Sembra che tu preferisca leggere in italiano.

Passa all'italiano

STATE OF PLAY — CYBERSECURITY

CRA state of play

The Cyber Resilience Act does not start all at once. Here is where it stands: the dates that matter, the status of the harmonised standards and of the reporting platform. A page kept up to date — for the detailed operational timeline see the guide the CRA deadlines.

Last updated: 24 August 2026

days to the reporting duty of 11 September 2026 (Art. 14)

Regulation

The part that moves: dates, obligations, guidance.

Done

10 December 2024

The regulation enters into force

The CRA is in force, but its application is staggered: the dates below are when the obligations actually begin to bite.

Art. 71(1)
Done

11 June 2026

Notified bodies can be designated

From this date Chapter IV applies: the third-party conformity-assessment machinery — needed for important and critical products — starts up. Notified-body routes take time and cannot be improvised under deadline.

Art. 71(2) · Capo IV
Imminent

11 September 2026

The reporting duty starts (Art. 14)

The nearest deadline and the one that surprises most: it also covers products already on the market. Actively exploited vulnerabilities and severe incidents must be reported on ENISA’s single platform — early warning within 24h, notification within 72h, final report within 14 days. What you need is the process, not a compliant product.

What you must have done

A working reporting process, not a compliant product. You need: an internal channel to detect actively exploited vulnerabilities and severe incidents, assigned roles and responsibilities, and the three timings met — early warning within 24 hours, notification within 72, final report within 14 days — to ENISA’s single platform. It applies to products already on the market too.

What to expect next: 11 December 2027: the Annex I essential requirements, conformity assessment and CE marking.

Art. 14, 16 ↗
Expected

11 December 2027

Full application and CE marking

From here the essential requirements (Annex I), risk assessment, conformity procedure and CE marking apply. A product with digital elements that does not meet them can no longer be placed on the market. It is also when the RED cyber requirements give way to the CRA.

What you must have done

Before this date: a documented cybersecurity risk assessment, a product meeting the Annex I essential requirements, a conformity-assessment procedure matching its class (self-assessment, or a notified body for important and critical products) and CE marking. From here, a non-compliant product with digital elements can no longer be placed on the market.

Art. 71(2) · Allegato I ↗
Done

Commission guidance published

Document C(2026) 5252 (non-binding) clarifies scope and confirms that the reporting duty applies regardless of when the product was placed on the market.

C(2026) 5252

Standards

Stable reference: harmonised standards and the IT/OT map.

In progress

CEN-CENELEC / ETSI harmonised standards (EN 40000 series)

These are the standards that will grant a presumption of conformity with the Annex I requirements. Several draft product standards are under public enquiry: teams designing now should track them, since they will become the common language of compliance.

Art. 27
Reference

IEC 62443 — the IT/OT reference map

The IEC 62443 family is the reference standard for the security of industrial automation and control systems (IACS): a mature base on which to rest the CRA requirements for an OT product. Use it as a map — secure development lifecycle (62443-4-1), product requirements (62443-4-2) — not as a deadline to chase. Note, though: its European adoption as EN 62443, with the A11:2026 harmonisation amendment tying it to the CRA requirements, is under revision — it is that version, once published, that can grant the presumption of conformity. The family is stable; its harmonised hook to the CRA is not.

IEC 62443-4-1 · -4-2 · EN 62443 (A11:2026)

Radar

At the edge of the product scope, but worth watching.

In progress

ENISA Single Reporting Platform (SRP)

The technical channel through which Article 14 notifications will flow, routing to the national CSIRTs. It is the infrastructure that must be ready by 11 September 2026.

Art. 16
In progress

NIS2 — where it touches the product

The NIS2 directive concerns the security of organisations (essential and important entities), not product conformity: it is a different axis from the CRA. For a manufacturer it enters from the supply side — the supply-chain security obligations of its NIS2-covered customers — and from internal risk management. Here it sits at the edge of the product scope, kept on radar, not detailed.

Dir. (UE) 2022/2555

An editorial reconstruction for information only, current as of the date shown: not advice and not an official source. Always verify dates and statuses against Regulation (EU) 2024/2847 and the ENISA and Commission sources.

Not sure where to start?

45 free minutes to map your regulatory exposure and know what you must have done for each deadline.

Book the Regulatory Spark