Skip to content
deveca GRC
Compliance & standards7 min read

Cyber Resilience Act (CRA): the 2026/2027 deadlines — what manufacturers actually need to do now

The Cyber Resilience Act sounds like 2027. It is not: the first fine-backed reporting duty starts in September 2026. Here is the timeline and a practical checklist.

Author:
  • CRA
  • Cyber Resilience Act
  • Reporting duties
  • SBOM

The Cyber Resilience Act has been in force since December 2024. The first hard deadline is September 2026: manufacturers that still have no working vulnerability-reporting process will have a concrete problem. Industry figures still show that only about a third of German industrial companies are familiar with the requirements.

This article gives you the full CRA timeline, what applies from September 2026, what waits until 2027, a checklist you can start now, and the mistakes we see in practice.

Why the CRA is a topic for today, not for 2027

The CRA covers almost anyone who places products with digital elements on the EU market — hardware and software. Connected machine controls, IoT devices, firmware, and networked software products are in scope. The scope is wider than most product and development teams assume.

From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents. The full set of essential cybersecurity requirements, conformity assessment, and CE marking follows on 11 December 2027. Waiting for 2027 means building the reporting process under time pressure.

The CRA timeline

  • 11 December 2024: the regulation entered into force.
  • 11 September 2026: reporting duties for exploited vulnerabilities and severe incidents, with fines.
  • 11 December 2027: essential requirements, technical documentation, SBOM, conformity assessment, and CE marking apply in full.
  • Support period: security updates for the expected product lifetime, at least five years where no shorter period is justified.

Checklist: ready by September 2026

  • Inventory every product with digital elements that you place on the EU market.
  • Name an owner for vulnerability intake and customer notification.
  • Produce an SBOM (CycloneDX) per product and keep it current.
  • Define severity, the 24-hour early warning, and the follow-up report.
  • Document secure-development practices you already have, so 2027 does not start from zero.

The mistakes we see

Teams treat the CRA as a 2027 documentation project, keep the product list in a spreadsheet nobody owns, and discover too late that firmware and pure software are in scope. Reporting without a named on-call path fails the first real incident.

Conclusion

September 2026 is the first enforceable date. A product inventory, an SBOM, and a reporting process started now leave time to do the work properly.

Map your CRA product inventory, SBOMs, and reporting in deveca GRC

GRC in practice

See how deveca supports your ISMS and compliance programme.