Resilience Act was published in the Official Journal on 20 November 2024 and entered into force on 10 December 2024. The staggered application dates are 11 June 2026 (Chapter IV, notified bodies), 11 September 2026 (Article 14 reporting) and 11 December 2027 (everything else).
Corrigendum to Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) (OJ L, 2024/2847, 23.10.2024)
Once a day RedComply checks EUR-Lex (the Official Journal and every act that is based on, completes, amends or corrects Regulation (EU) 2024/2847), ENISA news and publications, the European Commission's Cyber Resilience Act pages and ETSI press releases. Items marked "automatic" keep the official title and link to the official source. Entries marked "RedComply" are written by us and add a plain-language summary and, where relevant, what a manufacturer should do. This page is general information, not legal advice.
See every Cyber Resilience Act date on one timeline, or check how ready you are.
We use cookies and similar tools to make this site work, to measure usage, and (with your permission) to record sessions for product research. You can change your choice any time via "Cookie preferences" in the footer. Read our cookie policy