Now in force . Reporting duties apply since 11 Sept 2026.

Tell us what you sell. We tell you what applies to it, and when.

The three dates of the Cyber Resilience Act
  1. Notified bodies

    Chapter IV: conformity assessment bodies can be notified from this date.

  2. Reporting duty

    Article 14: actively exploited vulnerabilities and severe incidents are reported from this date, 24 hours for the early warning.

  3. Everything else

    The essential requirements, the technical file and the CE marking apply to every product placed on the market from this date.

The Cyber Resilience Act, for a software manufacturer

The Cyber Resilience Act reaches every product with digital elements placed on the EU market: the Article 14 reporting duty since 11 September 2026, the rest from 11 December 2027.

What do you place on the EU market?

Answer above to read the determination for your case; the full tool takes your answers with it.

Continue in the free determination

Six tools, free, no account

Every free template on one page

Three dates

Applies

11 September 2026

Article 14: an actively exploited vulnerability or a severe incident starts a 24-hour early warning, a 72-hour notification and a final report, filed on ENISA's single reporting platform. Every product in scope, including those already on the market.

Applies

11 June 2026

Chapter IV: the rules for notified bodies, so that the conformity assessment bodies for important and critical products can be designated. None had been on 11 September 2026.

Applies from

11 December 2027

Full application: the essential requirements of Annex I, the conformity assessment, the technical file, the CE mark and the support period, for every product placed on the market from that day, and for older products once they are substantially modified.

The CRA and the AI Act, since 27 July 2026

A product with digital elements can also be a high-risk AI system under Article 6 of the AI Act. Article 12(1) of the CRA, and since 27 July 2026 Article 42(3) of the AI Act as amended, deem such a system to comply with the AI Act's cybersecurity requirements of Article 15 where the product meets the Annex I Part I requirements, the manufacturer's processes meet Part II, and the level of protection is demonstrated in the CRA EU declaration of conformity. One conformity assessment, under Article 43 of the AI Act, covers both.

Is your product also a high-risk AI system? The determination, free

32 articles, from the primary sources

Does it apply to you, and how much

Reporting, since 11 September 2026

Building the file, by 11 December 2027

The record that makes the duty a page rather than a project

StandardOS keeps the scope determination, the coordinator, the named filer and deputy, each reportable event with its awareness timestamp and its three deadlines, the SBOM, the risk assessment and the technical file as living records, so that hour one of an incident is typing, not reading. Reporting is in the subscription; the technical file pack is €5,000 on top.

Dates are read from the Regulation's Article 71 and never typed on this page. This is not legal advice, and the Regulation is the text to read: Regulation (EU) 2024/2847.