Skip to content
EU Cyber Resilience Act Compliance Deadlines Approaching

EU Cyber Resilience Act Compliance Deadlines Approaching

First seen 23 Sep 2026, 06:24 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 23, 2026 at 07:28 UTC
  • UK organizations must comply with the EU Cyber Resilience Act when selling products in the EU.
  • Reporting obligations for vulnerabilities have been live since September 11, 2026.
  • Full compliance with all CRA requirements is required by December 11, 2027.

The EU Cyber Resilience Act (CRA) establishes mandatory cybersecurity requirements for products with digital elements sold in the EU. UK organizations selling such products are affected, regardless of their location. Reporting obligations under Article 14 began on September 11, 2026, requiring manufacturers to report actively exploited vulnerabilities and severe incidents. Full compliance with all CRA requirements is mandated by December 11, 2027. The CRA applies to all products with digital elements, including software and connected hardware. Key compliance milestones have already passed, including the entry into force of the CRA and the activation of the notified body framework. Organizations must prepare for the upcoming deadlines to avoid penalties, which can reach up to €15 million or 2.5% of global turnover. The CRA's phased implementation aims to ensure compliance infrastructure is in place before full technical obligations take effect.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2024-10-23
EU Cyber Resilience Act adopted
The EU Cyber Resilience Act was officially adopted, establishing cybersecurity requirements for digital products.
Surecloud
2024-12-10
CRA enters into force
The Cyber Resilience Act became law, initiating the phased compliance timeline for affected organizations.
Surecloud
2026-06-11
Notified body framework takes effect
The framework for third-party conformity assessments under the CRA became operational.
Surecloud
2026-09-11
Article 14 reporting duties go live
Manufacturers are now required to report actively exploited vulnerabilities and severe incidents to EU authorities.
Aikido.Dev
2027-12-11
Full application of CRA requirements
All products placed on the EU market must comply with the full requirements of the CRA, including CE marking and technical documentation.
Surecloud

More articles in this cluster (3)