One reason the CRA feels overwhelming is that people picture it as a single wall arriving in December 2027. It isn't a wall; it's three steps, and the first one lands well before the big one. Knowing the order changes what you do this quarter.
A phased rollout
The CRA entered into force in December 2024, but its obligations switch on in stages so the ecosystem — standards, notified bodies, the reporting platform — has time to stand up. Three dates carry the weight:
| Date | What applies |
|---|---|
| 11 Jun 2026 | Rules on conformity assessment bodies |
| 11 Sep 2026 | Vulnerability & incident reporting (the first enforceable obligation) |
| 11 Dec 2027 | Full application — all remaining obligations |
11 June 2026 — assessment bodies
The provisions on conformity assessment bodies apply, letting the machinery for notified bodies begin to stand up. For most manufacturers this is background — it matters directly only if your product needs a third-party route (important Class II or critical), in which case it's the start of the runway for engaging one.
11 September 2026 — reporting
The vulnerability and incident reporting obligations apply — the 24 / 72 / 14 timeline, through the ENISA Single Reporting Platform. This is the first part of the CRA with operational teeth, and the crucial detail is that it reaches products already on the market. Your existing, shipped portfolio is in scope from this date, more than a year before the full regime. It's why September, not December, is the deadline to organise around first.
11 December 2027 — full application
The complete regime applies: essential requirements, SBOM, vulnerability handling across the support period, technical documentation, Declaration of Conformity and CE marking. From this date a product with digital elements can't be placed on the EU market without a CE mark backing it.
Sequencing the work
Reporting lands 15 months before full compliance — and the evidence you build for it is most of what December 2027 needs.
The order the dates arrive in is also the order to work in: get reporting-ready for September 2026, and build that on vulnerability handling that produces defensible evidence; then let the December 2027 technical file assemble from the evidence you've been collecting all along. Run it as one continuous programme and the second deadline is mostly assembly. The full sequence is in the manufacturer's guide.
Frequently asked
When does the CRA apply?
It entered into force in December 2024 and applies in phases: the rules on conformity assessment bodies from 11 June 2026, the vulnerability and incident reporting obligations from 11 September 2026, and the full set of obligations from 11 December 2027.
Does the September 2026 reporting deadline apply to existing products?
Yes. From 11 September 2026 the reporting obligation covers products with digital elements already on the EU market, not only ones placed after that date — so your shipped portfolio is in scope more than a year before full compliance.
What is the final CRA deadline?
11 December 2027, when the full regime applies — essential requirements, SBOM, vulnerability handling, technical documentation, Declaration of Conformity and CE marking.