CRA Regulatory Updates

    Implementing and delegated acts, corrigenda, ENISA guidance, harmonised standards and application deadlines for the Cyber Resilience Act, pulled from the official sources.

    30 updates · Sources last checked 6 October 2026

    Notified bodies (Chapter IV)

     

    11 June 2026

    Vulnerability reporting (Article 14)

     

    11 September 2026

    Full application

     

    11 December 2027

    DeadlineHigh impact

    Full application of the Cyber Resilience Act — 11 December 2027

    All remaining obligations apply from 11 December 2027 (Article 71(2)): essential requirements of Annex I, conformity assessment, CE marking, technical documentation, the EU declaration of conformity and the obligations of importers and distributors. Products placed on the market before that date are covered only if substantially modified afterwards (Article 69).

    Action required

    Plan the placing-on-market date of every product release against this date; anything shipped after it needs the full technical file and declaration.

    RedComplyarticle-71article-69ce-markingtimeline
    Official source
    DeadlineHigh impact

    Article 14 reporting obligations apply — ENISA Single Reporting Platform live

    From 11 September 2026 manufacturers must notify actively exploited vulnerabilities and severe incidents through the ENISA Single Reporting Platform: early warning within 24 hours, vulnerability or incident notification within 72 hours, final report within 14 days (vulnerabilities) or one month (incidents). Notifications go to the CSIRT designated as coordinator and to ENISA via the platform (Article 14 and Article 16).

    Action required

    Register your reporting representatives on the platform, decide who signs off notifications, and rehearse the 24 h / 72 h / 14 d sequence with a tabletop exercise.

    RedComplyarticle-14article-16reportingsrpenisa
    Official source
    GuidanceHigh impact

    The CRA Single Reporting Platform is launched

    The EU Agency for Cybersecurity (ENISA) has deployed the initial operating capability of the Single Reporting… Single Reporting Platform (SRP) National/Authorities Private Sector

    ENISA · automaticarticle-14
    Official source
    AmendmentMedium impact

    Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on public contracts and concessions, repealing Directives 2014/23/EU, 2014/24/EU and 2014/25/EU, and amending Regulations (EC) No 1370/2007, (EU) 2023/1542, (EU) 2024/1157, (EU) 2024/1252, (EU) 2024/1735, (EU) 2024/1781, (EU) 2024/2847, (EU) 2024/3110 and (EU) 2025/40, and Directives 2008/98/EC, (EU) 2019/882, (EU) 2022/2381, (EU) 2023/1791 and (EU) 2024/1760 (Public Procurement Act)

    Commission proposal (not yet adopted): Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on public contracts and concessions, repealing Directives 2014/23/EU, 2014/24/EU and 2014/25/EU, and amending Regulations (EC) No 1370/2007, (EU) 2023/1542, (EU) 2024/1157, (EU) 2024/1252, (EU) 2024/1735, (EU) 2024/1781, (EU) 2024/2847, (EU) 2024/3110 and (EU) 2025/40, and Directives 2008/98/EC, (EU) 2019/882, (EU) 2022/2381, (EU) 2023/1791 and (EU) 2024/1760 (Public Procurement Act)

    EUR-Lex · Cellar · automaticcraproposal
    Official source
    StandardHigh impact

    ETSI launches approval process for 17 European Standards supporting the Cyber Resilience Act

    ETSI published 17 vertical final-draft European Standards developed under the CRA standardisation request, one per product category (for example routers, password managers, smart home hubs, connected toys, wearables). They translate Annex I essential requirements into testable criteria for each category. Until they are cited in the Official Journal they give no presumption of conformity under Article 27.

    Action required

    Read the draft that matches your product category and map its clauses to your Annex I applicability matrix; treat it as a preview, not as a harmonised standard.

    RedComplyetsiharmonised-standardsannex-iarticle-27public-enquiry
    Official source
    GuidanceMedium impact

    ENISA scales up its role in the CVE Program

    NATO Communications and Information Agency (NCIA), along with AI and cybersecurity innovator AISLE, join the Common Vulnerabilities and Exposures (CVE) Numbering Authorities (CNAs), under the ENISA Root. Vulnerability Services National / EU authorities Private Sector

    ENISA · automaticvulnerability-management
    Official source
    AmendmentMedium impact

    Berichtigung der Verordnung (EU) 2024/2847 des Europäischen Parlaments und des Rates vom 23. Oktober 2024 über horizontale Cybersicherheitsanforderungen für Produkte mit digitalen Elementen und zur Änderung der Verordnungen (EU) Nr. 168/2013 und (EU) 2019/1020 und der Richtlinie (EU) 2020/1828 (Cyberresilienz-Verordnung) (ABl. L, 2024/2847, 20.11.2024) (not available in English; language DEU)

    EUR-Lex · Cellar · automaticcorrigendumcraofficial-journal
    Official source
    GuidanceMedium impact

    ENISA Secure by Design and Default Playbook

    A Practical Guide to Secure by Design and Default Principles for SMEs Modern products with digital elements are increasingly expected to be secure by design and secure by default. However, many organisations, in particular small and medium… Product Security National / EU authorities Private Sector

    ENISA · automatic
    Official source
    GuidanceMedium impact

    Commission publishes new guidance to support timely Cyber Resilience Act implementation

    In a clear demonstration of its commitment to simplification and timely implementation, the Commission today published practical guidance to help manufacturers, developers, and businesses of all sizes meet their obligations under the Cyber Resilience Act.

    European Commission · automaticcraguidance
    Official source
    GuidanceMedium impact

    SME Cyber Resilience Maturity Assessment Model

    The SME Cyber Resilience Maturity Assessment Model provides a structured approach for micro, small and medium-sized enterprises (SMEs) to evaluate and strengthen their overall cyber resilience, while taking into account the requirements of the… Product Security National / EU authorities Private Sector

    ENISA · automaticcrasme
    Official source
    GuidanceMedium impact

    Where do SMEs stand in preparing for the Cyber Resilience Act?

    The EU Agency for Cybersecurity (ENISA) publishes the Micro, Small and Medium-sized enterprises (SME) Cyber Resilience Maturity Assessment Model, a simple and practical guidance for SMEs to support them assess their current status, identify… Product Security Product Security and Certification National / EU authorities Private Sector

    ENISA · automaticcrasme
    Official source
    GuidanceMedium impact

    SME CRA Survey Report

    ENISA is is working on practical guidance, tools and support activities tailored to the realities and needs of smaller organisations, to help small and medium-sized enterprises (SMEs) understand and implement the Cyber Resilience Act (CRA). This… Product Security National / EU authorities Private Sector

    ENISA · automaticsme
    Official source
    DeadlineMedium impact

    Chapter IV applies — Member States may notify conformity assessment bodies

    Articles 35 to 51 on the notification of conformity assessment bodies apply from 11 June 2026 (Article 71(2)). Notified bodies for the CRA can now be designated, which is the precondition for module B, module H and EU-type examination routes for important and critical products.

    Action required

    If your product is important class I/II or critical, shortlist notified bodies as they appear in NANDO and ask for lead times.

    RedComplyarticle-71notified-bodiesconformity-assessment
    Official source
    GuidanceMedium impact

    SBOM Adoption State of Play - 2026

    ENISA launched a survey at the end of 2025 to gather factual data on how organisations across industries and of varying sizes are approaching Software Bill of Materials (SBOM) adoption in response to the EU Cyber Resilience Act (CRA). This report… Product Security National / EU authorities Private Sector

    ENISA · automaticsbom
    Official source
    GuidanceMedium impact

    Technical Competence Requirements for CRA Notified Bodies

    The document focuses on high-level competences which will be required to perform conformity assessment activities, in particular the experience and training requirements for the personnel employed by a CAB wishing to be notified (CRA NB) –… Product Security Product Security and Certification National / EU authorities

    ENISA · automaticconformity-assessment
    Official source
    GuidanceMedium impact

    New CVE Numbering Authorities Under ENISA Root

    Today, four organisations have newly joined the Common Vulnerabilities and Exposures (CVE™) Program as CVE Numbering Authorities (CNAs) under ENISA Root. These organisations were all trained and onboarded by ENISA. Vulnerability Services National / EU authorities Private Sector

    ENISA · automaticvulnerability-management
    Official source
    AmendmentMedium impact

    Rectificatif au règlement (UE) 2024/2847 du Parlement européen et du Conseil du 23 octobre 2024 concernant des exigences de cybersécurité horizontales pour les produits comportant des éléments numériques et modifiant les règlements (UE) n° 168/2013 et (UE) 2019/1020 et la directive (UE) 2020/1828 (règlement sur la cyberrésilience) (JO L, 2024/2847, 20.11.2024) (not available in English; language FRA)

    EUR-Lex · Cellar · automaticcorrigendumcraofficial-journal
    Official source
    AmendmentMedium impact

    Korigendum k nariadeniu Európskeho parlamentu a Rady (EÚ) 2024/2847 z 23. októbra 2024 o horizontálnych požiadavkách kybernetickej bezpečnosti pre produkty s digitálnymi prvkami a o zmene nariadení (EÚ) č. 168/2013 a (EÚ) 2019/1020 a smernice (EÚ) 2020/1828 (akt o kybernetickej odolnosti) (Ú. v. EÚ L, 2024/2847, 20.11.2024) (not available in English; language SLK)

    EUR-Lex · Cellar · automaticcorrigendumcraofficial-journalsme
    Official source
    GuidanceMedium impact

    Call for Feedback: Advancing Software Supply Chain Security together!

    ENISA invites industry stakeholders and interested parties to provide their feedback on the draft SBOM Landscape Analysis and the Technical Advisory for Secure Use of Package Managers. Product Security Product Security and Certification National / EU authorities Private Sector

    ENISA · automatic
    Official source
    AmendmentMedium impact

    Commission Delegated Regulation (EU) 2026/881 — cybersecurity grounds for delaying dissemination of notifications

    Supplements the CRA by specifying the terms and conditions under which a CSIRT may delay disseminating a vulnerability notification received under Article 14 on cybersecurity-related grounds (Article 16(2)). Relevant to how and when your reported vulnerabilities reach other CSIRTs and ENISA.

    RedComplyarticle-14article-16delegated-actreportingofficial-journal
    Official source
    AmendmentHigh impact

    Commission Implementing Regulation (EU) 2025/2392 — technical description of important and critical product categories

    Adopted under Article 7(4), this implementing regulation gives the precise technical description of each product category listed in Annex III (important, class I and II) and Annex IV (critical). It is the text that decides borderline classification cases and therefore which conformity assessment route (module A self-assessment or a notified-body route) is available.

    Action required

    Re-check your product classification against the technical descriptions; a move into class II or critical removes the self-assessment route.

    RedComplyarticle-7annex-iiiannex-ivclassificationimplementing-actofficial-journal
    Official source
    GuidanceMedium impact

    Stepping up our role in Vulnerability Management: ENISA Becomes CVE Root

    The European Union Agency for Cybersecurity (ENISA) is now a Common Vulnerabilities and Exposures (CVE) Program-Root, thus becoming a central point of contact within the CVE program for national/EU authorities, EU CSIRTs network members, and… Vulnerability Services National / EU authorities Private Sector

    ENISA · automaticvulnerability-management
    Official source
    AmendmentMedium impact

    Corrigendum to Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) (OJ L, 2024/2847, 20.11.2024)

    EUR-Lex · Cellar · automaticcorrigendumcraofficial-journal
    Official source
    AmendmentMedium impact

    Rectificatif au règlement (UE) 2024/2847 du Parlement européen et du Conseil du 23 octobre 2024 concernant des exigences de cybersécurité horizontales pour les produits comportant des éléments numériques et modifiant les règlements (UE) n° 168/2013 et (UE) 2019/1020 et la directive (UE) 2020/1828 (règlement sur la cyberrésilience) (JO L, 2024/2847, 20.11.2024) (not available in English; language FRA)

    EUR-Lex · Cellar · automaticcorrigendumcraofficial-journal
    Official source
    AmendmentLow impact

    Commission Delegated Regulation (EU) 2025/1535 — exclusion of certain L-category vehicle products

    Supplements the CRA with an exclusion for products with digital elements that fall within the scope of Regulation (EU) No 168/2013 on two- or three-wheel vehicles and quadricycles, where equivalent cybersecurity requirements apply under that framework (Article 2(5) mechanism).

    RedComplyarticle-2scopedelegated-actofficial-journal
    Official source
    AmendmentMedium impact

    Corrigendum to Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) (OJ L, 2024/2847, 20.11.2024)

    EUR-Lex · Cellar · automaticcorrigendumcraofficial-journal
    Official source
    GuidanceMedium impact

    Consult the European Vulnerability Database to enhance your digital security!

    The European Union Agency for Cybersecurity (ENISA) has developed the European Vulnerability Database - EUVD as provided for by the NIS2 Directive. The EUVD service , to be maintained by ENISA, is now… Vulnerability Services National / EU authorities Private Sector

    ENISA · automaticvulnerability-management
    Official source
    AmendmentMedium impact

    Regulation (EU) 2025/327 of the European Parliament and of the Council of 11 February 2025 on the European Health Data Space and amending Directive 2011/24/EU and Regulation (EU) 2024/2847 (Text with EEA relevance)

    EUR-Lex · Cellar · automaticamendmentcraofficial-journal
    Official source
    DeadlineHigh impact

    Regulation (EU) 2024/2847 enters into force

    The Cyber Resilience Act was published in the Official Journal on 20 November 2024 and entered into force on 10 December 2024. The staggered application dates are 11 June 2026 (Chapter IV, notified bodies), 11 September 2026 (Article 14 reporting) and 11 December 2027 (everything else).

    RedComplycraentry-into-forcetimelineofficial-journal
    Official source
    AmendmentMedium impact

    Corrigendum to Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) (OJ L, 2024/2847, 23.10.2024)

    EUR-Lex · Cellar · automaticcorrigendumcraofficial-journal
    Official source

    How this feed is filled

    Once a day RedComply checks EUR-Lex (the Official Journal and every act that is based on, completes, amends or corrects Regulation (EU) 2024/2847), ENISA news and publications, the European Commission's Cyber Resilience Act pages and ETSI press releases. Items marked "automatic" keep the official title and link to the official source. Entries marked "RedComply" are written by us and add a plain-language summary and, where relevant, what a manufacturer should do. This page is general information, not legal advice.

    See every Cyber Resilience Act date on one timeline, or check how ready you are.