TL;DR: The EU Cyber Resilience Act is already in force, but its obligations phase in across 2026 and 2027, with vulnerability reporting due in September 2026 and full conformity, including CE marking, due in December 2027, according to FOSSA. The practical risk is timeline compression: reporting workflows, SBOM generation, secure-by-design defaults, and lifecycle security controls all need to be operational before enforcement arrives.
NHIMG editorial — based on content published by FOSSA: the EU Cyber Resilience Act timeline and readiness guidance
By the numbers:
- The Cyber Resilience Act was published in November 2024 and entered into force on 10 December 2024.
- Manufacturers must start vulnerability reporting from 11 September 2026, with a 24-hour early warning required from the moment of awareness.
- Full conformity, including CE marking, applies from 11 December 2027 for products placed on the EU market.
Questions worth separating out
Q: How should organisations prepare for phased Cyber Resilience Act deadlines?
A: Break the work into two tracks.
A: Because the CRA is not a single compliance switch.
Q: What breaks when vulnerability reporting is not rehearsed before the CRA deadline?
A: The first failure is usually coordination, not detection.
Practitioner guidance
- Map controls to each CRA milestone Build a phased compliance plan that separates September 2026 reporting obligations from December 2027 conformity work, with named owners for each control family and evidence stream.
- Publish and test vulnerability disclosure workflows Create a coordinated vulnerability disclosure policy, then rehearse the 24-hour early warning path, escalation roles, and data capture needed for ENISA reporting.
- Automate SBOM and update evidence Put machine-readable SBOM generation, release attestation, and decoupled security update tracking into the build and release pipeline so evidence is produced continuously.
What's in the full article
FOSSA's full post covers the operational detail this post intentionally leaves for the source:
- A milestone-by-milestone CRA readiness checklist for the 2026 reporting phase and the 2027 conformity phase
- Practical guidance for coordinating vulnerability disclosure, ENISA reporting fields, and internal incident workflows
- A 30/60/90-day plan for closing SBOM, secure-by-design, and update-governance gaps
- The specific compliance questions organisations should resolve with legal and product leadership before enforcement tightens
👉 Read FOSSA's guide to the EU Cyber Resilience Act timeline and readiness plan →
EU Cyber Resilience Act deadlines: what do security teams need to do now?
Explore further
Phased regulation changes the control ownership problem: the CRA forces product organisations to separate reporting readiness from final conformity readiness. That distinction matters because the first deadline is about incident governance, while the second is about product lifecycle assurance. Security leaders should treat this as a maturity test for whether product, security, and compliance teams can execute on different timelines without creating control gaps.
A question worth separating out:
Q: Who is accountable when a product fails CRA conformity or reporting expectations?
A: Accountability usually sits across product security, engineering, compliance, and legal, but one function must own the evidence chain. The best practice is to name a primary control owner for reporting readiness and a separate owner for conformity readiness, so responsibilities do not collapse into a shared but unmanaged obligation.
👉 Read our full editorial: EU Cyber Resilience Act timelines: what practitioners must prioritise