EU Cyber Resilience Act Article 14 reporting timeline & countdown
The EU Cyber Resilience Act applies in two steps. Article 14 mandatory reporting applies from 11 September 2026, and the full regulation, including CE marking, applies from 11 December 2027. When aware of an actively exploited vulnerability or severe incident, manufacturers must submit an early warning notification within 24 hours of becoming aware, a full notification within 72 hours, and a final report within 14 days after a corrective or mitigating measure is available (or 1 month for incidents) to ENISA and Member States via the Single Reporting Platform (SRP).
Drop this on your compliance dashboard
Paste the snippet below into any page that supports HTML. The widget loads in an iframe, weighs under 20 KB, sets no cookies, and updates every second.
<iframe src="https://cvdportal.com/embed/countdown" width="600" height="200" style="border:0;max-width:100%" loading="lazy" title="EU CRA Article 14 countdown"></iframe>
Default size is 600 by 200 pixels. The widget is responsive and scales to its container.
CRA key dates
All application dates come from Article 71 of Regulation (EU) 2024/2847. The full timeline of enforcement actions and guidance lives in the CRA enforcement tracker.
| Milestone | Date | Legal basis |
|---|---|---|
| Regulation entered into force | 10 December 2024 | Article 71(1) |
| Notified body provisions apply (Chapter IV) | 11 June 2026 | Article 71(2) |
| Article 14 vulnerability and incident reporting applies | 11 September 2026 | Article 71(2) |
| Full regulation applies, including CE marking | 11 December 2027 | Article 71(2) |
How to prepare for the 11 December 2027 deadline
Working back from the date the regulation applies in full. The order matters more than the pace, because stage two decides whether a notified body is in the project and that is the only step with a lead time measured in quarters.
Scope and classify every product
Establish which products are in scope and which class each falls into under Annex III and Annex IV. This is the determination everything else depends on, and it is the one that decides whether a notified body is involved. A Class II or critical product needs its assessment booked from here, not later.
Stand up intake and the reporting clock
Article 14 applies from 11 September 2026, more than a year ahead of the rest. A disclosure channel, a triage process and deadline tracking need to be running by then, because an actively exploited vulnerability from that date starts a 24-hour clock whether or not the rest of your programme is ready.
Risk assessment and Annex I gap closure
Run the per-product cybersecurity risk assessment, then work the Annex I essential requirements clause by clause, recording status and evidence as you go. This is the longest stage and the one that produces most of the technical file. Treating it as a documentation sprint at the end is the standard way to run out of time.
Technical file, declaration and CE marking
Assemble the Annex VII technical documentation from the recorded state, issue the Annex V EU Declaration of Conformity naming the conformity route taken, and apply the CE marking. Where a notified body was involved its identification number goes alongside. Products placed on the market after 11 December 2027 need the full file behind them.
What changes on 11 September 2026
Article 14 obliges every manufacturer of products with digital elements to notify ENISA and the relevant CSIRT of any actively exploited vulnerability or severe incident affecting the security of the product. The cascade is an early warning within 24 hours, an intermediate notification within 72 hours, and a final report within 14 days for an actively exploited vulnerability or one month for a severe incident.
Article 14 is the only substantive obligation that moves this early. Under Article 71(2) the Regulation applies from 11 December 2027, and the sole derogations are Article 14 from 11 September 2026 and Chapter IV on notified bodies from 11 June 2026. So Article 14 comes 15 months ahead of the rest.
Everything else arrives on 11 December 2027, including placing on the market, CE marking, conformity assessment, and the Article 13 manufacturer obligations such as the coordinated vulnerability disclosure policy and the security contact. In practice the CVD process needs to be running before September 2026 anyway, because Article 14 reporting depends on it. For the full picture of every obligation, read the EU Cyber Resilience Act guide.
Timeline questions, answered
When does the EU Cyber Resilience Act take effect?
The Cyber Resilience Act (Regulation (EU) 2024/2847) entered into force on 10 December 2024. Article 14 vulnerability and incident reporting applies from 11 September 2026, and the full regulation, including CE marking and conformity assessment, applies from 11 December 2027.
What is the CRA deadline in September 2026?
From 11 September 2026, every manufacturer of products with digital elements sold in the EU must report actively exploited vulnerabilities and severe incidents to ENISA and the relevant national CSIRT, with an early warning within 24 hours, a notification within 72 hours, and a final report after 14 days or one month.
What happens on 11 December 2027?
On 11 December 2027 the Cyber Resilience Act applies in full. Products with digital elements placed on the EU market must meet the Annex I essential requirements, carry CE marking, have technical documentation and an EU Declaration of Conformity, and manufacturers must run a coordinated vulnerability disclosure process under Article 13.
Which CRA obligations apply before 2027?
Two parts move early under Article 71(2). Chapter IV on notified bodies applies from 11 June 2026, and Article 14 reporting of actively exploited vulnerabilities and severe incidents applies from 11 September 2026. Everything else applies from 11 December 2027.
How long does it take to prepare for the CRA?
For a default-class product with an existing security process, months, and mostly evidence collection and documentation. For a Class II or critical product the schedule belongs to the notified body, where assessment alone can run 6 to 18 months and the first examination frequently finds non-conformities that need remediation and re-test. That is why classification comes first: it is the only step whose lead time is measured in quarters rather than weeks.
Get Article 13 ready in an afternoon
CVD Portal runs the Article 13 intake and the Article 14 cascade for EU manufacturers. The free tier covers Article 13. Reporting and Enterprise add the 24h / 72h / final report workflow.
CRA deadline briefing
A short email on the Cyber Resilience Act reporting obligations and the run-up to 11 September 2026.
We use your email only to send the briefing. Unsubscribe any time with one click.