Skip to content

Cyber Resilience Act

How should a manufacturer prepare for the December 2027 CRA deadline?

LAST REVIEWED

  • Now: product scope, classification, gap assessment against the essential requirements.
  • Before 11 September 2026: vulnerability intake, triage and reporting decision chain operating, since reporting obligations start then.
  • During 2026–2027: architectural and release-engineering changes, update mechanism proven end to end, SBOM in the pipeline.
  • 2027: conformity assessment, technical documentation assembly, declaration of conformity and CE marking.

Products with long hardware lifecycles are the constraint. If a fix requires a hardware revision or a new secure boot chain, that decision has to be made well before the final year.

Want this answered for your product?

The scope checker gives you a documented read in a few minutes, including a full PDF.