Public datasetUpdated 2026-08-03CC BY 4.0

CRA Enforcement Tracker

Every announced enforcement action under the EU Cyber Resilience Act, every ENISA guidance update, every Member State authority designation, every harmonised standard published in support of the regulation. Filterable by country, type, and year. Updated weekly. Free to republish with attribution.

25
Entries
2
Member states covered
5
Entry categories
2026-08-03
Last updated

Anchor dates

The EU Cyber Resilience Act timeline runs in two steps. Article 14 reporting applies from 11 September 2026 and the full regulation from 11 December 2027. Every tracker entry below sits against these dates from Article 71 of Regulation (EU) 2024/2847. For what each obligation means, see the EU Cyber Resilience Act guide.

EU Cyber Resilience Act key dates under Regulation (EU) 2024/2847
MilestoneDateLegal basis
Regulation entered into force10 December 2024Article 71(1)
Notified body provisions apply (Chapter IV)11 June 2026Article 71(2)
Article 14 vulnerability and incident reporting applies11 September 2026Article 71(2)
Full regulation applies, including CE marking11 December 2027Article 71(2)
Showing 25 of 25 entries
DateCountryTypeEventArticle
Anchor date
EU
EU-wide
Anchor dateCRA becomes fully applicable to all products with digital elements

All remaining obligations apply, including the essential cybersecurity requirements in Annex I, the Article 13 manufacturer obligations covering the coordinated vulnerability disclosure policy and the single point of contact, conformity assessment under Article 32, and CE marking of products with digital elements. Manufacturers must have completed conformity assessment before placing products on the market.

Source: EUR-Lex (Article 71(2))

Article 71(2)
Anchor date
EU
EU-wide
Anchor dateArticle 14 (incident and vulnerability reporting) becomes applicable

Manufacturers of products with digital elements placed on the EU market must report actively exploited vulnerabilities and severe incidents to ENISA and the relevant national CSIRT on the 24-hour early warning, 72-hour notification and final-report cadence. Article 71(2) derogates only Article 14 and Chapter IV from the general application date. Every other obligation, Article 13 included, applies from 11 December 2027.

Source: EUR-Lex (Article 71(2))

Article 14 (via Article 71(2))
EU
EU-wide
GuidanceENISA publishes SRP registration and notification guidance, and a reporting factsheet

ENISA updates its Single Reporting Platform FAQ and publishes separate guidance on authorised-representative user registration and on notification submission and update, alongside a two-page factsheet on reporting. Access to the platform requires a European Commission EU Login account, which applies to manufacturers and to the authorised representatives of open-source software stewards. The CSIRT designated as coordinator validates that a representative may report on behalf of a specific manufacturer, after first access rather than beforehand. ENISA states that no application programming interfaces will be provided at this stage, so every notification is filed manually.

Source: ENISA CRA SRP topic page and FAQ

Article 16 (single reporting platform)
EU
EU-wide
GuidanceENISA publishes the Secure by Design and Default Playbook

Twenty-two playbooks covering the application of secure by design and secure by default principles across a product life cycle, grouped into architectural foundations, operational integrity, default hardening and guided protection. The audience is SMEs and national authorities. The playbooks are also published on GitHub under CC BY 4.0. This is ENISA guidance rather than a harmonised standard, so applying it confers no presumption of conformity.

Source: ENISA publication

Annex I Part I
EU
EU-wide
Guidance2026 Minimum Elements for a Software Bill of Materials published, replacing the 2021 NTIA baseline

CISA and seventeen partner agencies, including the EU national authorities ANSSI, BSI, ACN, NASK, NBU, NCSC-NL and NÚKIB, publish version 2.1 of the SBOM minimum elements. It expands the data fields from seven to seventeen, replaces Supplier Name with Component Producer, and replaces Depth with Coverage, which requires all components including transitive dependencies with no minimum depth. It cites Regulation (EU) 2024/2847 and BSI TR-03183-2 as related guidance. It is not EU law, it is not a CRA obligation, and by its own terms it creates no new requirements. The CRA requirement is Annex I Part II(1), which asks for at least the top-level dependencies.

Source: CISA and international partners, 2026 SBOM Minimum Elements

Annex I Part II (1)
EU
EU-wide
GuidanceCommission adopts guidance on the application of the Cyber Resilience Act (C(2026) 5252)

The Commission adopts the Article 26(1) guidance, running to 84 pages and 67 worked examples. It defines when a manufacturer 'becomes aware' for the purposes of the Article 14 reporting deadlines, sets out a four-factor test for whether a software update is a substantial modification, confirms that the five-year support period in Article 13(8) is a minimum rather than a default, reduces the remote data processing definition to two cumulative questions, and states that a web application accessed exclusively through a browser is not a product with digital elements. The guidance is non-binding and follows a public consultation held between 3 and 31 March 2026.

Source: European Commission, CRA implementation

Article 26(1) (guidance)
EU
EU-wide
GuidanceCISA, NSA, JPCERT/CC, NCSC-NL and NCSC-UK publish joint guidance on establishing a CVD programme

A joint international guide on running a coordinated vulnerability disclosure programme and working with security researchers, co-authored by NCSC-NL among others. It covers policy scope, intake, triage and researcher communication. It is not EU law and creates no CRA obligation, but the practices it describes map onto what CRA Article 13 and Annex I Part II require a manufacturer to operate.

Source: Joint guidance, CISA and partners

Article 13, Annex I Part II
EU
EU-wide
StandardFirst ETSI CRA vertical standards reach enquiry and final draft stage

Several EN 304 6xx deliverables reach enquiry or final draft during June and July 2026, including anti-malware software, firewalls and intrusion detection or prevention systems, routers and switches, hypervisors and container runtimes, internet-connected toys and personal wearables. None is cited in the Official Journal, so none confers presumption of conformity.

Source: ETSI CYBER-EUSR open consultation area

Article 27 (presumption of conformity)
EU
EU-wide
GuidanceCommission publishes version 1.3 of its CRA implementation FAQ

The Commission services update their frequently asked questions on applying the CRA, covering scope questions, the open-source steward regime and the obligations timeline. The document carries its own version table and runs 1.0 (3 December 2025), 1.1 (17 December 2025), 1.2 (16 January 2026) and 1.3. It is prepared by the Commission services, is explicitly not representative of the Commission's official position, and creates no obligations beyond the Regulation.

Source: European Commission, CRA implementation FAQ

n/a
Anchor date
EU
EU-wide
Anchor dateChapter IV (Articles 35 to 51, notification of conformity assessment bodies) becomes applicable

The provisions governing notifying authorities, notified bodies and their notification take effect. This is the other half of the Article 71(2) derogation alongside Article 14, and it is what allows conformity assessment bodies to be notified under the CRA ahead of full applicability.

Source: EUR-Lex (Article 71(2))

Chapter IV, Articles 35 to 51 (via Article 71(2))
EU
EU-wide
Delegated actDelegated Regulation (EU) 2026/881 published in the Official Journal of the European Union

Publication completes the delayed-dissemination delegated act, roughly four months after adoption. The rules form part of the framework governing how Article 14 notifications flow between the coordinating CSIRT, ENISA and other recipients once the single reporting platform goes live.

Source: EUR-Lex, Delegated Regulation (EU) 2026/881

Article 14(9)
EU
EU-wide
StandardETSI opens public consultation on the EN 304 vertical CRA standards

ETSI TC CYBER publishes drafts of its EN 304 6xx series in an open consultation area, together with commenting instructions. The series covers the vertical standards under standardisation request M/606, one per Annex III product category, with the deliverable number set to 304 600 plus the mandate line item.

Source: ETSI CYBER-EUSR open consultation area

Article 27 (presumption of conformity)
EU
EU-wide
Delegated actCommission adopts Delegated Regulation (EU) 2026/881 on delaying dissemination of Article 14 notifications

Adopted under Article 14(9), the delegated act specifies the terms and conditions under which a coordinating CSIRT or ENISA may delay dissemination of a notification on cybersecurity-related grounds. It governs how far a manufacturer can expect a report to be held back from wider circulation while a vulnerability remains unremediated.

Source: EUR-Lex, Delegated Regulation (EU) 2026/881

Article 14(9)
EU
EU-wide
Implementing actImplementing Regulation (EU) 2025/2392 specifies the technical description of the important and critical product categories

The Commission adopts the implementing act describing the core functionality of each category of important products in Annex III and critical products in Annex IV, with non-exhaustive illustrative examples. The categorisation determines which conformity assessment route applies, so the description settles whether a given product faces the stricter Annex III route or the Annex IV certification route. Published in the Official Journal on 1 December 2025 and in force from 21 December 2025.

Source: EUR-Lex, Implementing Regulation (EU) 2025/2392

Annexes III and IV, Article 7(4)
EU
EU-wide
StandardCEN-CENELEC JTC 13 publishes work programme for harmonised CRA standards

JTC 13 publishes its work programme detailing the harmonised standards under development for CRA Annex I essential requirements, with target publication dates ahead of full applicability in December 2027.

Source: CEN-CENELEC cybersecurity sector page

n/a
EU
EU-wide
GuidanceENISA launches the European Union Vulnerability Database (EUVD)

ENISA launches the EUVD as required under NIS2 Article 12, providing a public catalogue of vulnerabilities with European context. The EUVD will integrate with the CRA Single Reporting Platform once Article 14 reporting becomes applicable in September 2026.

Source: EUVD (ENISA)

Article 16 (EUVD interaction)
EU
EU-wide
StandardCEN, CENELEC and ETSI formally accept standardisation request M/606

The three European Standardisation Organisations accept the CRA standardisation request, committing to deliver the 41 requested standards. Work is split between CEN-CENELEC JTC 13 for the horizontal EN 40000 series and ETSI TC CYBER for the vertical EN 304 6xx series. Acceptance starts the drafting programme but confers nothing on manufacturers until a standard is cited in the Official Journal.

Source: CEN-CENELEC news announcement

Article 27 (presumption of conformity)
FR
France
GuidanceANSSI publishes CRA implementation guidance for French manufacturers

L'Agence nationale de la sécurité des systèmes d'information (ANSSI) publishes guidance for French manufacturers on CRA scope, the Article 13 SPOC requirement, and the upcoming Article 14 reporting workflow. ANSSI is the expected national CSIRT recipient under Article 14.

Source: ANSSI CRA page

n/a
EU
EU-wide
StandardCommission issues standardisation request M/606 to CEN, CENELEC and ETSI for harmonised CRA standards

Commission Implementing Decision C(2025) 618 final requests 41 harmonised European standards supporting the essential cybersecurity requirements in Annex I of the CRA, split between horizontal standards and vertical standards for the Annex III product categories. Compliance with a standard cited in the Official Journal provides a presumption of conformity under Article 27. The mandate expires on 30 November 2027.

Source: Commission Implementing Decision C(2025) 618 final

Article 27 (presumption of conformity)
DE
Germany
GuidanceBSI signals lead role for CRA market surveillance and conformity assessment in Germany

The Bundesamt für Sicherheit in der Informationstechnik (BSI) publishes guidance positioning itself as the expected lead authority for CRA market surveillance and conformity assessment in Germany, pending formal national legislation transposing supervisory powers.

Source: BSI CRA page

n/a
EU
EU-wide
GuidanceENISA publishes CRA overview and FAQ on its dedicated topic page

ENISA opens a dedicated Cyber Resilience Act topic page summarising the regulation, the application timetable, and the agency's role in the Single Reporting Platform and the European vulnerability database (EUVD).

Source: ENISA topic page

n/a
Anchor date
EU
EU-wide
Anchor dateRegulation (EU) 2024/2847 enters into force

The Cyber Resilience Act enters into force across the European Union. Most substantive obligations apply later (see September 2026 and December 2027 anchors), but the legal framework is now binding on Member States for transposition and on the Commission for delegated and implementing acts.

Source: EUR-Lex (Official Journal)

Article 71 (entry into force)
EU
EU-wide
GuidanceCRA text published in the Official Journal of the European Union

Regulation (EU) 2024/2847 of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements is published in the OJ, locking in the 20-day countdown to entry into force.

Source: EUR-Lex OJ L 2024/2847

n/a
EU
EU-wide
GuidanceCouncil of the EU formally adopts the Cyber Resilience Act

The Council adopts the CRA after the European Parliament's plenary vote in March 2024, completing the ordinary legislative procedure. Final text proceeds to OJ publication and signature.

Source: Council of the EU press release

n/a
EU
EU-wide
GuidanceEuropean Parliament adopts CRA at first reading

MEPs approve the trilogue-agreed text by a wide margin, clearing the final political hurdle before Council adoption. Key amendments included the carve-out for open-source software stewards and the staged application timetable.

Source: European Parliament press release

n/a

Methodology

An entry is included when one of the following has occurred: a formal enforcement action by an EU or Member State authority under the CRA, an ENISA or Commission guidance or FAQ publication, a Member State designation of an NCA or CSIRT with CRA scope, a harmonised standard published or referenced under Article 27, a delegated or implementing act adopted under the CRA, or a court decision touching CRA scope.

Each entry cites an official source as the primary reference (Official Journal, ENISA, the European Commission, a national authority, or a national publication). Reputable trade press is accepted only as a secondary corroborating source.

Anchor dates (entry into force, Article 13 and 14 applicability, full applicability) are included as a navigation aid and are visually flagged so they are not confused with actual events. All dates are the date of the underlying event, not the date the entry was added.

To suggest an entry or flag an error, email [email protected] with a working source URL. Corrections are made in place and the dataset's last-updated date is bumped.

Run Article 13 and 14 in CVD Portal

CVD Portal runs the Article 13 coordinated disclosure intake and the Article 14 reporting cascade for EU manufacturers. Free tier covers Article 13. Reporting and Enterprise add the 24h / 72h / final report workflow for Article 14.

CRA deadline briefing

A short email on the Cyber Resilience Act reporting obligations and the run-up to 11 September 2026.

We use your email only to send the briefing. Unsubscribe any time with one click.