Logo Teldat

• Cybersecurity Glossary

Cyber Resilience Act Timeline 2024-2027: All the Key Dates

The Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, follows a Staged timeline from 2024 to 2027 rather than a single compliance date. It entered into force on 10 December 2024, the conformity assessment body framework applies from 11 June 2026, the Reporting obligations apply from 11 September 2026, and the bulk of the regulation, including the essential requirements and CE marking, applies in full from 11 December 2027. This page lays out the full CRA timeline with every key date, explains what each milestone means, and shows what it implies for manufacturers of products with digital elements such as Teldat.

The CRA timeline at a glance

The Cyber Resilience Act does not have a single compliance date. Instead, Regulation (EU) 2024/2847 sets out a staged timeline, with obligations phasing in between its entry into force in 2024 and full application in 2027. Understanding this sequence is the key to preparing at the right time rather than too late or for the wrong deadline.

A common mistake is to treat the CRA as a 2027 problem. In reality the first binding obligation, incident and vulnerability reporting, applies from 11 September 2026, more than a year before the rest, and reaches products already on the market. Reading the timeline correctly means recognizing that the earliest deadline is also one of the most operationally demanding.

For a European manufacturer of products with digital elements such as Teldat, whose routers and gateways fall within the CRA’s scope, the timeline is not an abstract schedule but a set of dates the company itself must meet. That is why it tracks the milestones as a manufacturer in scope, preparing for each phase as it arrives.

Full timeline of key dates

The table below sets out every key date in the CRA timeline, from adoption through to full application, including the supporting milestones for conformity assessment bodies and harmonized standards. The three binding dates are the ones most organizations plan around.

Date Milestone What it means?
23 October 2024 Adoption The CRA is adopted as Regulation (EU) 2024/2847
20 November 2024 Publication Published in the Official Journal of the EU
10 December 2024 Entry into force The staged implementation clock starts
11 June 2026 Conformity assessment bodies Chapter IV applies, notified bodies can be designated
11 September 2026 Reporting obligations Article 14 vulnerability and incident reporting begins
During 2026 and 2027 Harmonized standards Standards delivered to support compliance ahead of 2027
11 December 2027 Full application Essential requirements and CE marking apply in full

Reading the table: the three dates in bold effect, 10 December 2024, 11 September 2026 and 11 December 2027, are the binding milestones. The others prepare the ground: the conformity assessment framework and the harmonized standards exist so that manufacturers can actually meet the full application deadline when it arrives in December 2027.

The three binding milestones

Behind the full table, three dates are the ones that actually create obligations. Each marks a different kind of duty, and together they define the shape of the CRA timeline.

1
10 December 2024, entry into force
The CRA became law across the EU on this date, starting the implementation clock. Nothing became immediately mandatory for manufacturers, but from this point the design of new products carries CRA relevance, because they will need to meet the essential requirements by the time full application arrives.
2
11 September 2026, reporting obligations
From this date, manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA and their national CSIRT, on a 24 hour, 72 hour and 14 day cascade. This is the first obligation with operational teeth, and it applies even to products already on the market, so it cannot be deferred to 2027.
3
11 December 2027, full application
This is the comprehensive deadline. From this date, products with digital elements placed on the EU market must meet the essential cybersecurity requirements, complete the relevant conformity assessment and carry the CE marking. It is the point at which the CRA applies in full across all member states.
4
11 June 2026, The supporting milestone
Ahead of the reporting deadline, the framework for notifying conformity assessment bodies applies from 11 June 2026. This lets notified bodies be designated in advance, building the infrastructure that manufacturers of important and critical products will need to demonstrate conformity by December 2027.

Why September 2026 comes first?

Of all the dates on the timeline, 11 September 2026 is the one that most changes what organizations must do now. Here is why it, rather than the 2027 date, is the immediate priority.

1
It applies to existing products
Unlike full application in 2027, the reporting obligation reaches products already on the EU market. Manufacturers cannot wait for a clean start with new product lines, because their current portfolio is in scope for reporting from September 2026 onward.
2
It demands detection, not paperwork
The 24 hour early warning cannot be met by a template alone. It requires the ability to detect active exploitation and severe incidents quickly, which means continuous monitoring and vulnerability management need to be in place well before the date itself.
3
It comes with real penalties
CRA breaches can attract fines of up to 15 million euros or 2.5% of worldwide annual turnover. Because the reporting duty is the first to bite, it is also the first point at which those penalties become a live risk, which sharpens the priority further.
4
It sets the tone for 2027
Organizations that build monitoring, detection and response for the September 2026 reporting duty are also laying groundwork for the essential requirements that apply in full in 2027. Treating the timeline as a sequence, not two isolated dates, makes the whole path more manageable.

How to prepare for each phase?

Because the CRA phases in, preparation is best planned against the timeline rather than left to a single push before 2027. These are the priorities that align with each stage.

1
Now, reporting readiness
With the reporting obligation already live, the immediate priority is being able to detect and report. That means monitoring products in the field, having runbooks ready, knowing your CSIRT and being registered on the reporting platform, so the process runs rather than being improvised under a 24 hour clock.
2
Toward 2027, essential requirements
In parallel, manufacturers should work toward the essential cybersecurity requirements that apply in full in December 2027, designing security into products, preparing technical documentation and planning for conformity assessment and CE marking against the harmonized standards as they arrive.
3
Across the lifecycle, secure maintenance
The CRA expects security across a product’s whole life, including updates and vulnerability handling after sale. Building maintenance and update processes now serves both the reporting duty and the later essential requirements, so it is effort that pays off across the timeline.
4
Supply chain, choosing partners
Because the CRA runs through the supply chain, the choice of hardware and component suppliers matters. Sourcing from manufacturers that track the CRA timeline and design for it, ideally under European jurisdiction, helps align your own products and reduces surprises later in the schedule.

The CRA timeline and Teldat

Teldat is a European manufacturer of products with digital elements, such as routers and network gateways, so the CRA timeline applies to Teldat directly. It tracks the milestones as a manufacturer in scope, not as an outside compliance vendor.

1
Tracking the milestones from the inside
Because its products are in scope, Teldat follows the CRA timeline as its own compliance path, preparing for the reporting obligations that began in September 2026 and working toward the essential requirements and CE marking that apply in full in December 2027.
2
Security across the product lifecycle
The timeline ultimately rests on building and maintaining secure products. As a manufacturer, Teldat works vulnerability management and secure maintenance into its hardware and software, which is the foundation both the reporting duty and the later essential requirements depend on.
3
A European Partner for your supply chain
For organizations that operate Teldat equipment, sourcing hardware from a European manufacturer that tracks the CRA timeline and works under European jurisdiction helps align their own supply chain with the regulation as each milestone arrives.
4
Detection that supports the reporting phase
Since the September 2026 phase depends on fast detection, the monitoring and visibility Teldat builds into its network and security portfolio, including be.Safe XDR, support the rapid awareness that the reporting timeline ultimately requires.

A manufacturer that tracks the timeline: because Teldat is itself subject to the CRA, it plans against the same dates as its customers. It builds security and vulnerability management into European made hardware under European jurisdiction, which helps customers align their supply chain across the CRA timeline. Teldat does not certify compliance, and each organization remains responsible for its own obligations, but sourcing from an in scope European manufacturer is a meaningful part of the picture.

Frequently asked questions about the CRA timeline

❯ When did the Cyber Resilience Act enter into force?

The Cyber Resilience Act, Regulation (EU) 2024/2847, entered into force on 10 December 2024. It had been adopted on 23 October 2024 and published in the Official Journal of the EU on 20 November 2024. Entry into force started the clock on a staged implementation timeline, but it did not make all the obligations binding at once. Instead, the CRA phases in its requirements between 2024 and 2027, so entry into force mainly marks the point from which the countdown to the later, binding milestones begins.

❯ What are the key dates in the Cyber Resilience Act timeline?

The CRA timeline has three binding milestones and a few supporting ones. It entered into force on 10 December 2024. From 11 June 2026, the framework for notifying conformity assessment bodies applies, so notified bodies can be designated ahead of full application. From 11 September 2026, the reporting obligations under Article 14 apply, requiring manufacturers to report actively exploited vulnerabilities and severe incidents. Finally, from 11 December 2027, the bulk of the regulation applies in full, including the essential cybersecurity requirements and CE marking. Harmonized standards are also expected during 2026 and 2027 to support compliance.

❯ When do the CRA obligations fully apply?

The bulk of the Cyber Resilience Act applies in full from 11 December 2027. From that date, products with digital elements placed on the EU market must meet the essential cybersecurity requirements and carry the CE marking, and manufacturers must have completed the relevant conformity assessment. This is the final and most comprehensive milestone in the timeline. However, it is not the first deadline manufacturers face: the reporting obligations apply more than a year earlier, from 11 September 2026, and apply even to products already on the market, so compliance work cannot wait until 2027.

❯ Why does September 2026 matter in the CRA timeline?

11 September 2026 matters because it is the first CRA obligation with real operational impact. From that date, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents to ENISA and their national CSIRT, following a 24 hour early warning, 72 hour notification and 14 day or one month final report cascade. Crucially, this obligation applies to products already on the EU market, not only new ones, so it reaches existing product lines well before the full application date of December 2027. It is the deadline that tests whether an organization’s incident detection and response actually work.

❯ How does Teldat approach the CRA timeline?

As a European manufacturer of products with digital elements, such as routers and network gateways, Teldat is itself subject to the CRA and its staged timeline. It treats the milestones not as an outside compliance vendor but as a manufacturer in scope, building security and vulnerability management into its hardware and software across the product lifecycle, and preparing for the reporting obligations that began in September 2026 as well as the full application in December 2027. For organizations that operate Teldat equipment, sourcing from a European manufacturer that tracks the CRA timeline and works under European jurisdiction helps align their own supply chain with the regulation, though each organization remains responsible for its own compliance.

As a European manufacturer of products with digital elements, Teldat tracks the Cyber Resilience Act timeline from the inside, building security and vulnerability management into its hardware under European jurisdiction to help customers align their supply chain.