In force since December 2024. Chapter IV (notification of conformity assessment bodies) has applied since 11 June 2026 and Article 14 reporting since 11 September 2026; the Regulation as a whole applies from 11 December 2027. The scalar alone is insufficient — read the milestones.
What it does
Horizontal cybersecurity requirements for products with digital elements.
How it allocates obligations
Product security across the lifecycle.
Regulated actor
Manufacturer of a product with digital elements
Protected party
End user
Territorial reach
Established in the EU · Outside the EU, serving EU users
Entry into force, application and transposition are different events and are kept apart. A date at month precision is shown as a month rather than invented as a day.
23 October 2024AdoptionAdoption
20 November 2024Publication in the Official JournalPublication in the Official Journal
10 December 2024Entry into forceEntry into force
11 June 2026Application dateChapter IV (Articles 35 to 51), on the notification of conformity assessment bodies, applies.
11 September 2026Reporting deadlineReporting of actively exploited vulnerabilities and serious incidents begins.What it requires: Stand up a coordinated vulnerability disclosure and incident reporting process before this date.
11 December 2027Application dateFull application of the Cyber Resilience Act.What it requires: Complete conformity assessment for products with digital elements.
1 rule in the dataset turn on this instrument. They are conditions, not a test: the engine ranks them against what you actually answer, and downgrades rather than excludes where a question is left blank.
Potentially applicable
actor Manufacturer or Manufacturer of a product with digital elements or Connected-product provideractivity Placing connected products on the market or Placing products with digital elements on the market
The Cyber Resilience Act sets horizontal cybersecurity requirements for products with digital elements across their lifecycle. Reporting of actively exploited vulnerabilities and serious incidents begins on 11 September 2026; full application follows on 11 December 2027.
3 provisions recorded. This is what the dataset holds, not the whole instrument — an article that is not here has not been entered, which is a different statement from its not existing.
Article
Heading
Binds
Applies
Art. 13
Obligations of manufacturersWhen placing a product with digital elements on the market, manufacturers must ensure it has been designed, developed and produced in accordance with the essential cybersecurity requirements in Part I of Annex I.
Manufacturer · Manufacturer of a product with digital elements
Applies from 11 June 2026the instrument’s general date; nothing specific to this article is recordedthen from 11 December 2027: application date
Art. 14
Reporting obligations of manufacturersManufacturers must notify any actively exploited vulnerability, and severe incidents, simultaneously to the CSIRT designated as coordinator and to ENISA, via the single reporting platform. Applies from 11 September 2026 (Art. 71(2)).
Manufacturer · Manufacturer of a product with digital elements
Applies from 11 June 2026the instrument’s general date; nothing specific to this article is recordedthen from 11 December 2027: application date
Art. 16
Establishment of a single reporting platformENISA establishes the single reporting platform for the notifications under Articles 14 and 15, and manages and maintains its day-to-day operations.
not recorded
Applies from 11 June 2026the instrument’s general date; nothing specific to this article is recordedthen from 11 December 2027: application date
Enforcement
No enforcement recorded
This dataset holds no enforcement action under this instrument. That is what the record says; it is not a finding that none has been taken.
Every statement this site makes about CRA, graded by what actually carries it. The grade is derived from the claim type and its sources, never stored, so it cannot drift from what it describes.
The instrument record itself was last verified on 27 August 2026; every claim below carries its own date.
1 Interpretation
Interpretationinterpretation
The EU's directive-based instruments underperform its regulation-based ones badly — the strongest single argument for the regulation-first drafting approach used elsewhere in the rulebook.
1 recorded interaction with other instruments — each with a direction, the provisions that carry it and its own sources. Direction is preserved as recorded: an instrument that amends another is not the same as one amended by it.