CRA Implementation Timeline

Key dates and milestones for Cyber Resilience Act compliance from 2024 to 2027

Current Status: CRA is now in force (December 2024). You have approximately 3 years to achieve full compliance before the December 2027 deadline.

Time Until Full CRA Compliance

---
Days
--
Hours
--
Minutes

Until December 11, 2027 - Full CRA Compliance Deadline

Complete CRA Implementation Timeline

Follow the key dates and milestones from adoption to full compliance

legislative ✓ Completed

CRA Adopted by Council

European Council formally adopts the Cyber Resilience Act

legislative ✓ Completed

CRA Published

Official publication in EU Official Journal

legislative ✓ Completed

CRA Enters into Force

Regulation becomes legally binding - preparation period begins

high priority
standards ✓ Completed

Standardization Request Issued

European Commission requests development of 41 harmonized standards

assessment

Conformity Assessment Bodies Authorized

Third-party assessment bodies authorized to certify product compliance

medium priority
standards

Vulnerability Handling Standard Deadline

Harmonized standards for vulnerability handling must be adopted

compliance

Mandatory Vulnerability Reporting

Manufacturers must report actively exploited vulnerabilities and severe incidents

high priority
standards

Vertical Standards Deadline

All product-specific vertical standards must be adopted

standards

Harmonized Standards Complete

Final deadline for all CRA harmonized standards adoption

compliance

Full CRA Compliance Required

All CRA obligations become mandatory - products must comply to enter EU market

critical priority

Your CRA Preparation Roadmap

What you should focus on during each phase leading up to full compliance

1
Now - 2025

Preparation Phase

Start building CRA readiness

  • Conduct initial product assessment
  • Begin security by design implementation
  • Establish vulnerability management processes
  • Monitor harmonized standards development
2
2025 - 2026

Implementation Phase

Implement core requirements

  • Complete technical documentation
  • Implement essential cybersecurity requirements
  • Set up conformity assessment processes
  • Prepare vulnerability reporting systems
3
2026 - 2027

Compliance Phase

Achieve full compliance

  • Undergo conformity assessment
  • Complete CE marking documentation
  • Launch vulnerability reporting
  • Final compliance verification

Don't Miss These Critical Deadlines

Mark your calendar for these make-or-break dates

September 11, 2026

Vulnerability Reporting Starts

You must report actively exploited vulnerabilities and severe security incidents without delay. Set up your reporting systems before this date.

December 11, 2027

Full Compliance Deadline

All CRA requirements become mandatory. Products that don't comply cannot enter the EU market. No extensions will be granted.

Don't Wait Until 2027

Starting early gives you time to address unexpected challenges, test your compliance measures, and avoid the last-minute rush when conformity assessment bodies may be overwhelmed.

Harmonized Standards Development

Track the development of technical standards that will define specific compliance requirements

41 Standards Being Developed

15 Horizontal Standards

Each aligned with one Essential Cybersecurity Requirement from Annex I, applicable across all product categories

26 Vertical Standards

Tailored to specific product categories like IoT devices, industrial systems, consumer electronics

Security by Design

Standards for implementing security from product conception

Expected: Early 2026

Vulnerability Handling

Process standards for managing security vulnerabilities

Deadline: August 30, 2026

Risk Assessment

Methodologies for cybersecurity risk evaluation

Expected: Mid 2026

What Should You Do Now?

Based on where we are in the timeline, here are your immediate priorities

🎯

1. Assess Your Products

Identify which products need CRA compliance

Start Assessment
📋

2. Review Requirements

Understand Annex I essential requirements

View Requirements
🛡️

3. Start Security Design

Begin implementing security by design

Compliance Guide
👥

4. Get Expert Help

Work with CRA compliance specialists

Contact Us

Official Source

Regulation (EU) 2024/2847 - Cyber Resilience Act

Implementation timeline and transitional provisions for cybersecurity requirements of products with digital elements.

View on EUR-Lex

🤝 Still Feeling Overwhelmed by CRA?

The Cyber Resilience Act has a lot of moving parts. Our free tools work great for most people, but if you're dealing with something really complex or have a tight deadline, we can help you figure it out faster.