Cyber Resilience Act
Transition periods and dates of application
Practical term
Transition periods and dates of application govern when the individual parts of the Cyber Resilience Act (CRA) actually have to be applied. The regulation entered into force on 10 December 2024, on the twentieth day following its publication in the Official Journal (Article 71(1)). That is a long way from having to comply with it. Article 71(2) sets the general date of application at 11 December 2027.
Entry into force and date of application are two different things, and the distinction is more than pedantry. On entry into force the regulation exists as binding Union law and the Commission’s empowerments begin to run; the power to adopt delegated acts runs for five years from 10 December 2024 under Article 61(2). Obligations for manufacturers, by contrast, arise only when the relevant provision becomes applicable.
Three dates to plan around
- 11 June 2026: Chapter IV, Articles 35 to 51, on the notification of conformity assessment bodies. From that day the rules under which Member States notify conformity assessment bodies apply.
- 11 September 2026: Article 14, carrying the manufacturer reporting obligations for actively exploited vulnerabilities and severe incidents, including the 24-hour deadline for the early warning.
- 11 December 2027: everything else. That covers the essential cybersecurity requirements in Annex I, conformity assessment, the CE marking, the duties of importers and distributors, and market surveillance in full.
The regulation brings nothing else forward. Any provision that is neither Article 14 nor part of Chapter IV applies from 11 December 2027, however closely it relates in substance to one that arrives earlier.
Products already on the market before the date of application
Legacy stock is governed by Article 69(2): products placed on the market before 11 December 2027 become subject to the requirements of the regulation only if, from that date, they undergo a substantial modification. What counts is placing on the market, not continued distribution. A product first made available in November 2027 therefore stays outside even if distributors are still supplying it in 2029.
The reference point is the individual unit. Article 3, point (21) defines placing on the market as the first making available of a product with digital elements on the Union market, and recital 38 states expressly that the essential cybersecurity requirements apply to each individual product when it is placed on the market, whether it is produced as a single unit or in series. Devices still sitting in the manufacturer’s warehouse on the cut-off date are placed on the market when they ship. The regulation applies to them in full, even though the model has been selling for years.
Article 69(3) carves out a single exception. The obligations in Article 14 apply to every product with digital elements within scope that was placed on the market before 11 December 2027. From 11 September 2026 a legacy product can put a 24-hour clock in motion even though it will never bear a CE marking under this regulation and has to meet none of the Annex I requirements.
Certificates issued under other legislation
Article 69(1) is about paperwork rather than products. EU type-examination certificates and approval decisions issued in respect of cybersecurity requirements for products with digital elements that are subject to Union harmonisation legislation other than this regulation remain valid until 11 June 2028. Two qualifications sit alongside that date: a certificate that would expire earlier ends on its own terms, and where the other legislation provides otherwise, validity follows that legislation, which may also run beyond 11 June 2028.
Article 69(1) does not turn such a certificate into evidence of conformity with the CRA. That evidence follows rules of its own, the conformity assessment procedures in Article 32. The provision only bridges the stretch in which two sets of rules sit side by side.
Deadlines that bind someone other than the manufacturer
Several dates are addressed to the Commission or to Member States. They still matter for your own planning, because without them the groundwork is missing:
- Article 7(4): by 11 December 2025 the Commission is to adopt an implementing act setting out the technical description of the categories in Annexes III and IV. In borderline cases only that description settles whether something counts among the important or critical products.
- Article 14(9): also by 11 December 2025, a delegated act is to specify the terms on which dissemination of a notification may be delayed on cybersecurity grounds.
- Article 35(2): by 11 December 2026 there should be a sufficient number of notified bodies in the Union to avoid bottlenecks and hindrances to market entry.
- Article 70: by 11 September 2028 the Commission reports on the effectiveness of the single reporting platform, and by 11 December 2030, then every four years, on the regulation as a whole.
The regulation attaches no legal consequence to any of these dates passing. For planning purposes they read better as expectations than as commitments.
Future changes carry transition periods of their own
Annexes III and IV can change, and with them a product’s classification. Where the Commission adds a category to Annex III by delegated act, or moves one from class I to class II, that act is where appropriate to provide a transitional period of at least twelve months before the conformity assessment procedures in Article 32(2) and (3) apply (Article 7(3)).
Article 8 is stricter. Delegated acts imposing a certification requirement on critical products, or amending Annex IV, must provide a transitional period of at least six months. In both cases a shorter period is available only on imperative grounds of urgency.
A gap the text leaves open
Article 14(7) requires notifications to go through the single reporting platform established under Article 16. Article 16 belongs neither to Article 14 nor to Chapter IV, so it applies only from 11 December 2027, while the reporting duty itself starts on 11 September 2026. How those fifteen months are bridged in practice does not follow from the text of the regulation.
The same pattern shows up with open-source software stewards. Article 24(3) extends obligations under Article 14 to them on conditions of its own: paragraph 1 to the extent that they are involved in developing the product, and paragraphs 3 and 8 to the extent that a severe incident affects the network and information systems they provide for that development. Article 24 itself, like the rest of the text, applies only from 11 December 2027.
Practical questions
-
The benefit is real but narrow. Under Article 69(2), a product placed on the market before that date stays outside the requirements for as long as it undergoes no substantial modification. For software that state rarely lasts, because a functional update that changes the intended purpose can already qualify as substantial. The Article 14 reporting obligations apply regardless, legacy products included. Pulling a launch forward therefore defers the work rather than removing it.
-
No. The duty to handle vulnerabilities across a defined support period sits in Article 13(8), and Article 13 is among the provisions that apply only from 11 December 2027. Article 69(2) keeps legacy products out of it unless a substantial modification follows, and Article 69(3) takes Article 14 alone back out of that shelter. A legacy product can therefore carry a reporting duty without any accompanying duty to supply security updates.
-
Counting on it would be unwise. Article 35(2) names 11 December 2026 as the point by which there should be a sufficient number of notified bodies in the Union so that market entry is not held up. The English text frames this as a best-efforts duty on Member States (“shall strive to ensure”), the German more firmly; neither version gives an individual manufacturer a claim. Recital 80 points to the way out: harmonised standards available in good time let manufacturers of class I important products run the assessment under internal control. If you need a notified body, book the slot early.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.