In short: The CRA entered into force on 10 December 2024. Reporting of actively exploited vulnerabilities and severe incidents (Article 14) has applied since 11 September 2026, also to products already on the market. Everything else, including the essential requirements, the SBOM, technical documentation and CE marking, applies from 11 December 2027.
The dates
| Date | What happens | Source |
|---|---|---|
| Regulation (EU) 2024/2847 published in the Official Journal. | OJ L 2024/2847 | |
| Entry into force, twenty days after publication. | Art. 71(1) | |
| Chapter IV applies: notification of conformity assessment bodies. Relevant to you only if your product needs third-party assessment. | Art. 71(2) | |
| The Commission publishes non-binding guidance, C(2026) 5252, on scope, open source, support periods, reporting and more, with practical examples. | European Commission | |
| Reporting applies. Actively exploited vulnerabilities and severe incidents must be reported (Article 14), also for products already on the market. ENISA's Single Reporting Platform goes live. | Art. 71(2), 69(3); ENISA | |
| Everything else applies: the essential requirements of Annex I (secure by design, vulnerability handling, the SBOM), technical documentation, conformity assessment, the EU declaration of conformity and CE marking. Open-source stewards' reporting obligations start. | Art. 71(2); Commission, ENISA |
Products you already sell
Two rules decide this. Products placed on the market before 11 December 2027 are subject to the regulation's requirements “only if, from that date, those products are subject to a substantial modification” (Article 69(2)). But Article 14 is the exception: the reporting obligations “shall apply to all products with digital elements that fall within the scope of this Regulation that have been placed on the market before 11 December 2027” (Article 69(3)).
So: reporting applies to everything you sell today. The design, documentation and CE-marking requirements apply to what you place on the market from December 2027, and to older products you substantially modify after that.
Now, before December 2027
- Reporting is live. Know who decides that a vulnerability is actively exploited and who files on ENISA's platform; register before you need to. See the reporting guide.
- Know what you ship. You can't assess an exploited dependency without knowing which versions contain it.
- Plan the support period. It must be at least five years, unless the product is expected to be in use for less (Article 13(8)).
From 11 December 2027
- Meet the essential requirements in Annex I Part I (product properties) and Part II (vulnerability handling, including an SBOM).
- Draw up technical documentation (Annex VII) and keep it, with the EU declaration of conformity, for at least 10 years after placing the product on the market or for the support period, whichever is longer (Article 13(13)).
- Carry out the conformity assessment for your product's category, sign the declaration of conformity and affix the CE marking.
The Commission's guidance C(2026) 5252 is non-binding but worked through with examples; it is the best place to check scope questions such as remote data processing or whether a change is a substantial modification.
Sources
- Regulation (EU) 2024/2847 (Cyber Resilience Act), OJ L, 20 November 2024EUR-Lex
- Cyber Resilience ActEuropean Commission, updated 7 September 2026
- Cyber Resilience Act: reporting obligationsEuropean Commission, updated 11 September 2026
- Commission publishes new guidance to support timely Cyber Resilience Act implementation, C(2026) 5252European Commission, 27 July 2026
- Single Reporting Platform: frequently asked questionsENISA, updated 3 October 2026
This guide explains the regulation in plain English for small software makers. It is not legal advice; check your own situation with counsel. Whenproof is a tool, not a law firm, and does not make a product compliant.