Skip to main content
Oficiálna stránka verejnej správy SR
Cyber Resilience Act · National Security Authority

CRA implementation timeline

Last updated:

CRA implementation timeline

The Cyber Resilience Act (CRA) has been in force since 10 December 2024. Its obligations do not all apply from the same date. The timeline below explains who is affected by each milestone and what it means.

Right now: From 11 September 2026, Article 14 applies — manufacturers must report actively exploited vulnerabilities and severe incidents. From Slovakia, start with the SK-CERT route page, which distinguishes occurrence type and JISKB access. ENISA’s direct SRP is also available; check its current availability on the SRP status page.

Next binding date: 11 December 2026 — Member States must strive to ensure that enough notified bodies are available. This is a milestone for Member States and notification applicants, not the general product-compliance date.

Date Status on 11 Sep 2026 Who is affected What changes / action required Legal or official source
23 Oct 2024 past everyone The Regulation was adopted. CRA — Official Journal, Regulation (EU) 2024/2847
20 Nov 2024 past everyone The Regulation was published in the Official Journal. CRA — official text
10 Dec 2024 in effect everyone The CRA entered into force. This is not the date on which all substantive duties began to apply. Article 71(1) CRA
11 Jun 2026 applies conformity-assessment and notifying authorities Chapter IV (Articles 35–51), on notification of conformity-assessment bodies, began to apply. This is not the general product-compliance date. Article 71(2) CRA
27 Jul 2026 published manufacturers, developers, businesses and advisers The Commission published its first practical CRA implementation guidance. It is non-binding; the legal acts remain controlling. Communication and annex C(2026) 5252
11 Sep 2026 applies manufacturers of products with digital elements Article 14 applies. Operate the 24-hour early warning, 72-hour notification and later final report process. In Slovakia, select the national channel according to occurrence type and JISKB access; direct SRP access is also available. Reporting also covers in-scope products placed on the market before 11 Dec 2027. Articles 14, 16, 69(3) and 71(2) CRA; Commission reporting overview
11 Dec 2026 future Member States; indirectly notification applicants Member States must strive to ensure that enough notified bodies are available. This is not a guarantee of service availability on that date. Article 35(2) CRA
11 Dec 2027 future economic operators and other persons covered by the CRA The CRA generally applies. Products placed on the market earlier are otherwise subject to the main requirements only if substantially modified from that date; reporting is the express earlier exception. Articles 69(2)–(3) and 71(2) CRA
11 Jun 2028 future holders of certain existing certificates/decisions Transitional validity ends for certain EU type-examination certificates and approval decisions concerning cybersecurity, unless they expire sooner or other Union legislation provides otherwise. Article 69(1) CRA
11 Sep 2028 future Commission, ENISA and coordinator CSIRTs Deadline for the Commission’s report on the effectiveness of the Single Reporting Platform. It is not a new manufacturer deadline. Article 70(2) CRA
11 Dec 2030 and every 4 years thereafter future Commission; indirectly all stakeholders CRA evaluation and review cycle. Article 70(1) CRA
What to do now

The Commission implementation plan also tracks indicative milestones for standards, guidance and further acts. Those milestones are not automatically statutory deadlines for an economic operator. Follow the Commission’s current implementation plan.

Information verified: 11 September 2026. Continue to check the platform’s current availability and later changes in official sources.