Cyber Resilience Act
How should a manufacturer prepare for the December 2027 CRA deadline?
LAST REVIEWED
- Now: product scope, classification, gap assessment against the essential requirements.
- Before 11 September 2026: vulnerability intake, triage and reporting decision chain operating, since reporting obligations start then.
- During 2026–2027: architectural and release-engineering changes, update mechanism proven end to end, SBOM in the pipeline.
- 2027: conformity assessment, technical documentation assembly, declaration of conformity and CE marking.
Products with long hardware lifecycles are the constraint. If a fix requires a hardware revision or a new secure boot chain, that decision has to be made well before the final year.
Want this answered for your product?
The scope checker gives you a documented read in a few minutes, including a full PDF.