Independent guide to Regulation (EU) 2024/2847 · Status: in force
News · Current state of play

Where the CRA stands today

A running view of the Cyber Resilience Act's implementation; what has happened, what is in progress, and the dates still ahead.

In force; implementation phaseObligations are phasing in; full application is December 2027.
Last updated
September 2026
Implementation timeline

Milestones

11 Sep 2026

Reporting obligations apply

Manufacturers must notify actively exploited vulnerabilities and severe incidents to ENISA and the national CSIRT. ENISA's single reporting platform (Article 16) is to be operational by this date.

Imminent
13 Aug 2026

ETSI vertical drafts under Public Enquiry

ETSI opened the formal approval procedure on 17 vertical final draft standards (the EN 304 xxx series, covering Annex III products from routers to connected toys). Comment windows close between mid-September and mid-November 2026, depending on the vertical. The drafts are publicly readable.

In progress
11 Jun 2026

Chapter IV applies

The provisions on notification of conformity-assessment bodies take effect, so notified bodies can be designated ahead of full application.

Complete
2025 – 2026

Guidance & standards development

The Commission approved the content of its Article 26 application guidance in July 2026 (formal adoption follows once all EU-language versions are ready), alongside a living FAQ, while the European standards bodies draft the harmonised standards.

In progress
Apr 2025

Standardisation request accepted

CEN, CENELEC and ETSI accepted the Commission's request M/606 to develop around 41 harmonised standards (15 horizontal and the remainder vertical, product-specific).

Complete
10 Dec 2024

Entered into force

The CRA became law across the EU; the implementation clock started.

Complete
10 Oct 2024

Adopted and signed into law

The Regulation was formally adopted by the European Parliament and Council.

Complete