• Cybersecurity Glossary
Cyber Resilience Act Timeline 2024-2027: All the Key Dates
The Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, follows a Staged timeline from 2024 to 2027 rather than a single compliance date. It entered into force on 10 December 2024, the conformity assessment body framework applies from 11 June 2026, the Reporting obligations apply from 11 September 2026, and the bulk of the regulation, including the essential requirements and CE marking, applies in full from 11 December 2027. This page lays out the full CRA timeline with every key date, explains what each milestone means, and shows what it implies for manufacturers of products with digital elements such as Teldat.
The CRA timeline at a glance
The Cyber Resilience Act does not have a single compliance date. Instead, Regulation (EU) 2024/2847 sets out a staged timeline, with obligations phasing in between its entry into force in 2024 and full application in 2027. Understanding this sequence is the key to preparing at the right time rather than too late or for the wrong deadline.
A common mistake is to treat the CRA as a 2027 problem. In reality the first binding obligation, incident and vulnerability reporting, applies from 11 September 2026, more than a year before the rest, and reaches products already on the market. Reading the timeline correctly means recognizing that the earliest deadline is also one of the most operationally demanding.
For a European manufacturer of products with digital elements such as Teldat, whose routers and gateways fall within the CRA’s scope, the timeline is not an abstract schedule but a set of dates the company itself must meet. That is why it tracks the milestones as a manufacturer in scope, preparing for each phase as it arrives.
Full timeline of key dates
The table below sets out every key date in the CRA timeline, from adoption through to full application, including the supporting milestones for conformity assessment bodies and harmonized standards. The three binding dates are the ones most organizations plan around.
| Date | Milestone | What it means? |
|---|---|---|
| 23 October 2024 | Adoption | The CRA is adopted as Regulation (EU) 2024/2847 |
| 20 November 2024 | Publication | Published in the Official Journal of the EU |
| 10 December 2024 | Entry into force | The staged implementation clock starts |
| 11 June 2026 | Conformity assessment bodies | Chapter IV applies, notified bodies can be designated |
| 11 September 2026 | Reporting obligations | Article 14 vulnerability and incident reporting begins |
| During 2026 and 2027 | Harmonized standards | Standards delivered to support compliance ahead of 2027 |
| 11 December 2027 | Full application | Essential requirements and CE marking apply in full |
Reading the table:Â the three dates in bold effect, 10 December 2024, 11 September 2026 and 11 December 2027, are the binding milestones. The others prepare the ground: the conformity assessment framework and the harmonized standards exist so that manufacturers can actually meet the full application deadline when it arrives in December 2027.
The three binding milestones
Behind the full table, three dates are the ones that actually create obligations. Each marks a different kind of duty, and together they define the shape of the CRA timeline.
Why September 2026 comes first?
Of all the dates on the timeline, 11 September 2026 is the one that most changes what organizations must do now. Here is why it, rather than the 2027 date, is the immediate priority.
How to prepare for each phase?
Because the CRA phases in, preparation is best planned against the timeline rather than left to a single push before 2027. These are the priorities that align with each stage.
The CRA timeline and Teldat
Teldat is a European manufacturer of products with digital elements, such as routers and network gateways, so the CRA timeline applies to Teldat directly. It tracks the milestones as a manufacturer in scope, not as an outside compliance vendor.
A manufacturer that tracks the timeline:Â because Teldat is itself subject to the CRA, it plans against the same dates as its customers. It builds security and vulnerability management into European made hardware under European jurisdiction, which helps customers align their supply chain across the CRA timeline. Teldat does not certify compliance, and each organization remains responsible for its own obligations, but sourcing from an in scope European manufacturer is a meaningful part of the picture.
Frequently asked questions about the CRA timeline
❯ When did the Cyber Resilience Act enter into force?
The Cyber Resilience Act, Regulation (EU) 2024/2847, entered into force on 10 December 2024. It had been adopted on 23 October 2024 and published in the Official Journal of the EU on 20 November 2024. Entry into force started the clock on a staged implementation timeline, but it did not make all the obligations binding at once. Instead, the CRA phases in its requirements between 2024 and 2027, so entry into force mainly marks the point from which the countdown to the later, binding milestones begins.
❯ What are the key dates in the Cyber Resilience Act timeline?
The CRA timeline has three binding milestones and a few supporting ones. It entered into force on 10 December 2024. From 11 June 2026, the framework for notifying conformity assessment bodies applies, so notified bodies can be designated ahead of full application. From 11 September 2026, the reporting obligations under Article 14 apply, requiring manufacturers to report actively exploited vulnerabilities and severe incidents. Finally, from 11 December 2027, the bulk of the regulation applies in full, including the essential cybersecurity requirements and CE marking. Harmonized standards are also expected during 2026 and 2027 to support compliance.
❯ When do the CRA obligations fully apply?
The bulk of the Cyber Resilience Act applies in full from 11 December 2027. From that date, products with digital elements placed on the EU market must meet the essential cybersecurity requirements and carry the CE marking, and manufacturers must have completed the relevant conformity assessment. This is the final and most comprehensive milestone in the timeline. However, it is not the first deadline manufacturers face: the reporting obligations apply more than a year earlier, from 11 September 2026, and apply even to products already on the market, so compliance work cannot wait until 2027.
❯ Why does September 2026 matter in the CRA timeline?
11 September 2026 matters because it is the first CRA obligation with real operational impact. From that date, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents to ENISA and their national CSIRT, following a 24 hour early warning, 72 hour notification and 14 day or one month final report cascade. Crucially, this obligation applies to products already on the EU market, not only new ones, so it reaches existing product lines well before the full application date of December 2027. It is the deadline that tests whether an organization’s incident detection and response actually work.
❯ How does Teldat approach the CRA timeline?
As a European manufacturer of products with digital elements, such as routers and network gateways, Teldat is itself subject to the CRA and its staged timeline. It treats the milestones not as an outside compliance vendor but as a manufacturer in scope, building security and vulnerability management into its hardware and software across the product lifecycle, and preparing for the reporting obligations that began in September 2026 as well as the full application in December 2027. For organizations that operate Teldat equipment, sourcing from a European manufacturer that tracks the CRA timeline and works under European jurisdiction helps align their own supply chain with the regulation, though each organization remains responsible for its own compliance.
Navigate the CRA timeline with Teldat
As a European manufacturer of products with digital elements, Teldat tracks the Cyber Resilience Act timeline from the inside, building security and vulnerability management into its hardware under European jurisdiction to help customers align their supply chain.







