The Clock Is Ticking
The CRA has a staggered enforcement timeline. Understanding these deadlines is critical for planning your compliance roadmap.
Key Dates
September 2026 β Reporting Obligations Begin
- Must report actively exploited vulnerabilities to ENISA within 24 hours
- Must report severe incidents within 72 hours
- Requires established vulnerability handling processes
December 2027 β Full Enforcement
- All CRA requirements become mandatory
- Products must meet essential cybersecurity requirements
- CE marking required for market access
- SBOM documentation mandatory
- Security update obligations active
Your Compliance Roadmap
Now β June 2026 (Preparation Phase)
Month 1-2: Product Classification
βββ Identify all products with digital elements
βββ Classify: Default, Important Class I/II, Critical
βββ Document product boundaries and digital interfaces
Month 3-4: Gap Analysis
βββ Assess current security practices against CRA requirements
βββ Identify missing processes (SBOM, vulnerability handling, etc.)
βββ Estimate remediation effort and budget
Month 5-8: Implementation
βββ Implement SBOM generation in CI/CD pipelines
βββ Establish coordinated vulnerability disclosure
βββ Set up incident reporting procedures
βββ Security-by-design training for development teams
Month 9-12: Testing & Documentation
βββ Internal conformity assessment (default products)
βββ Prepare technical documentation
βββ Conduct security testing and penetration testing
βββ Engage third-party assessors if requiredJune 2026 β September 2026 (Reporting Readiness)
Focus: Ensure vulnerability reporting infrastructure is operational.
# Incident reporting SLA tracker
class CRAReportingTracker:
DEADLINES = {
"actively_exploited_vulnerability": timedelta(hours=24),
"severe_incident": timedelta(hours=72),
"vulnerability_assessment": timedelta(days=14),
"final_report": timedelta(days=30),
}
async def report_vulnerability(self, vuln):
# Early warning to ENISA
await self.submit_to_enisa(
type="early_warning",
vulnerability=vuln,
deadline=self.DEADLINES["actively_exploited_vulnerability"],
)
# Schedule follow-up reports
await self.schedule_followup(vuln)September 2026 β December 2027 (Progressive Compliance)
Progressively implement remaining requirements:
- Security testing automation
- Product lifecycle security management
- CE marking preparation
- Third-party assessment (if Class II or Critical)
Cost of Non-Compliance
| Violation | Maximum Fine |
|---|---|
| Essential requirements violation | β¬15M or 2.5% global turnover |
| Other CRA obligations | β¬10M or 2% global turnover |
| Incorrect/incomplete information | β¬5M or 1% global turnover |
Industry Impact
Based on assessments Iβve conducted:
- Average compliance cost: β¬200K-2M per product line (depending on classification)
- Timeline to achieve compliance: 12-18 months for most organizations
- Biggest gap: SBOM generation and vulnerability handling processes
Start now. September 2026 is closer than you think.
Need a CRA compliance roadmap for your organization? I help teams plan and execute cybersecurity regulation compliance. Get in touch.