The CRA doesn’t come into force all at once, and this is where the costliest misunderstanding is born. Those who read “obligations from December 2027” file the matter away as tomorrow’s problem. Then they discover that a part of the regulation, the one carrying the most immediate operational risk, has already kicked in earlier. The CRA deadlines are not a calendar to mark: they are three states of readiness, each with a precise what you must have done.
The regulation (EU 2024/2847) has been in force since 10 December 2024, but its application is staggered. Article 71, paragraph 2 sets three moments: the regulation applies from 11 December 2027; article 14 applies from 11 September 2026; chapter IV (articles 35 to 51, notification of conformity assessment bodies) from 11 June 2026. They should be read in order of urgency, not of date. If the general picture, what a product with digital elements is and which obligations it carries, is not yet in focus, the starting point is The CRA in one hour.
11 September 2026, reporting
From this date, article 14 applies: the obligation to report actively exploited vulnerabilities and severe incidents. It’s the nearest deadline and the one that surprises most, for two reasons.
The first: it also concerns products already on the market. The Commission’s guidance (document C(2026) 5252, non-binding) clarifies that the reporting obligation runs from 11 September 2026 regardless of when the product was placed on the market. It doesn’t concern only what you design from tomorrow, but everything you’ve sold that’s still in the field. The second: the timescales are in hours. On discovering an exploited vulnerability, the early warning must be sent within 24 hours (art. 14, para. 2, point a), the notification within 72 hours (point b), the final report within 14 days of the corrective measure (point c). The channel is ENISA’s single reporting platform (art. 16), with routing to the coordinating national CSIRT.
Operational note (my indication, not the text of the law). What you must have done for this date is not “have a compliant product”. It’s far more concrete: knowing who in the company is authorised to notify, having an EU Login account already created, having a process, even a minimal one, that in the first 24 hours doesn’t waste your time deciding who calls whom, and a register where what you notified and when stays traceable. A company without this process isn’t “behind on the CRA”: it’s exposed to a deadline that’s already live.
11 December 2027, the full obligations
It’s the date almost everyone knows, and indeed it’s the one that gives the false sense of time. From here the substantive requirements apply: the essential requirements of Annex I (product security in part I, vulnerability handling in part II), the cybersecurity risk assessment (art. 13, para. 2 and 3), the conformity assessment procedure (art. 32), and CE marking (art. 30). From this date, a product with digital elements that doesn’t meet them cannot be placed on the market.
What the regulation requires is a process, not a folder of documents. The risk assessment must be documented and maintained for the whole support period (art. 13, para. 3, and Annex I, part II). Whoever already has a certified quality system starts with an advantage on this documentary structure, but not on everything: the map of what to reuse and what to build is in Already ISO 9001 certified?. For “important” products (art. 7, Annex III) and “critical” ones (art. 8, Annex IV) you also need the application of harmonised standards, which gives a presumption of conformity (art. 27), or the involvement of a notified body (art. 32, para. 2 and 3): this is where the third date comes into play, 11 June 2026, from which notified bodies can be designated. These are paths with their own timescales, not improvised in the final weeks.
The point that escapes people about 2027 is the forward reach of the work. The decisions you make today on a product in development, a device that will still be in production in 2028, are already CRA decisions. One fear, though, the Commission’s guidance (C(2026) 5252) lightens: a product designed before the CRA can stay on the market after 2027 on the basis of a current risk assessment, without any obligation to reconstruct historical design documentation that no longer exists. The constraint is on the future, not the past.
End of 2027, the RED bows out
There’s a third date that specifically concerns those who make wireless devices. The cybersecurity requirements tied to the RED (Radio Equipment Directive) cease to apply on 11 December 2027, and the CRA becomes the single reference. The Commission has removed the overlap with Delegated Regulation (EU) 2026/339, avoiding having the same device answer to two parallel sets of technical requirements.
For those who make IoT and radio equipment it’s good news in terms of clarity: one framework, not two. But it’s also a deadline dressed up as a simplification. Whoever was relying on the RED as their cyber reference point has to move the anchor to the CRA, which is broader and continuous.
Operational note (my indication). What you must have done: having verified that the wireless products currently covered by the RED are mapped onto the CRA, without assuming that “we were already RED compliant” equals “we’re CRA compliant”. They are two different perimeters.
How to read the three dates together
The trap is treating them as a single deadline at 2027. In reality they work on two different horizons. September 2026 is a problem of process and people, who notifies, through which channel, in how many hours, and it has to be solved now, regardless of how mature your products are. December 2027 is a design problem, and you only win it if the right decisions enter the products as you draw them, not afterwards.
Whoever keeps the two things separate arrives ready for both. Whoever confuses them risks passing the first deadline believing they still have a year of margin.
References: Regulation (EU) 2024/2847 (CRA), articles 7, 8, 13, 14, 16, 27, 30, 32, 71 and Annexes I, III, IV; Delegated Regulation (EU) 2026/339 (RED); Commission guidance C(2026) 5252 (non-binding). The notes flagged as operational are my interpretations, not regulatory text.