CRA enforcement countdown — T-365d, T-180d, T-90d
Operational countdown to the CRA general application date of 11 December 2027. Concrete checkpoints at T-12m, T-6m, T-3m and T-0 for hardware manufacturers.
By Vladimír Vician
The general application date of the Cyber Resilience Act (Regulation (EU) 2024/2847) is fixed by Article 71 at 11 December 2027. Two earlier checkpoints already apply: the Article 14 reporting obligations apply from 11 September 2026, and the notified body provisions in Chapter IV apply from 11 June 2026 so that the conformity assessment infrastructure is ready when the rest of the Regulation takes effect.
That gives every manufacturer of products with digital elements a fixed countdown. This article translates the legal calendar into four operational checkpoints — T-365d, T-180d, T-90d and T-0 — measured backwards from 11 December 2027. The checkpoints assume you have not yet started CRA preparation; if you started earlier, treat them as deadlines rather than start dates.
The legal calendar fixed by Article 71
Article 71 of the CRA sets three different application dates:
| Provision | Application date | Why this date |
|---|---|---|
| Chapter IV (notified bodies, Articles 35–51) | 11 June 2026 | Conformity assessment infrastructure must exist before manufacturers can be assessed |
| Article 14 (reporting obligations) | 11 September 2026 | Vulnerability and incident reporting starts early so the ENISA pipeline is operational |
| Rest of the Regulation (incl. essential requirements, CE marking, DoC) | 11 December 2027 | General application — the "T-0" of this article |
Article 69(2) adds a key transitional rule for legacy stock:
Products with digital elements that have been placed on the market before 11 December 2027 shall be subject to the requirements set out in this Regulation only if, from that date, those products are subject to a substantial modification.
Together, these provisions define the countdown that follows. The interaction with existing stock is explained in detail in cra-existing-products-on-market.
T-365 days — December 2026 — scope and structure
At twelve months out, the work is legal, organisational and architectural — not yet documentation.
1. Scope every SKU against Article 2. Article 2 of the CRA covers "products with digital elements" that have a direct or indirect logical or physical data connection. Specific sectoral regimes are excluded — medical devices under Regulation (EU) 2017/745, motor vehicles under Regulation (EU) 2019/2144, civil aviation equipment under Regulation (EU) 2018/1139, and a few others. For each SKU on your roadmap or in production, decide: in scope, out of scope, or partially in scope.
2. Classify into Annex III / IV. Annex III lists Important products in Class I and Class II; Annex IV lists Critical products. The classification drives the conformity assessment route at T-3 months. Routers, firewalls, password managers, smart home hubs and similar items typically land in Annex III. The full Annex III breakdown is in cra-annex-3-important-products.
3. Identify substantial modifications. Because Article 69(2) grandfathers existing stock until "substantial modification", you need a written internal definition now of what qualifies as substantial. A new SoC, a new wireless interface, a change of OS family — yes. A minor security patch — typically no. Document the criteria so support engineering does not accidentally trigger CRA on a fielded SKU.
4. Appoint an EU authorised representative. If the manufacturer is established outside the EU, an EU authorised representative is mandatory under the CRA. See eu-authorised-representative-ec-rep-guide for the duties and ec-rep-cost-guide for typical pricing. Contracting takes 2-3 months — do it now, not at T-3m.
One email at launch · cancel any time
T-180 days — June 2027 — tooling and reporting live
By six months out, every system that produces evidence for the technical file must be running in production.
1. SBOM generation in every firmware build. A CycloneDX or SPDX SBOM is the foundation of CRA Annex I and the vulnerability handling required under Annex I Part II. By T-6 months the SBOM must be generated automatically on every build, archived per release, and queryable for CVE matching. Tooling options are compared in sbom-tooling-embedded-comparison; update cadence is covered in sbom-update-frequency-cra.
2. Article 14 reporting workflow already operational. This is not optional at T-6 months — it has been a legal obligation since 11 September 2026. Article 14 requires an early warning notification within 24 hours of becoming aware of an actively exploited vulnerability or severe incident, a notification within 72 hours, and a final report within 14 days (or one month for incidents). See cra-enisa-24-hour-reporting for the ENISA pipeline and cra-september-2026-reporting-checklist for the operational checklist.
3. Vulnerability handling process documented. Annex I Part II requires that manufacturers identify and document vulnerabilities, address them without delay, and have a coordinated vulnerability disclosure policy. Publish a security.txt, a vulnerability disclosure page, and an internal triage SLA.
4. Risk assessment under Annex I Part I. Each product family needs a documented risk assessment that maps the essential cybersecurity requirements onto its threat model. See risk-assessment-ce-compliance for the methodology shared across CE marking regimes.
T-90 days — September 2027 — conformity assessment in flight
At three months out, the conformity assessment route per Annex VIII must be in execution.
Module A — Internal control is available for products that are neither Important nor Critical, where the manufacturer can demonstrate full application of harmonised standards. For Module A products, the technical file must be drafted at this point. See technical-file-101 and the technical-file-iot-template.
Module B+C, Module H or European cybersecurity certification scheme apply to Important Class I and Class II products under Annex III. By T-90 days the notified body contract must be signed and the assessment under way — notified body capacity is finite, and waiting until T-30 days is operationally infeasible. See when-you-need-a-notified-body and conformity-assessment-modules-a-to-h for the route choice.
Critical products under Annex IV must, where the Commission has adopted a delegated act under Article 8, use a European cybersecurity certification scheme at "substantial" assurance level. Engagement with the scheme operator typically takes 6+ months — if you are in this bucket and started at T-12m, you are already behind.
For products falling under both CRA and the RED, the path through both regimes is described in red-cra-overlap-connected-radio.
T-0 — 11 December 2027 — application date
From this date:
- Every new product placed on the EU market must carry CE marking covering CRA, a Declaration of Conformity that includes the CRA reference, and a complete technical file. The CRA DoC requirements add to the existing CE marking requirements — see declaration-of-conformity-101 and sample-doc-walkthrough.
- Products placed on the market before this date are grandfathered under Article 69(2) until they undergo a substantial modification. The decision tree for legacy stock is in cra-existing-products-on-market.
- Article 14 reporting continues, now alongside the full essential requirements regime.
- EU type-examination certificates issued under other Union harmonisation legislation for cybersecurity requirements remain valid until 11 June 2028 per Article 69(1).
Common mistakes
- Treating Article 14 as a 2027 problem. Reporting obligations apply from 11 September 2026 — not 11 December 2027. Many manufacturers in 2026 still have not stood up the ENISA reporting pipeline.
- Confusing entry into force with application. The CRA entered into force in December 2024; it applies in stages. Internal communications that reference "the CRA in 2024" cause project managers to deprioritise the work.
- Assuming the importer covers EC REP duties. The importer's CRA duties are distinct from the EU authorised representative's. See ec-rep-vs-importer-responsibilities.
- Defining "substantial modification" only after launch. Without a written definition, support engineering decisions on a firmware refactor can accidentally re-trigger conformity assessment.
- Booking the notified body at T-30 days. Capacity is finite; T-3 months is the practical floor.
How Cenitia helps
Cenitia maintains the regulatory calendar continuously. The platform tracks every CRA application date, every delegated act, and every harmonised standard publication and flags the technical files and Declarations of Conformity that need an update. The countdown above is generated as a per-project plan in the platform, with the T-12m, T-6m, T-3m and T-0 milestones turned into actionable items in your workspace.
When a customer's product moves from "Important Class I" to "Important Class II" — or when the Commission publishes a delegated act under Article 8 that affects a Critical product — the affected technical files are automatically re-flagged. See cra-december-2027-readiness for the readiness checklist and cra-timeline-and-reporting-obligations for the full timeline view.
One email at launch · cancel any time
Frequently asked questions
When does the CRA actually start applying?
Per Article 71 of Regulation (EU) 2024/2847, the CRA shall apply from 11 December 2027 in general. Article 14 reporting obligations apply earlier, from 11 September 2026, and the Chapter IV provisions on notified bodies apply from 11 June 2026 to allow conformity assessment infrastructure to be ready.
Do products already on the market on 11 December 2027 need to be re-certified?
No. Article 69(2) states that products with digital elements placed on the market before 11 December 2027 are subject to the CRA only if, from that date, those products are subject to a substantial modification. See cra-existing-products-on-market for the operational interpretation.
Why does Cenitia recommend starting at T-12 months?
Conformity assessment for Annex III Important products typically takes 3-6 months once a notified body is engaged, and notified body capacity for CRA scope was still being built across 2026. Scoping at T-12m gives time to pick a route, prepare the technical file, and book assessment slots before T-3m.
Is the Article 14 reporting obligation already in force?
Yes. Article 71 of Regulation (EU) 2024/2847 fixes the application date of Article 14 at 11 September 2026. Manufacturers must already report actively exploited vulnerabilities and severe incidents within 24 hours of becoming aware, with the 72-hour notification and 14-day final report following. See cra-september-2026-reporting-checklist.
What if our product is sold by an EU importer — do we still need an EU authorised representative?
Yes. CRA requires non-EU manufacturers to designate an EU authorised representative. The importer's responsibilities under the CRA are different and do not substitute for the EC REP. See ec-rep-vs-importer-responsibilities for the split of duties.
Can we wait until 2027 to start the SBOM work?
Operationally, no. The SBOM has to be ready when the technical documentation is drafted at T-3m and must already feed the Article 14 vulnerability handling process from September 2026. Cenitia recommends SBOM tooling deployed by T-6 months at the latest.
Related from the Library
- CRA December 2027 readiness checklist — readiness scoring for the application date
- CRA September 2026 reporting checklist — operational checklist for the earlier reporting application date
- CRA for existing products on market — interpretation of Article 69(2)
- CRA timeline and reporting obligations — the full timeline at a glance
- When you need a notified body — Annex III Important / Annex IV Critical routes
Further reading
- Regulation (EU) 2024/2847 — official text on EUR-Lex
- European Commission — Cyber Resilience Act policy page
- ENISA — vulnerability handling and disclosure resources
- BSI (Germany) — CRA national guidance hub
- ANSSI (France) — cybersecurity regulator
- ACN (Italy) — national cybersecurity authority
- Annotated CRA portal — article-by-article reference
Last reviewed: 5 July 2026. Cited regulations watched continuously by Cenitia — when one amends, this article is flagged for update.
FAQ
Frequently asked questions
When does the CRA actually start applying?
Per Article 71 of Regulation (EU) 2024/2847, the CRA shall apply from 11 December 2027 in general. Article 14 reporting obligations apply earlier, from 11 September 2026, and the Chapter IV provisions on notified bodies apply from 11 June 2026 to allow conformity assessment infrastructure to be ready.
Do products already on the market on 11 December 2027 need to be re-certified?
No. Article 69(2) states that products with digital elements placed on the market before 11 December 2027 are subject to the CRA only if, from that date, those products are subject to a substantial modification. See cra-existing-products-on-market for the operational interpretation.
Why does Cenitia recommend starting at T-12 months?
Conformity assessment for Annex III Important products typically takes 3-6 months once a notified body is engaged, and notified body capacity for CRA scope was still being built across 2026. Scoping at T-12m gives time to pick a route, prepare the technical file, and book assessment slots before T-3m.
Is the Article 14 reporting obligation already in force?
Yes. Article 71 of Regulation (EU) 2024/2847 fixes the application date of Article 14 at 11 September 2026. Manufacturers must already report actively exploited vulnerabilities and severe incidents within 24 hours of becoming aware, with the 72-hour notification and 14-day final report following. See cra-september-2026-reporting-checklist.
What if our product is sold by an EU importer — do we still need an EU authorised representative?
Yes. CRA requires non-EU manufacturers to designate an EU authorised representative. The importer's responsibilities under the CRA are different and do not substitute for the EC REP. See ec-rep-vs-importer-responsibilities for the split of duties.
Can we wait until 2027 to start the SBOM work?
Operationally, no. The SBOM has to be ready when the technical documentation is drafted at T-3m and must already feed the Article 14 vulnerability handling process from September 2026. Cenitia recommends SBOM tooling deployed by T-6 months at the latest.
Continue reading
Related guides
reference
CRA harmonised standards — OJEU tracker (July 2026)
Live status of harmonised standards under the Cyber Resilience Act: standardisation request M/606, EN 40000 series, expected OJEU listings 2027.
6 min read
tutorial
How to check NANDO for Notified Bodies
Step-by-step guide to NANDO — the Commission's public database of Notified Bodies. Search by Directive, by 4-digit ID, by country, and verify a quoted NB number on a DoC.
5 min read
tutorial
How to find harmonised standards in the Official Journal
Tutorial: locate the current list of harmonised standards giving presumption of conformity in the OJEU, verify references, and read excluded clauses.
6 min read
tutorial
How to navigate EUR-Lex — find the consolidated version
Tutorial on EUR-Lex search, ELI URIs, CELEX numbers, and how to find the current consolidated version of an EU regulation plus subscribe to updates.
5 min read
Put this into practice
Free tools & references
- CRA Readiness CheckerScore your product against the Cyber Resilience Act essential requirements.Open tool →
- EU Directive SelectorDescribe your product and find which EU directives and regulations apply.Open tool →
New to the terminology? Browse the compliance glossary — plain-English, citation-backed definitions of every term above.