Cyber Resilience Act deadlines
Three dates matter. The second is the one that catches people out, and it is now in effect.
10 December 2024
Entered into forceArt. 71(1)
The Regulation is law. Almost nothing applies yet, which is why most vendors filed it away and forgot it.
11 September 2026
Reporting obligations applyArt. 71(2)
Article 14 starts. From this date an actively exploited vulnerability in a product you place on the EU market must be reported within 24 hours, to the CSIRT designated as coordinator and to ENISA, through the single reporting platform established under Article 16.
11 December 2027
Full obligations applyArt. 71(2)
Conformity assessment, CE marking, technical documentation and the vulnerability-handling requirements of Annex I. This is the larger piece of work, and it is why the reporting duty arriving first catches people out.
There is no legacy exemption
A product placed on the market before these dates stays in scope for reporting while it remains within its support period.Art. 69(3) The common assumption that older products are grandfathered in is wrong, and it is the assumption most likely to leave a vendor with an unreported incident.
Does the first of those dates apply to you?
The reporting duty turns on what you ship and where you sell it, not on the size of your company. Five questions, no sign-up, and it names the authority you would report to.
This produces evidence, timelines and drafts. It is not legal advice, and you remain the party responsible for reporting.