ISO & Compliance Implementation

The EU Cyber Resilience Act: A Compliance Timeline for Software and Connected-Device Vendors

If you sell software or connected hardware into the EU market, the Cyber Resilience Act applies to you whether or not you’re based there — and its first binding deadline is closer than most vendors’ current compliance roadmaps assume.

01

Who this actually applies to

The Cyber Resilience Act (CRA) covers “products with digital elements” placed on the EU…

02

The two dates that matter

September 11, 2026 — reporting obligations begin. Manufacturers must report actively…

03

What the reporting obligation actually requires

Article 14’s reporting timeline is tight and specific.

Who this actually applies to

The Cyber Resilience Act (CRA) covers “products with digital elements” placed on the EU market — a deliberately broad scope spanning standalone software, connected hardware, and remote data processing solutions tied to a product. It names specific categories for extra scrutiny: identity management systems, browsers, password managers, VPN products, routers, and operating systems sit in the “important” product category, with tighter conformity assessment requirements than general software.

WITHIN 24 Hours Early warning WITHIN 72 Hours Fuller notification FINAL REPORT 14 Days / 1 Month Vulnerability vs. severe incident
The clock starts the moment you become aware, not when you’ve finished investigating — which is why this requires a detection and escalation process, not just a reporting template.

The two dates that matter

  • September 11, 2026 — reporting obligations begin. Manufacturers must report actively exploited vulnerabilities and severe incidents through ENISA’s Single Reporting Platform, expected operational by this date.
  • December 11, 2027 — the full product security regime applies, including CE-marking obligations and the broader essential cybersecurity requirements for products placed on the market.

What the reporting obligation actually requires

Article 14’s reporting timeline is tight and specific. For an actively exploited vulnerability: an early warning within 24 hours of becoming aware of it, a fuller vulnerability notification within 72 hours, and a final report within 14 days of a corrective or mitigating measure becoming available. For a severe incident affecting the availability, integrity, authenticity, or confidentiality of a product’s data or functions: the same 24-hour and 72-hour cadence, with a final report within one month of the incident notification.

Penalties are not symbolic. Fines run up to €15 million or 2.5% of worldwide annual turnover for failures on essential cybersecurity requirements and core manufacturer obligations, and up to €10 million or 2% for other obligations like CE marking and documentation — whichever figure is higher, which for a large organization is the turnover percentage.

Building the reporting capability before September 2026

A 24-hour early-warning requirement assumes an organization already has the internal process to detect, triage, and escalate a vulnerability or incident fast enough to hit that window — which is a security operations and incident response capability, not a compliance documentation exercise. Vendors whose current incident response process measures response time in days, not hours, have real operational work to do before this deadline, not just a policy to write.

Frequently asked questions

Does the Cyber Resilience Act apply to us if we’re not based in the EU?

Yes, if you place products with digital elements on the EU market — the CRA applies based on where products are sold and used, not where the manufacturer is headquartered, similar in reach to how GDPR applies extraterritorially.

What’s the difference between the September 2026 and December 2027 deadlines?

September 2026 starts the vulnerability and incident reporting obligations specifically. December 2027 brings the full regime into force, including CE marking, conformity assessment, and the broader essential cybersecurity requirements that apply to the product itself, not just incident reporting.

Does open-source software fall under the Cyber Resilience Act?

The CRA includes specific provisions distinguishing commercial products from non-commercial open-source software development, with lighter obligations for genuinely open, non-commercial projects — but software that’s open-source and also commercially distributed or supported as part of a product generally falls under the standard requirements. This distinction has enough nuance that it’s worth confirming your specific situation against the current guidance rather than assuming either way.