Cyber Resilience Act timeline and obligations for software makers
The dates, the articles and the numbers, in one table you can cite. Source: Official Journal L, 20 November 2024.
| Date | What applies | Article | Who |
|---|---|---|---|
| 10 Dec 2024 | Entry into force | Art. 71(1) | No duty yet |
| 11 Jun 2026 | Provisions on notified conformity assessment bodies apply (Chapter IV) | Art. 35–51, 71(2) | Member States, notified bodies |
| 11 Sep 2026 | Reporting obligations for actively exploited vulnerabilities and severe incidents. Early warning 24 h, notification 72 h, final report 14 days after the fix (vulnerability) or 1 month after the notification (incident), via the ENISA single reporting platform (Art. 16, operational from this date). You must also inform impacted users. Applies to products already on the market (Art. 69(3)). | Art. 14, 71(2) | Manufacturers (open-source stewards: Art. 24(3), formally from 11 Dec 2027, though ENISA accepts their reports from Sep 2026) |
| 11 Dec 2027 | Full application: essential requirements, vulnerability handling incl. SBOM, technical documentation, conformity assessment, EU declaration of conformity, CE marking, user information, support period, importer/distributor duties, penalties. Products placed on the market before this date are covered only if substantially modified afterwards (Art. 69(2)). | Art. 13, 18–21, 24, 27–32, 64, 69, Annexes I–VIII | Everyone in scope |
Reporting clocks (Article 14)
| Event | Early warning | Notification | Final report | To whom |
|---|---|---|---|---|
| Actively exploited vulnerability in the product | 24 h from awareness | 72 h from awareness | 14 days after a corrective or mitigating measure is available | CSIRT designated as coordinator + ENISA, via the single reporting platform |
| Severe incident having an impact on the security of the product | 24 h from awareness | 72 h from awareness | 1 month after the notification | Same |
| Impacted users | Informed without undue delay of the vulnerability/incident and of corrective or mitigating measures (Art. 14(8)) | Users | ||
Key numbers
| Support period | At least 5 years from placing on the market, unless the product is expected to be in use for less (Art. 13(8)). Security updates remain available for at least 10 years after issuance or for the remainder of the support period, whichever is longer (Art. 13(9)). |
|---|---|
| Record keeping | Technical documentation and EU declaration of conformity kept for 10 years after placing on the market or for the support period, whichever is longer (Art. 13(13)). |
| SBOM | Machine-readable, covering at least the top-level dependencies (Annex I Part II (1)). It goes in the technical documentation (Annex VII (8)). You do not have to publish it. |
| Penalties | Up to €15,000,000 or 2.5 % of worldwide annual turnover (Annex I, Art. 13, Art. 14); up to €10,000,000 or 2 % (other obligations); up to €5,000,000 or 1 % (incorrect, incomplete or misleading information). See Art. 64, applicable from 11 Dec 2027. Micro and small enterprises get no fine for merely missing the 24-hour early-warning deadline. Open-source stewards get no fines at all (Art. 64(10)). |
| Conformity routes | Default products: internal control (Module A). Important class I: internal control only if harmonised standards, common specifications or an EU certification scheme are fully applied, otherwise third-party. Important class II: third-party (notified body). Critical: EU cybersecurity certificate where required by delegated act. See Art. 32 and Annex VIII. Categories are detailed in Implementing Regulation (EU) 2025/2392. |
| Out of scope | Pure SaaS (Recital 12, NIS2 instead); free and open-source software outside a commercial activity (Recital 18); medical devices, vehicles, civil aviation, marine equipment, national security (Art. 2). |
Check anything important against the consolidated text on EUR-Lex (CELEX 32024R2847). This page is a summary, not legal advice.