Last updated: 2026-08-11 · Jurisdiction: European Union · Instrument: Regulation (EU) 2024/2847 (Cyber Resilience Act), application staged under Article 71
Cyber Resilience Act: what applies from 11 September 2026, and the full obligation timeline
The EU Cyber Resilience Act does not switch on all at once. Article 71 stages it: the reporting duty in Article 14 is legally binding from 11 September 2026, the notified-body machinery from 11 June 2026, and the essential requirements and CE marking only from 11 December 2027. This page is a vendor-neutral map of that clock, of what Article 14 actually requires, of who is in scope, and of how the Article 64 fine bands are structured. The analysis does not depend on using ISMS Copilot, and it is not legal advice.
The short version
Treat 11 September 2026 as the first operational CRA date for a manufacturer already in scope: from then, an actively exploited vulnerability or a severe incident in your product with digital elements must be reported, on a 24-hour then 72-hour then final-report clock, simultaneously to the coordinating CSIRT and to ENISA via the single reporting platform. The Annex I essential requirements, conformity assessment, the CE mark and the Article 64 penalty framework apply later, from 11 December 2027. The order in the calendar is the opposite of the order most roadmaps assume.
Why a dedicated obligations page (and not only the existing post)
Our practitioner post “The CRA is a 2026 problem, not a 2027 one” argues the sequencing point: why the reporting duty, not the CE mark, should drive the plan. That is an argument. This page is the reference underneath it: the full Article 71 clock, the Article 14 reporting mechanics as a table, who is in scope, and the Article 64 fine bands with their own application date. The two are meant to be read together: this guide links the blog for the sequencing argument, and the blog links back here for the dated reference.
If you need to know whether the CRA applies to a specific product, and whether that product is default, important or critical, use the free CRA applicability checker. This guide is the calendar and the duties; the checker is the scope decision for one product.
Application timeline: the staggered Article 71 clock
Article 71 does not give the CRA one deadline. It gives it four dates, and the earliest operational obligation lands roughly fifteen months before the essential requirements it depends on. The table below is the structure most “CRA deadline” headlines flatten to a single 2027 date.
| Date | What applies | Anchor |
|---|---|---|
| 10 December 2024 | The Regulation enters into force, on the twentieth day after its publication in the Official Journal. The staggered application clock in Article 71 starts here; almost none of its obligations apply yet. | Article 71(1) |
| 11 June 2026 | Chapter IV (Articles 35 to 51) applies: the rules on notifying authorities and notified bodies and on how conformity assessment bodies are designated. This lets Member States stand up the notified-body machinery before the essential requirements bite, so assessment capacity exists ahead of 2027. | Article 71(2); Chapter IV (Articles 35 to 51) |
| 11 September 2026 | Article 14 applies: the reporting duty for actively exploited vulnerabilities and severe incidents. This is the first operational obligation a manufacturer already in scope actually has to run, and it is roughly fifteen months before the essential requirements it operationally depends on. | Article 71(2); Article 14 |
| 11 December 2027 | The rest of the Regulation applies: the Annex I essential cybersecurity requirements, the vulnerability-handling requirements, conformity assessment, the CE marking, and the obligations of manufacturers, importers and distributors. The Article 64 penalty framework also applies from this date with the rest of the Regulation. | Article 71(2), first sentence |
Version and jurisdiction stamp: Regulation (EU) 2024/2847 (Cyber Resilience Act), signed at Strasbourg 23 October 2024, in force 10 December 2024, application staged under Article 71. Checked 2026-08-11.
What switches on 11 September 2026: the Article 14 reporting duty
Article 14 is the first thing a manufacturer already in scope has to operate. From 11 September 2026, a manufacturer must notify any actively exploited vulnerability in its product with digital elements, and any severe incident affecting the security of that product, simultaneously to the CSIRT designated as coordinator for the relevant Member State and to ENISA, through the single reporting platform established under Article 16.
An actively exploited vulnerability, for this purpose, is one for which there is reliable evidence that a malicious actor has exploited it in a system without the permission of the system owner (Article 3). Exploitation, not code execution specifically, is the trigger. That is a live, dated event that starts a 24-hour clock the moment you become aware of it. The two tracks and their three stages are set out below.
Article 14 at a glance: two tracks, three stages each
Original plain-English paraphrase of the Article 14 stages. The deadlines are the same at the front (24 hours, then 72 hours) and diverge at the final report: 14 days for a vulnerability, one month for a severe incident. The Article's own conditions still control; this table is a map, not a substitute for the text.
| Reportable event | Early warning (24h) | Notification (72h) | Final report |
|---|---|---|---|
| Actively exploited vulnerability in the product | Early-warning notification without undue delay and in any event within 24 hours of becoming aware, indicating where applicable the Member States where the product has been made available. | Vulnerability notification without undue delay and in any event within 72 hours: general information about the product, the general nature of the exploit and the vulnerability, and any corrective or mitigating measures taken and that users can take. | Final report no later than 14 days after a corrective or mitigating measure is available: a description of the vulnerability with severity and impact, information on any malicious actor where available, and details of the security update or fix. |
| Severe incident affecting product security | Early-warning notification without undue delay and in any event within 24 hours of becoming aware, including at least whether the incident is suspected of being caused by unlawful or malicious acts, and where applicable the Member States where the product has been made available. | Incident notification without undue delay and in any event within 72 hours: general information about the nature of the incident, an initial assessment, and any corrective or mitigating measures taken and that users can take. | Final report within one month after the 72-hour incident notification: a detailed description with severity and impact, the type of threat or root cause likely to have triggered it, and the applied and ongoing mitigation measures. |
The recipient routing matters as much as the timing. Both tracks go simultaneously to the CSIRT designated as coordinator and to ENISA, via the Article 16 single reporting platform. It is not ENISA alone, and it is not your data protection authority: a CRA report and a GDPR Article 33 breach notification are different duties with different recipients, even when the same event triggers both.
Two qualifications keep the table honest. The 72-hour notification and the final report are each required only to the extent the relevant information has not already been provided, and the coordinating CSIRT may request an intermediate report (Article 14(6)). Article 14 also reaches beyond authority reporting: under Article 14(8) the manufacturer must, after becoming aware, inform the impacted users of the product (and where appropriate all users) of the incident or vulnerability and of any corrective or mitigating measures they can take. The table above is the reporting spine, not the whole of the Article.
Who is in scope, and in which role
The CRA applies to economic operators making products with digital elements available on the EU market in the course of a commercial activity. A product with digital elements is a software or hardware product whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network, together with its remote data-processing solutions and any components placed on the market separately (Article 3). That connection criterion is part of scope, not a formality. The Regulation also carves out products already covered by certain sectoral Union law (for example medical devices, motor vehicles and civil aviation) under Article 2, and treats free and open-source software supplied outside a commercial activity separately.
The duties fall by role. Manufacturers carry the primary obligations, including the Article 14 reporting duty. Importers (Article 19) and distributors (Article 20) have their own due-diligence obligations, and under Article 21 an importer or distributor that places a product on the market under its own name or trademark, or that substantially modifies it, shall be considered a manufacturer and takes on the Article 13 and 14 duties. Product category matters too: most products self-assess, but Annex III important products (Class I and Class II) and Annex IV critical products face stricter conformity routes, and Class II and critical products generally require a notified body.
Working out whether the CRA applies to a specific product, and which product category it sits in, is exactly what the free CRA applicability checker does: it returns whether the CRA applies and whether the product is default, important (Class I or II) or critical. Supply-chain role (manufacturer, importer, distributor) is a separate facts question this tool does not decide.
What the 2027 date actually brings
From 11 December 2027 the main body of the Regulation applies: the Annex I essential cybersecurity requirements, covering secure-by-design and secure-by-default properties and the vulnerability-handling process, together with conformity assessment, the CE marking, and the full manufacturer, importer and distributor obligations. This is the “CRA compliance” most roadmaps picture, and it is genuinely the larger programme.
The reason the earlier reporting date still leads is dependency, not date size. Reporting an actively exploited vulnerability inside 24 hours assumes you can already detect it, know which shipped versions are affected, and triage severity before the 72-hour window closes. Those capabilities are described in Annex I, Part II (a machine-readable software bill of materials, a coordinated vulnerability disclosure policy, and a remediation process) and are legally due in 2027, but the 2026 reporting duty is hard to satisfy reliably without a subset of them. The sequencing argument in our blog post is exactly this point: build the report-readiness minimum against the September 2026 date, as a down payment on the 2027 requirements rather than throwaway work.
Penalties: three bands, and a date most summaries miss
Article 64 sets three administrative-fine bands, scaled to the seriousness of the failure. There is no single “CRA fine.”
| Band | Ceiling (undertakings) | Applies to |
|---|---|---|
| Article 64(2) | Up to EUR 15 000 000, or for an undertaking up to 2.5% of total worldwide annual turnover of the preceding financial year, whichever is higher | Non-compliance with the Annex I essential cybersecurity requirements and with the obligations in Article 13 (manufacturers) and Article 14 (reporting) |
| Article 64(3) | Up to EUR 10 000 000, or for an undertaking up to 2% of total worldwide annual turnover of the preceding financial year, whichever is higher | Non-compliance with the other listed obligations (including Articles 18 to 23 on importers and distributors, Article 28, and the notified-body-related duties in Articles 39, 41, 47, 49 and 53) |
| Article 64(4) | Up to EUR 5 000 000, or for an undertaking up to 1% of total worldwide annual turnover of the preceding financial year, whichever is higher | Supplying incorrect, incomplete or misleading information to notified bodies and market surveillance authorities in reply to a request |
The date is the subtle part. On a literal reading of Article 71(2), Article 14 applies from 11 September 2026, but the rest of the Regulation, including the Article 64 administrative-fine framework, applies from 11 December 2027. So the reporting duty binds in the 2026 to 2027 window while the CRA's own fine ceilings sit with the later date. That is about when the CRA's administrative fines become available under the Regulation itself; it is not a claim that national market-surveillance powers or other enforcement routes are idle in the gap. Read the bands above as the penalty structure of the Act, and confirm how your Member State handles the intervening period rather than assuming an Article 64 fine attaches to a missed 2026 report before December 2027. Either way, the reporting capability is worth building for the September 2026 date, because the obligation itself is live then.
Two carve-outs are worth knowing. The table's summary of Article 64(3) is non-exhaustive (the Regulation names several further provisions), so the “applies to” column above is illustrative, not a complete catalogue of every listed obligation. And under Article 64(10), manufacturers that qualify as microenterprises or small enterprises are not subject to these administrative fines for failing to meet Article 14's 24-hour early-warning deadlines. The duty to report still applies to them; the specific fine for a late early warning does not.
Check one product, then come back to the calendar
The free CRA applicability checker walks the Article 2 and 3 scope and exclusions and the Annex III / Annex IV categories, and returns whether the CRA applies to your product and whether it is default, important (Class I or II) or critical. It runs in your browser and stores nothing. Use this guide for the dated obligation picture; use the checker for one product's scope.
Seven mistakes that produce the wrong CRA plan
Anchoring the whole programme to 11 December 2027
December 2027 is the date the essential requirements, conformity assessment and CE mark apply. It is the last date in Article 71, not the first. The reporting duty in Article 14 is legally binding from 11 September 2026, and the notified-body machinery in Chapter IV from 11 June 2026. A plan that sequences backwards from the CE mark puts the first live obligation last.
Reading Article 14 as a single deadline
Article 14 is two tracks (actively exploited vulnerabilities and severe incidents) and three stages each (a 24-hour early warning, a 72-hour notification, and a final report). The final-report clock differs by track: 14 days after a fix is available for a vulnerability, one month after the 72-hour notification for a severe incident. Treating it as one 24-hour rule mis-scopes the process you have to build.
Notifying the wrong recipient, or only one of them
Under Article 14 a manufacturer notifies simultaneously the CSIRT designated as coordinator for the relevant Member State and ENISA, through the single reporting platform established under Article 16. It is not ENISA alone, and it is not the national data protection authority. Getting the routing wrong is a dated, provable failure on a 24-hour clock.
Assuming the Article 64 fines are enforceable the moment reporting starts
On a literal reading of Article 71(2), Article 14 applies from 11 September 2026, but the rest of the Regulation, including the Article 64 administrative-fine framework, applies from 11 December 2027. The reporting duty is binding in the 2026 to 2027 window; the CRA's own administrative-fine ceilings sit with the main body of the Regulation. That is about CRA administrative fines under Article 64, not every national enforcement route. Read the fine bands as the penalty structure of the Act, not as a proof that a missed 2026 report is fined under Article 64 before December 2027, and check how your Member State handles the intervening period.
Confusing the CRA reporting duty with NIS 2 or GDPR reporting
The CRA Article 14 duty is about vulnerabilities and incidents in a product with digital elements you manufacture, reported to a CSIRT and ENISA. NIS 2 Article 23 incident reporting is about incidents affecting an essential or important entity's own services. GDPR Article 33 is about personal-data breaches reported to a supervisory authority. The same event can trigger more than one, but they are different duties with different recipients and clocks.
Thinking the CRA only touches manufacturers
The obligations fall on manufacturers first, but importers (Article 19) and distributors (Article 20) have their own due-diligence duties, and under Article 21 an importer or distributor that markets a product under its own name or trademark, or substantially modifies it, shall be considered a manufacturer and takes on the Article 13 and 14 duties. The applicable duty depends on your role in the chain, not just on whether you wrote the code.
Ignoring the product category (default, important, critical)
Most products self-assess, but Annex III important products (Class I and Class II) and Annex IV critical products face stricter conformity routes, and Class II and critical products generally need a notified body. Which bucket a product sits in changes the assessment path, and those categories are fixed by the CRA lists and Commission technical descriptions, not by the manufacturer's preference.
Where this page sits in the CRA cluster
| Surface | Job | Format |
|---|---|---|
| This guide | Map the staggered Article 71 clock, the Article 14 reporting duty, scope and roles, and the Article 64 fine bands | Long-form explainer |
| CRA applicability checker | Decide whether the CRA applies to one product and its category (default / important / critical) | Free tool |
| “The CRA is a 2026 problem” post | Argue why the reporting duty, not the 2027 CE mark, should sequence the work; complementary, not a substitute for this reference | Blog |
| Cyber Resilience Act framework page | Product-oriented overview of working under the CRA with ISMS Copilot | Framework hub |
Browse the full set of free compliance tools, or read the related dated explainer of what applies under the EU AI Act from 2 August 2026.
Frequently asked questions
When does the Cyber Resilience Act actually apply?
It is staggered under Article 71. The Regulation entered into force on 10 December 2024. Chapter IV (Articles 35 to 51, on notifying authorities and notified bodies) applies from 11 June 2026. Article 14 (the reporting duty for actively exploited vulnerabilities and severe incidents) applies from 11 September 2026. Everything else, including the Annex I essential requirements, conformity assessment, the CE mark, and the Article 64 penalty framework, applies from 11 December 2027.
What has to be reported under Article 14, and how fast?
Two things: any actively exploited vulnerability in your product with digital elements, and any severe incident affecting the security of that product. For each, you submit an early warning within 24 hours of becoming aware, a fuller notification within 72 hours, and a final report. The final-report deadline differs: no later than 14 days after a corrective or mitigating measure is available for a vulnerability, and within one month after the 72-hour notification for a severe incident. All of it goes simultaneously to the CSIRT designated as coordinator and to ENISA, via the single reporting platform under Article 16.
Who does the CRA apply to?
It applies to economic operators that make products with digital elements available on the EU market in the course of a commercial activity. A product with digital elements is a software or hardware product whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network, together with its remote data-processing solutions and any separately marketed components. Manufacturers carry the primary obligations; importers (Article 19) and distributors (Article 20) have their own due-diligence duties, and under Article 21 either shall be considered a manufacturer if it markets a product under its own name or trademark or substantially modifies it. Certain products under sectoral Union law (e.g. medical devices) are excluded under Article 2, and free and open-source software supplied outside a commercial activity is treated separately. Use the free CRA applicability checker to work through whether a specific product is in scope and which product category it sits in (default, important, or critical). Supply-chain role is a separate facts question.
What are the fines under the Cyber Resilience Act?
There is no single figure. Article 64(2) sets up to EUR 15 000 000 or 2.5% of worldwide annual turnover (whichever is higher) for non-compliance with the Annex I essential requirements and the Article 13 and 14 obligations. Article 64(3) sets up to EUR 10 000 000 or 2% for the other listed obligations. Article 64(4) sets up to EUR 5 000 000 or 1% for supplying incorrect, incomplete or misleading information to notified bodies and market surveillance authorities. The penalty framework applies from 11 December 2027 with the rest of the Regulation, even though the Article 14 reporting duty is binding from 11 September 2026.
Is the reporting duty enforceable before the 2027 essential requirements apply?
Article 14 is legally applicable from 11 September 2026: the duty exists and the clocks run. What is more subtle is the penalty side. On a literal reading of Article 71(2), the main body of the Regulation, including the Article 64 administrative fines, applies from 11 December 2027. So the reporting obligation binds in the 2026 to 2027 window while the CRA's own fine ceilings sit with the later date. That is about when CRA administrative fines under Article 64 become available; it does not mean national market-surveillance powers are idle in the gap. Build the reporting capability for the September 2026 date rather than gamble on the gap. Confirm the position in your Member State's implementing measures.
How is this different from the free CRA applicability checker?
This page is the dated obligation and timeline map: what applies when, what Article 14 requires, and how the fine bands are structured. The free checker at /resources/cra-applicability-checker takes a specific product and returns whether the CRA applies and whether the product is default, important (Annex III Class I or II) or critical (Annex IV). Use the guide for the calendar and the reporting mechanics; use the checker for one product's scope and category.
Is this legal advice?
No. It is educational content that paraphrases the structure of Regulation (EU) 2024/2847 in original wording. Scope, your role in the supply chain, product classification and the reporting mechanics are fact-specific and can be affected by delegated and implementing acts. Confirm against the Official Journal text, ENISA and Commission guidance, your competent authority, and counsel.
Primary sources
- Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act): Article 3 (definitions, including 'product with digital elements'), Article 14 (reporting obligations of manufacturers: 24-hour early warning, 72-hour notification, final report, CSIRT coordinator and ENISA via the Article 16 single reporting platform), Article 64 (penalties: the 2.5% / 2% / 1% and EUR 15M / 10M / 5M bands), and Article 71 (entry into force 10 December 2024; Article 14 from 11 September 2026; Chapter IV from 11 June 2026; the rest from 11 December 2027). eur-lex.europa.eu (checked 2026-08-11).
- European Commission, Cyber Resilience Act policy page (Shaping Europe's digital future): entry into force 10 December 2024, reporting obligations from 11 September 2026, main obligations from 11 December 2027, and the practical guidance published 27 July 2026. digital-strategy.ec.europa.eu (checked 2026-08-11).
- European Commission, Cyber Resilience Act FAQ: scope, the manufacturer / importer / distributor roles, the default / important (Annex III) / critical (Annex IV) product categories, and conformity assessment. digital-strategy.ec.europa.eu (checked 2026-08-11).
Written and maintained by the ISMS Copilot team. Our compliance content is produced by certified information security professionals, including a CISM-certified ISO 27001 Lead Implementer who still runs audits. Last reviewed 2026-08-11.
This page paraphrases the structure of Regulation (EU) 2024/2847 in original wording. It is educational content, not legal advice and not a binding determination of any product's scope, category or reporting obligation. Confirm against the current Official Journal text, ENISA and Commission guidance, and your competent authority or counsel.
Ready to do compliance work faster?
Built for speed, accuracy, and audit-ready output.
