Skip to main content
πŸŽ“ Claude Code Masterclass Learn AI-assisted development on Udemy β€” plus the companion book on Leanpub & Amazon. Start Learning
CRA Timeline: Key Deadlines and Enforcement Milestones
DevOps

CRA Timeline: Key Deadlines and Enforcement Milestones

Critical dates for EU Cyber Resilience Act compliance. From reporting obligations in 2026 to full enforcement in 2027, here's what to prepare and when.

LB
Luca Berton
Β· 1 min read

The Clock Is Ticking

The CRA has a staggered enforcement timeline. Understanding these deadlines is critical for planning your compliance roadmap.

Key Dates

September 2026 β€” Reporting Obligations Begin

  • Must report actively exploited vulnerabilities to ENISA within 24 hours
  • Must report severe incidents within 72 hours
  • Requires established vulnerability handling processes

December 2027 β€” Full Enforcement

  • All CRA requirements become mandatory
  • Products must meet essential cybersecurity requirements
  • CE marking required for market access
  • SBOM documentation mandatory
  • Security update obligations active

Your Compliance Roadmap

Now β†’ June 2026 (Preparation Phase)

Month 1-2: Product Classification
  └── Identify all products with digital elements
  └── Classify: Default, Important Class I/II, Critical
  └── Document product boundaries and digital interfaces

Month 3-4: Gap Analysis
  └── Assess current security practices against CRA requirements
  └── Identify missing processes (SBOM, vulnerability handling, etc.)
  └── Estimate remediation effort and budget

Month 5-8: Implementation
  └── Implement SBOM generation in CI/CD pipelines
  └── Establish coordinated vulnerability disclosure
  └── Set up incident reporting procedures
  └── Security-by-design training for development teams

Month 9-12: Testing & Documentation
  └── Internal conformity assessment (default products)
  └── Prepare technical documentation
  └── Conduct security testing and penetration testing
  └── Engage third-party assessors if required

June 2026 β†’ September 2026 (Reporting Readiness)

Focus: Ensure vulnerability reporting infrastructure is operational.

# Incident reporting SLA tracker
class CRAReportingTracker:
    DEADLINES = {
        "actively_exploited_vulnerability": timedelta(hours=24),
        "severe_incident": timedelta(hours=72),
        "vulnerability_assessment": timedelta(days=14),
        "final_report": timedelta(days=30),
    }
    
    async def report_vulnerability(self, vuln):
        # Early warning to ENISA
        await self.submit_to_enisa(
            type="early_warning",
            vulnerability=vuln,
            deadline=self.DEADLINES["actively_exploited_vulnerability"],
        )
        
        # Schedule follow-up reports
        await self.schedule_followup(vuln)

September 2026 β†’ December 2027 (Progressive Compliance)

Progressively implement remaining requirements:

  • Security testing automation
  • Product lifecycle security management
  • CE marking preparation
  • Third-party assessment (if Class II or Critical)

Cost of Non-Compliance

ViolationMaximum Fine
Essential requirements violation€15M or 2.5% global turnover
Other CRA obligations€10M or 2% global turnover
Incorrect/incomplete information€5M or 1% global turnover

Industry Impact

Based on assessments I’ve conducted:

  • Average compliance cost: €200K-2M per product line (depending on classification)
  • Timeline to achieve compliance: 12-18 months for most organizations
  • Biggest gap: SBOM generation and vulnerability handling processes

Start now. September 2026 is closer than you think.


Need a CRA compliance roadmap for your organization? I help teams plan and execute cybersecurity regulation compliance. Get in touch.

#cra #compliance #timeline #eu-regulation #cybersecurity
Share:
AI Infrastructure for Regulated Enterprises

Need help with AI Infrastructure for Regulated Enterprises?

Reference architecture and SOC 2/ISO 27001 control mapping for AI in finance, healthcare, and public sector.

Learn more about AI Infrastructure for Regulated Enterprises

Want to operate this yourself, in production?

Take the free AI Platform Engineer Readiness Scorecard to see which skills transfer β€” then build a production-shaped AI platform in the 4-week Bootcamp.

Take the Scorecard β†’
Luca Berton β€” AI & Cloud Advisor, Docker Captain

Luca Berton

AI & Cloud Advisor Β· Docker Captain Β· KubeCon Speaker

15+ years in enterprise infrastructure. Author of 8 technical books, creator of Ansible Pilot (1M+ YouTube views, 648K site users). Former Red Hat engineer. Speaker at KubeCon EU 2026 and Red Hat Summit 2026.

Free 30-min AI & Cloud consultation

Book Now