How do I prepare for the 11 December 2027 CRA deadline?
Also asked
- What are the three CRA application dates?
- Which CRA obligations apply before December 2027?
- When do I need a notified body booked by?
- What has to be ready by 11 September 2026?
Article 71(2) sets three dates rather than one, and the order they arrive in dictates the sequence. Classify every product first, because that decides whether a notified body is involved and third-party assessment is scheduled in quarters. Stand up vulnerability intake and deadline tracking before 11 September 2026, when Article 14 applies. Run the risk assessment and close the Annex I requirements with evidence through 2026 and 2027. Assemble the technical documentation, declaration of conformity and CE marking ahead of 11 December 2027.
The awkward part of the ordering is that the reporting duty binds 15 months before the disclosure process that feeds it becomes formally mandatory.
At a glance
- Entry into force
- Twentieth day after OJ publication, Article 71(1)
- Chapter IV, notified bodies
- 11 June 2026, Articles 35 to 51
- Article 14 reporting
- 11 September 2026
- Everything else
- 11 December 2027
- First thing to do
- Classify, because it gates the notified body decision
- Third-party assessment
- Scheduled in quarters, not weeks
Last reviewed 7 August 2026
Verified against Regulation (EU) 2024/2847 Articles 14, 32 and 71 as published in OJ L, 20.11.2024, read in full text on EUR-Lex on 7 August 2026, and Commission guidance C(2026) 5252 final of 27 July 2026.
Article 71(2) gives you three dates
The Regulation applies from 11 December 2027. Article 71(2) then carves out exactly two derogations that move earlier: Article 14 applies from 11 September 2026, and Chapter IV, Articles 35 to 51, applies from 11 June 2026.[1] Nothing else moves.
Those two exceptions are not arbitrary. Chapter IV governs notification of conformity assessment bodies, so it lands 18 months early to ensure notified bodies exist and are designated before manufacturers need to book them. Article 14 lands 15 months early because vulnerability reporting does not depend on the conformity machinery being finished.
Planning against 11 December 2027 alone is therefore a mistake with a specific cost. It puts the reporting obligation, which binds first, at the end of the programme.
Classify first, because it is the only step measured in quarters
Classification decides the conformity assessment route, and the route decides whether a third party is in the project. A default product self-assesses under module A. An Annex III class I product keeps module A only where harmonised standards, common specifications or a European cybersecurity certification scheme at assurance level at least substantial cover the applicable requirements. Class II loses module A in every case, and an Annex IV critical product takes a certification scheme under Article 8(1) or, where its conditions are not met, the class II routes.[3]
Every other stage of preparation can run in parallel once the class is settled, and none of them can be scheduled sensibly before it. Notified body capacity is finite and designations were still expanding after Chapter IV applied in June 2026, so a class II or critical manufacturer that classifies late finds the queue rather than the calendar setting its deadline.[1]
The classification and its reasoning belong in the technical documentation, not in someone's notes.[4]
What has to work by 11 September 2026
From that date, becoming aware of an actively exploited vulnerability in your product, or of a severe incident affecting its security, starts a 24-hour clock to an early warning, a 72-hour clock to a full notification, and a final report after that.[2]
What this requires operationally is narrower than a compliance programme. You need a channel through which a researcher, customer or authority can reach you, a triage step that produces a documented awareness determination, somewhere the three deadlines are tracked, and a settled answer to which CSIRT is your coordinator.
The ordering trap is worth naming. The coordinated vulnerability disclosure policy and single point of contact that make you aware of these events are Article 13 obligations, and Article 13 does not bind until 11 December 2027.[1] The duty that depends on running disclosure lands more than a year before the duty to run disclosure, so the intake channel is a September 2026 deliverable whatever the formal date on Article 13 says.
The block that lands on 11 December 2027
Everything not carved out by Article 71(2) arrives together.[1] The Annex I essential requirements, the Article 13 manufacturer obligations including the risk assessment and the support period, the Article 31 technical documentation, the Article 32 conformity assessment, the Article 28 EU declaration of conformity, and the Article 30 CE marking rules.
Sequence that block by dependency rather than by effort. The risk assessment determines which Annex I requirements apply, so it precedes the gap work. The Annex I positions and their evidence are what the technical file reports, so the file is an output rather than a separate writing exercise. The declaration of conformity is a signed legal statement that rests on the file, and the CE marking follows the declaration.
Teams that treat the technical documentation as an end-stage document sprint reconstruct decisions from memory and produce a file that contradicts the product. Recording the classification reasoning, the risk assessment and the evidence as the work happens turns the file into a report of what was done.
Sources
Every claim above traces to one of these. Items marked Binding are law in force. Everything else is interpretive and is labelled as such.
- [1]Regulation (EU) 2024/2847 (Cyber Resilience Act), Article 71 (Entry into force and application)Binding
Publications Office of the European Union · Article 71(1) and (2) · CELEX:32024R2847 · OJ L, 20.11.2024
“However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026”
Accessed 2026-08-07
- [2]
Publications Office of the European Union · Article 14(1) to (4) · CELEX:32024R2847 · OJ L, 20.11.2024
Accessed 2026-08-07
- [3]
Publications Office of the European Union · Article 32(2) to (4) · CELEX:32024R2847 · OJ L, 20.11.2024
Accessed 2026-08-07
- [4]Commission guidance on the application of Regulation (EU) 2024/2847 (Cyber Resilience Act), C(2026) 5252 finalCommission guidance
European Commission · C(2026) 5252
Non-binding. Only the Court of Justice of the European Union can give an authoritative interpretation of the CRA.
Accessed 2026-08-07
Further reading on this site
Follow-up questions
What happens to products already on the market on 11 December 2027?+
Placing on the market is the trigger, so the question is when a given unit was placed rather than what date it is now. Products placed on the market before the Regulation applies are treated differently from those placed after it, and a substantial modification can reset that position by making the modified product a new placing. Check the substantial modification test against any planned change that lands near the date.
Is there any extension or transition period beyond 2027?+
Article 71(2) provides no general transition beyond the two derogations that move dates earlier rather than later. The Regulation applies from 11 December 2027 and is binding in its entirety and directly applicable in all Member States, with no national implementation step that could shift the date.
We are a small manufacturer. Does the timeline differ?+
The dates are the same. Article 33 provides support measures for microenterprises and small and medium-sized enterprises, and proportionality runs through how the requirements are met rather than whether they apply. A small manufacturer of a default-class product self-assesses under module A with no notified body, which is a materially shorter path than the class-based routes.
Work out where your product actually lands
Free CRA classification for your product, a vulnerability disclosure portal on your own domain, and Article 14 deadline tracking. Receiving and tracking reports is free for every manufacturer placing products with digital elements on the EU market.