Cyber Resilience Act timeline: what applies from when
Last updated: 2026-09-30
The Cyber Resilience Act entered into force on 10 December 2024 and applies in three steps. Chapter IV, on the notification of conformity assessment bodies, applies from 11 June 2026; Article 14, on reporting, from 11 September 2026; the regulation as a whole from 11 December 2027. At the time of writing, September 2026, the reporting obligations of Article 14 already apply.
What the text says
Article 71(1):
"This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union."
Article 71(2):
"This Regulation shall apply from 11 December 2027."
"However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026."
Article 69(2):
"Products with digital elements that have been placed on the market before 11 December 2027 shall be subject to the requirements set out in this Regulation only if, from that date, those products are subject to a substantial modification."
Article 69(3):
"By way of derogation from paragraph 2 of this Article, the obligations laid down in Article 14 shall apply to all products with digital elements that fall within the scope of this Regulation that have been placed on the market before 11 December 2027."
The dates in order:
- 20 November 2024: publication in the Official Journal.
- 10 December 2024: entry into force.
- 11 December 2025: the date by which the Commission was to adopt the implementing act on the technical description of important and critical product categories (Article 7(4)) and the delegated act on delaying the dissemination of notifications (Article 14(9)).
- 11 June 2026: Chapter IV applies.
- 11 September 2026: Article 14 applies. ENISA's single reporting platform has been live since that day.
- 11 December 2026: the date by which Member States are to strive for a sufficient number of notified bodies (Article 35(2)).
- 11 December 2027: the regulation applies.
- 11 September 2028: Commission report on the single reporting platform (Article 70(2)).
- 11 December 2030: first Commission report on the evaluation and review of the regulation (Article 70(1)).
What this means in practice
- As written, a product placed on the market before 11 December 2027 comes under the requirements only if it is substantially modified from that date. Article 3, point (30), defines a substantial modification.
- Reporting is the exception. Article 14 applies to products in scope that were placed on the market before that date.
- Placing on the market is, in Article 3, point (21), "the first making available of a product with digital elements on the Union market". How this applies to each new version of a software product is a question of interpretation that this guide does not settle.
- The Commission's implementation page lists an implementing act on technical descriptions related to important and critical products, dated 28 November 2025, and a delegated act on CSIRTs withholding notifications, dated 11 December 2025. It also lists Commission guidance published on 27 July 2026.
- Article 31(2) asks for the technical documentation before a product is placed on the market. For a product placed on the market on or after 11 December 2027, that work falls before the date it is placed on the market.
What to keep as evidence
- For each product and version: the date it was first made available on the Union market.
- The changes made after that date, and your assessment of whether they are a substantial modification.
- From 11 September 2026: the moment you became aware of each actively exploited vulnerability or severe incident, and what you notified.
- The support period and the information used to determine it.
- The software bill of materials of each version, before and after 11 December 2027.
Where DevKit Dossier fits
DevKit Dossier keeps the records these dates ask about. Your CI generates a CycloneDX or SPDX JSON file with Syft or Trivy and uploads it to the SBOM archive per release, where each file keeps its upload time; DevKit Dossier is not a scanner. It checks each release's current SBOM every day against OSV and GitHub advisories, CISA KEV, EPSS and NVD scores; it runs the Article 14 reporting clock (24 hours, 72 hours, 14 days) with a checklist and exports an evidence pack to attach to Annex VII technical documentation. It does not submit anything to ENISA's single reporting platform, gives no legal advice and does not certify anything. It is hosted in the EU and self-serve, at a flat price per organisation of 49, 99 or 249 EUR per month with a 14-day trial.
Sources
- Regulation (EU) 2024/2847 (Cyber Resilience Act)
- European Commission, Cyber Resilience Act
- European Commission, Cyber Resilience Act, implementation
- ENISA, press release of 11 September 2026 on the launch of the platform
This guide is general information, not legal advice.
DevKit Dossier