The Cyber Resilience Act has been in force since December 2024. The first hard deadline is September 2026: manufacturers that still have no working vulnerability-reporting process will have a concrete problem. Industry figures still show that only about a third of German industrial companies are familiar with the requirements.
This article gives you the full CRA timeline, what applies from September 2026, what waits until 2027, a checklist you can start now, and the mistakes we see in practice.
Why the CRA is a topic for today, not for 2027
The CRA covers almost anyone who places products with digital elements on the EU market — hardware and software. Connected machine controls, IoT devices, firmware, and networked software products are in scope. The scope is wider than most product and development teams assume.
From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents. The full set of essential cybersecurity requirements, conformity assessment, and CE marking follows on 11 December 2027. Waiting for 2027 means building the reporting process under time pressure.
The CRA timeline
- 11 December 2024: the regulation entered into force.
- 11 September 2026: reporting duties for exploited vulnerabilities and severe incidents, with fines.
- 11 December 2027: essential requirements, technical documentation, SBOM, conformity assessment, and CE marking apply in full.
- Support period: security updates for the expected product lifetime, at least five years where no shorter period is justified.
Checklist: ready by September 2026
- Inventory every product with digital elements that you place on the EU market.
- Name an owner for vulnerability intake and customer notification.
- Produce an SBOM (CycloneDX) per product and keep it current.
- Define severity, the 24-hour early warning, and the follow-up report.
- Document secure-development practices you already have, so 2027 does not start from zero.
The mistakes we see
Teams treat the CRA as a 2027 documentation project, keep the product list in a spreadsheet nobody owns, and discover too late that firmware and pure software are in scope. Reporting without a named on-call path fails the first real incident.
Conclusion
September 2026 is the first enforceable date. A product inventory, an SBOM, and a reporting process started now leave time to do the work properly.
Map your CRA product inventory, SBOMs, and reporting in deveca GRC
