CRA Enforcement Tracker
Every announced enforcement action under the EU Cyber Resilience Act, every ENISA guidance update, every Member State authority designation, every harmonised standard published in support of the regulation. Filterable by country, type, and year. Updated weekly. Free to republish with attribution.
Anchor dates
The EU Cyber Resilience Act timeline runs in two steps. Article 14 reporting applies from 11 September 2026 and the full regulation from 11 December 2027. Every tracker entry below sits against these dates from Article 71 of Regulation (EU) 2024/2847. For what each obligation means, see the EU Cyber Resilience Act guide.
| Milestone | Date | Legal basis |
|---|---|---|
| Regulation entered into force | 10 December 2024 | Article 71(1) |
| Notified body provisions apply (Chapter IV) | 11 June 2026 | Article 71(2) |
| Article 14 vulnerability and incident reporting applies | 11 September 2026 | Article 71(2) |
| Full regulation applies, including CE marking | 11 December 2027 | Article 71(2) |
| Date | Country | Type | Event | Article |
|---|---|---|---|---|
Anchor date | EU EU-wide | Anchor date | CRA becomes fully applicable to all products with digital elements All remaining obligations apply, including the essential cybersecurity requirements in Annex I, the Article 13 manufacturer obligations covering the coordinated vulnerability disclosure policy and the single point of contact, conformity assessment under Article 32, and CE marking of products with digital elements. Manufacturers must have completed conformity assessment before placing products on the market. Source: EUR-Lex (Article 71(2)) | Article 71(2) |
Anchor date | EU EU-wide | Anchor date | Article 14 (incident and vulnerability reporting) becomes applicable Manufacturers of products with digital elements placed on the EU market must report actively exploited vulnerabilities and severe incidents to ENISA and the relevant national CSIRT on the 24-hour early warning, 72-hour notification and final-report cadence. Article 71(2) derogates only Article 14 and Chapter IV from the general application date. Every other obligation, Article 13 included, applies from 11 December 2027. Source: EUR-Lex (Article 71(2)) | Article 14 (via Article 71(2)) |
| EU EU-wide | Guidance | ENISA publishes SRP registration and notification guidance, and a reporting factsheet ENISA updates its Single Reporting Platform FAQ and publishes separate guidance on authorised-representative user registration and on notification submission and update, alongside a two-page factsheet on reporting. Access to the platform requires a European Commission EU Login account, which applies to manufacturers and to the authorised representatives of open-source software stewards. The CSIRT designated as coordinator validates that a representative may report on behalf of a specific manufacturer, after first access rather than beforehand. ENISA states that no application programming interfaces will be provided at this stage, so every notification is filed manually. Source: ENISA CRA SRP topic page and FAQ | Article 16 (single reporting platform) | |
| EU EU-wide | Guidance | ENISA publishes the Secure by Design and Default Playbook Twenty-two playbooks covering the application of secure by design and secure by default principles across a product life cycle, grouped into architectural foundations, operational integrity, default hardening and guided protection. The audience is SMEs and national authorities. The playbooks are also published on GitHub under CC BY 4.0. This is ENISA guidance rather than a harmonised standard, so applying it confers no presumption of conformity. Source: ENISA publication | Annex I Part I | |
| EU EU-wide | Guidance | 2026 Minimum Elements for a Software Bill of Materials published, replacing the 2021 NTIA baseline CISA and seventeen partner agencies, including the EU national authorities ANSSI, BSI, ACN, NASK, NBU, NCSC-NL and NÚKIB, publish version 2.1 of the SBOM minimum elements. It expands the data fields from seven to seventeen, replaces Supplier Name with Component Producer, and replaces Depth with Coverage, which requires all components including transitive dependencies with no minimum depth. It cites Regulation (EU) 2024/2847 and BSI TR-03183-2 as related guidance. It is not EU law, it is not a CRA obligation, and by its own terms it creates no new requirements. The CRA requirement is Annex I Part II(1), which asks for at least the top-level dependencies. Source: CISA and international partners, 2026 SBOM Minimum Elements | Annex I Part II (1) | |
| EU EU-wide | Guidance | Commission adopts guidance on the application of the Cyber Resilience Act (C(2026) 5252) The Commission adopts the Article 26(1) guidance, running to 84 pages and 67 worked examples. It defines when a manufacturer 'becomes aware' for the purposes of the Article 14 reporting deadlines, sets out a four-factor test for whether a software update is a substantial modification, confirms that the five-year support period in Article 13(8) is a minimum rather than a default, reduces the remote data processing definition to two cumulative questions, and states that a web application accessed exclusively through a browser is not a product with digital elements. The guidance is non-binding and follows a public consultation held between 3 and 31 March 2026. | Article 26(1) (guidance) | |
| EU EU-wide | Guidance | CISA, NSA, JPCERT/CC, NCSC-NL and NCSC-UK publish joint guidance on establishing a CVD programme A joint international guide on running a coordinated vulnerability disclosure programme and working with security researchers, co-authored by NCSC-NL among others. It covers policy scope, intake, triage and researcher communication. It is not EU law and creates no CRA obligation, but the practices it describes map onto what CRA Article 13 and Annex I Part II require a manufacturer to operate. | Article 13, Annex I Part II | |
| EU EU-wide | Standard | First ETSI CRA vertical standards reach enquiry and final draft stage Several EN 304 6xx deliverables reach enquiry or final draft during June and July 2026, including anti-malware software, firewalls and intrusion detection or prevention systems, routers and switches, hypervisors and container runtimes, internet-connected toys and personal wearables. None is cited in the Official Journal, so none confers presumption of conformity. | Article 27 (presumption of conformity) | |
| EU EU-wide | Guidance | Commission publishes version 1.3 of its CRA implementation FAQ The Commission services update their frequently asked questions on applying the CRA, covering scope questions, the open-source steward regime and the obligations timeline. The document carries its own version table and runs 1.0 (3 December 2025), 1.1 (17 December 2025), 1.2 (16 January 2026) and 1.3. It is prepared by the Commission services, is explicitly not representative of the Commission's official position, and creates no obligations beyond the Regulation. | n/a | |
Anchor date | EU EU-wide | Anchor date | Chapter IV (Articles 35 to 51, notification of conformity assessment bodies) becomes applicable The provisions governing notifying authorities, notified bodies and their notification take effect. This is the other half of the Article 71(2) derogation alongside Article 14, and it is what allows conformity assessment bodies to be notified under the CRA ahead of full applicability. Source: EUR-Lex (Article 71(2)) | Chapter IV, Articles 35 to 51 (via Article 71(2)) |
| EU EU-wide | Delegated act | Delegated Regulation (EU) 2026/881 published in the Official Journal of the European Union Publication completes the delayed-dissemination delegated act, roughly four months after adoption. The rules form part of the framework governing how Article 14 notifications flow between the coordinating CSIRT, ENISA and other recipients once the single reporting platform goes live. | Article 14(9) | |
| EU EU-wide | Standard | ETSI opens public consultation on the EN 304 vertical CRA standards ETSI TC CYBER publishes drafts of its EN 304 6xx series in an open consultation area, together with commenting instructions. The series covers the vertical standards under standardisation request M/606, one per Annex III product category, with the deliverable number set to 304 600 plus the mandate line item. | Article 27 (presumption of conformity) | |
| EU EU-wide | Delegated act | Commission adopts Delegated Regulation (EU) 2026/881 on delaying dissemination of Article 14 notifications Adopted under Article 14(9), the delegated act specifies the terms and conditions under which a coordinating CSIRT or ENISA may delay dissemination of a notification on cybersecurity-related grounds. It governs how far a manufacturer can expect a report to be held back from wider circulation while a vulnerability remains unremediated. | Article 14(9) | |
| EU EU-wide | Implementing act | Implementing Regulation (EU) 2025/2392 specifies the technical description of the important and critical product categories The Commission adopts the implementing act describing the core functionality of each category of important products in Annex III and critical products in Annex IV, with non-exhaustive illustrative examples. The categorisation determines which conformity assessment route applies, so the description settles whether a given product faces the stricter Annex III route or the Annex IV certification route. Published in the Official Journal on 1 December 2025 and in force from 21 December 2025. | Annexes III and IV, Article 7(4) | |
| EU EU-wide | Standard | CEN-CENELEC JTC 13 publishes work programme for harmonised CRA standards JTC 13 publishes its work programme detailing the harmonised standards under development for CRA Annex I essential requirements, with target publication dates ahead of full applicability in December 2027. | n/a | |
| EU EU-wide | Guidance | ENISA launches the European Union Vulnerability Database (EUVD) ENISA launches the EUVD as required under NIS2 Article 12, providing a public catalogue of vulnerabilities with European context. The EUVD will integrate with the CRA Single Reporting Platform once Article 14 reporting becomes applicable in September 2026. Source: EUVD (ENISA) | Article 16 (EUVD interaction) | |
| EU EU-wide | Standard | CEN, CENELEC and ETSI formally accept standardisation request M/606 The three European Standardisation Organisations accept the CRA standardisation request, committing to deliver the 41 requested standards. Work is split between CEN-CENELEC JTC 13 for the horizontal EN 40000 series and ETSI TC CYBER for the vertical EN 304 6xx series. Acceptance starts the drafting programme but confers nothing on manufacturers until a standard is cited in the Official Journal. Source: CEN-CENELEC news announcement | Article 27 (presumption of conformity) | |
| FR France | Guidance | ANSSI publishes CRA implementation guidance for French manufacturers L'Agence nationale de la sécurité des systèmes d'information (ANSSI) publishes guidance for French manufacturers on CRA scope, the Article 13 SPOC requirement, and the upcoming Article 14 reporting workflow. ANSSI is the expected national CSIRT recipient under Article 14. Source: ANSSI CRA page | n/a | |
| EU EU-wide | Standard | Commission issues standardisation request M/606 to CEN, CENELEC and ETSI for harmonised CRA standards Commission Implementing Decision C(2025) 618 final requests 41 harmonised European standards supporting the essential cybersecurity requirements in Annex I of the CRA, split between horizontal standards and vertical standards for the Annex III product categories. Compliance with a standard cited in the Official Journal provides a presumption of conformity under Article 27. The mandate expires on 30 November 2027. | Article 27 (presumption of conformity) | |
| DE Germany | Guidance | BSI signals lead role for CRA market surveillance and conformity assessment in Germany The Bundesamt für Sicherheit in der Informationstechnik (BSI) publishes guidance positioning itself as the expected lead authority for CRA market surveillance and conformity assessment in Germany, pending formal national legislation transposing supervisory powers. Source: BSI CRA page | n/a | |
| EU EU-wide | Guidance | ENISA publishes CRA overview and FAQ on its dedicated topic page ENISA opens a dedicated Cyber Resilience Act topic page summarising the regulation, the application timetable, and the agency's role in the Single Reporting Platform and the European vulnerability database (EUVD). Source: ENISA topic page | n/a | |
Anchor date | EU EU-wide | Anchor date | Regulation (EU) 2024/2847 enters into force The Cyber Resilience Act enters into force across the European Union. Most substantive obligations apply later (see September 2026 and December 2027 anchors), but the legal framework is now binding on Member States for transposition and on the Commission for delegated and implementing acts. Source: EUR-Lex (Official Journal) | Article 71 (entry into force) |
| EU EU-wide | Guidance | CRA text published in the Official Journal of the European Union Regulation (EU) 2024/2847 of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements is published in the OJ, locking in the 20-day countdown to entry into force. Source: EUR-Lex OJ L 2024/2847 | n/a | |
| EU EU-wide | Guidance | Council of the EU formally adopts the Cyber Resilience Act The Council adopts the CRA after the European Parliament's plenary vote in March 2024, completing the ordinary legislative procedure. Final text proceeds to OJ publication and signature. Source: Council of the EU press release | n/a | |
| EU EU-wide | Guidance | European Parliament adopts CRA at first reading MEPs approve the trilogue-agreed text by a wide margin, clearing the final political hurdle before Council adoption. Key amendments included the carve-out for open-source software stewards and the staged application timetable. | n/a |
Methodology
An entry is included when one of the following has occurred: a formal enforcement action by an EU or Member State authority under the CRA, an ENISA or Commission guidance or FAQ publication, a Member State designation of an NCA or CSIRT with CRA scope, a harmonised standard published or referenced under Article 27, a delegated or implementing act adopted under the CRA, or a court decision touching CRA scope.
Each entry cites an official source as the primary reference (Official Journal, ENISA, the European Commission, a national authority, or a national publication). Reputable trade press is accepted only as a secondary corroborating source.
Anchor dates (entry into force, Article 13 and 14 applicability, full applicability) are included as a navigation aid and are visually flagged so they are not confused with actual events. All dates are the date of the underlying event, not the date the entry was added.
To suggest an entry or flag an error, email [email protected] with a working source URL. Corrections are made in place and the dataset's last-updated date is bumped.
Run Article 13 and 14 in CVD Portal
CVD Portal runs the Article 13 coordinated disclosure intake and the Article 14 reporting cascade for EU manufacturers. Free tier covers Article 13. Reporting and Enterprise add the 24h / 72h / final report workflow for Article 14.
CRA deadline briefing
A short email on the Cyber Resilience Act reporting obligations and the run-up to 11 September 2026.
We use your email only to send the briefing. Unsubscribe any time with one click.