Beginning on September 11, 2026, according to Article 14, “Reporting obligations of manufacturers”, manufacturers will have to report to national authorities and ENISA, the European Union Agency for Cybersecurity, about actively exploited vulnerabilities and severe incidents.

Following this first major milestone, the regulation in its entirety will apply as of December 11, 2027, and all products that fall within the scope will require a CE marking indicating compliance with the CRA.

Summary of CRA deadlines
For a more detailed look at how Digi is committed to helping you navigate the requirements, download our comprehensive guide Complying with the Cyber Resilience Act (CRA).